CVE Wiki Pixee · CVE intelligence

Notable CVEs

42 tracked · 7 known-exploited (KEV). Sorted by exploitation signal, then severity.

CVE Product / weakness CVSS EPSS Signal
CVE-2026-10520
Ivanti Sentry
OS Command Injection RCE
10.0 47.9% KEV
CVE-2018-1273
Spring Data Commons
SpEL injection / remote code execution via property binder
9.8 KEV
CVE-2026-35273
PeopleSoft Enterprise PeopleTools
Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP
9.8 KEV
CVE-2026-54420
LiteSpeed cPanel Plugin / LiteSpeed WHM Plugin
Symlink follow / CWE-61 UNIX symbolic link following leading to privilege escalation or path escape on shared hosting (CloudLinux/CageFS bypass)
8.5 0.61% KEV
CVE-2026-42897
Microsoft Exchange Server
Cross-Site Scripting (XSS) leading to spoofing
8.1 KEV
CVE-2026-6973
Ivanti EPMM (Endpoint Manager Mobile)
Improper Input Validation leading to Remote Code Execution
7.2 4.79% KEV
CVE-2026-20262
Cisco Catalyst SD-WAN Manager (SD-WAN vManage)
Path Traversal / Arbitrary File Write (CWE-22)
6.5 1.74% KEV
CVE-2026-48303
Adobe Campaign Classic (ACC)
Incorrect Authorization leading to arbitrary code execution (CWE-863)
10.0 0.50%
CVE-2026-10611
MISP
Authentication bypass via LDAP mixed auth with OTP enforcement skip
10.0
CVE-2026-46389
uds-identity-config
Authentication Bypass via Logic Error in Client Secret Comparison (CWE-287, CWE-303)
10.0
CVE-2026-27446
Apache ActiveMQ Artemis
Missing Authentication for Critical Function - unauthenticated Core protocol federation connection hijack (CWE-306)
9.8 8.34%
CVE-2022-32511
jmespath.rb
Unsafe deserialization via JSON.load instead of JSON.parse
9.8 2.13%
CVE-2026-20253
Splunk Enterprise
Missing Authentication for Critical Function (CWE-306) - Unauthenticated arbitrary file create/truncate via PostgreSQL sidecar service endpoint, leading to pre-auth RCE
9.8 1.68%
CVE-2024-39011
chargeover redoc
Prototype Pollution leading to RCE / DoS
9.8 0.91%
CVE-2023-34575
PrestaShop opartsavecart
SQL Injection
9.8 0.27%
CVE-2023-34576
PrestaShop opartfaq
SQL Injection
9.8 0.22%
CVE-2026-9170
IBM HTTP Server
Improper Input Validation leading to Denial of Service and Remote Code Execution
9.8 0.07%
CVE-2026-44083
QuMagie
Authorization bypass through user-controlled key (IDOR / Broken Object Level Authorization)
9.8 0.06%
CVE-2023-36263
Prestashop opartlimitquantity
SQL Injection
9.8 0.05%
CVE-2026-53838
OpenClaw
Time-of-check Time-of-use (TOCTOU) / State Mutation Race Condition (CWE-367) in node pairing reconnection logic
9.8
CVE-2026-54133
jmespath.php
Code Injection via insufficient escaping of attacker-controlled JMESPath function names in generated PHP source (RCE)
9.8
CVE-2026-50628
Apache (OAuthRequestFilter)
Improper Input Validation / Inverted Security Check (CWE-20) - IP-based OAuth request filtering logic error
9.8
CVE-2026-49875
Apache CXF
XML External Entity (XXE) injection via unsecured SAXParserFactory (CWE-611)
9.8
CVE-2026-25089
Fortinet FortiSandbox
Unauthenticated OS Command Injection (CWE-78)
9.8
CVE-2026-47928
Adobe ColdFusion
Improper Input Validation leading to Arbitrary Code Execution (RCE)
9.6 2.48%
CVE-2026-47281
Visual Studio Code
Improper Input Validation leading to Privilege Escalation (Missing Authentication / Hard-coded Credentials / Missing Authorization)
9.6 0.39%
CVE-2026-53474
migration-planner (kubev2v/migration-planner)
SQL Injection via unsanitized spreadsheet cell input (CWE-89)
9.6 0.31%
CVE-2026-53476
assisted-migration-agent
Path traversal via malicious gzipped tarball (Zip Slip / symlink follow)
9.6 0.29%
CVE-2026-12027
Google Chrome Headless
Sandbox escape via inappropriate implementation in Headless renderer
9.6
CVE-2026-53475
assisted-migration-agent
Improper Certificate Validation / Hardcoded Insecure TLS (CWE-295)
9.3 0.17%
CVE-2026-34691
Adobe Experience Manager Forms JEE
Stored Cross-Site Scripting (XSS)
9.3 0.10%
CVE-2026-7161
GeoVision GV-IP Device Utility
Insufficient encryption / credentials leak via UDP broadcast (CWE-656, security through obscurity)
9.3
CVE-2026-45328
ESP-IDF (Espressif IoT Development Framework)
Improper Input Validation / Out-of-bounds Write in TEE secure-service wrappers (CWE-20, CWE-787)
9.3
CVE-2026-48188
OTRS / ((OTRS)) Community Edition
Improper Input Validation - Unauthenticated SQL Injection leading to Authentication Bypass
9.1 0.32%
CVE-2026-26241
QNAP File Station 5
Stack-based buffer overflow (CWE-121) remote memory corruption / process crash
9.1 0.14%
CVE-2026-26240
QNAP File Station 5
Stack-based buffer overflow (CWE-121) leading to memory corruption or process crash via remote exploitation
9.1 0.14%
CVE-2026-7876
IBM Aspera HSTS for CP4I
Authentication Bypass
9.1 0.04%
CVE-2026-50627
Apache CXF
JWT Audience Claim Validation Bypass (Token Confusion/Routing Attack)
9.1
CVE-2026-34182
OpenSSL
Insufficient input validation on AuthEnvelopedData cipher and tag length fields leading to authentication bypass and decryption oracle (CWE-354)
9.1
CVE-2026-4408
Samba
OS Command Injection via unsanitized shell meta-character substitution (CWE-78) leading to Remote Code Execution
9.0
CVE-2026-4480
Samba
OS Command Injection via unescaped shell metacharacters in print job description (CWE-78)
9.0
CVE-2026-48710
Starlette
HTTP Host header validation bypass / HTTP Request Smuggling (CWE-444, CWE-1289)
6.5 0.91%