Notable CVEs
42 tracked · 7 known-exploited (KEV). Sorted by exploitation signal, then severity.
| CVE | Product / weakness | CVSS | EPSS | Signal |
|---|---|---|---|---|
| CVE-2026-10520 | Ivanti Sentry OS Command Injection RCE | 10.0 | 47.9% | KEV |
| CVE-2018-1273 | Spring Data Commons SpEL injection / remote code execution via property binder | 9.8 | — | KEV |
| CVE-2026-35273 | PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP | 9.8 | — | KEV |
| CVE-2026-54420 | LiteSpeed cPanel Plugin / LiteSpeed WHM Plugin Symlink follow / CWE-61 UNIX symbolic link following leading to privilege escalation or path escape on shared hosting (CloudLinux/CageFS bypass) | 8.5 | 0.61% | KEV |
| CVE-2026-42897 | Microsoft Exchange Server Cross-Site Scripting (XSS) leading to spoofing | 8.1 | — | KEV |
| CVE-2026-6973 | Ivanti EPMM (Endpoint Manager Mobile) Improper Input Validation leading to Remote Code Execution | 7.2 | 4.79% | KEV |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager (SD-WAN vManage) Path Traversal / Arbitrary File Write (CWE-22) | 6.5 | 1.74% | KEV |
| CVE-2026-48303 | Adobe Campaign Classic (ACC) Incorrect Authorization leading to arbitrary code execution (CWE-863) | 10.0 | 0.50% | |
| CVE-2026-10611 | MISP Authentication bypass via LDAP mixed auth with OTP enforcement skip | 10.0 | — | |
| CVE-2026-46389 | uds-identity-config Authentication Bypass via Logic Error in Client Secret Comparison (CWE-287, CWE-303) | 10.0 | — | |
| CVE-2026-27446 | Apache ActiveMQ Artemis Missing Authentication for Critical Function - unauthenticated Core protocol federation connection hijack (CWE-306) | 9.8 | 8.34% | |
| CVE-2022-32511 | jmespath.rb Unsafe deserialization via JSON.load instead of JSON.parse | 9.8 | 2.13% | |
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function (CWE-306) - Unauthenticated arbitrary file create/truncate via PostgreSQL sidecar service endpoint, leading to pre-auth RCE | 9.8 | 1.68% | |
| CVE-2024-39011 | chargeover redoc Prototype Pollution leading to RCE / DoS | 9.8 | 0.91% | |
| CVE-2023-34575 | PrestaShop opartsavecart SQL Injection | 9.8 | 0.27% | |
| CVE-2023-34576 | PrestaShop opartfaq SQL Injection | 9.8 | 0.22% | |
| CVE-2026-9170 | IBM HTTP Server Improper Input Validation leading to Denial of Service and Remote Code Execution | 9.8 | 0.07% | |
| CVE-2026-44083 | QuMagie Authorization bypass through user-controlled key (IDOR / Broken Object Level Authorization) | 9.8 | 0.06% | |
| CVE-2023-36263 | Prestashop opartlimitquantity SQL Injection | 9.8 | 0.05% | |
| CVE-2026-53838 | OpenClaw Time-of-check Time-of-use (TOCTOU) / State Mutation Race Condition (CWE-367) in node pairing reconnection logic | 9.8 | — | |
| CVE-2026-54133 | jmespath.php Code Injection via insufficient escaping of attacker-controlled JMESPath function names in generated PHP source (RCE) | 9.8 | — | |
| CVE-2026-50628 | Apache (OAuthRequestFilter) Improper Input Validation / Inverted Security Check (CWE-20) - IP-based OAuth request filtering logic error | 9.8 | — | |
| CVE-2026-49875 | Apache CXF XML External Entity (XXE) injection via unsecured SAXParserFactory (CWE-611) | 9.8 | — | |
| CVE-2026-25089 | Fortinet FortiSandbox Unauthenticated OS Command Injection (CWE-78) | 9.8 | — | |
| CVE-2026-47928 | Adobe ColdFusion Improper Input Validation leading to Arbitrary Code Execution (RCE) | 9.6 | 2.48% | |
| CVE-2026-47281 | Visual Studio Code Improper Input Validation leading to Privilege Escalation (Missing Authentication / Hard-coded Credentials / Missing Authorization) | 9.6 | 0.39% | |
| CVE-2026-53474 | migration-planner (kubev2v/migration-planner) SQL Injection via unsanitized spreadsheet cell input (CWE-89) | 9.6 | 0.31% | |
| CVE-2026-53476 | assisted-migration-agent Path traversal via malicious gzipped tarball (Zip Slip / symlink follow) | 9.6 | 0.29% | |
| CVE-2026-12027 | Google Chrome Headless Sandbox escape via inappropriate implementation in Headless renderer | 9.6 | — | |
| CVE-2026-53475 | assisted-migration-agent Improper Certificate Validation / Hardcoded Insecure TLS (CWE-295) | 9.3 | 0.17% | |
| CVE-2026-34691 | Adobe Experience Manager Forms JEE Stored Cross-Site Scripting (XSS) | 9.3 | 0.10% | |
| CVE-2026-7161 | GeoVision GV-IP Device Utility Insufficient encryption / credentials leak via UDP broadcast (CWE-656, security through obscurity) | 9.3 | — | |
| CVE-2026-45328 | ESP-IDF (Espressif IoT Development Framework) Improper Input Validation / Out-of-bounds Write in TEE secure-service wrappers (CWE-20, CWE-787) | 9.3 | — | |
| CVE-2026-48188 | OTRS / ((OTRS)) Community Edition Improper Input Validation - Unauthenticated SQL Injection leading to Authentication Bypass | 9.1 | 0.32% | |
| CVE-2026-26241 | QNAP File Station 5 Stack-based buffer overflow (CWE-121) remote memory corruption / process crash | 9.1 | 0.14% | |
| CVE-2026-26240 | QNAP File Station 5 Stack-based buffer overflow (CWE-121) leading to memory corruption or process crash via remote exploitation | 9.1 | 0.14% | |
| CVE-2026-7876 | IBM Aspera HSTS for CP4I Authentication Bypass | 9.1 | 0.04% | |
| CVE-2026-50627 | Apache CXF JWT Audience Claim Validation Bypass (Token Confusion/Routing Attack) | 9.1 | — | |
| CVE-2026-34182 | OpenSSL Insufficient input validation on AuthEnvelopedData cipher and tag length fields leading to authentication bypass and decryption oracle (CWE-354) | 9.1 | — | |
| CVE-2026-4408 | Samba OS Command Injection via unsanitized shell meta-character substitution (CWE-78) leading to Remote Code Execution | 9.0 | — | |
| CVE-2026-4480 | Samba OS Command Injection via unescaped shell metacharacters in print job description (CWE-78) | 9.0 | — | |
| CVE-2026-48710 | Starlette HTTP Host header validation bypass / HTTP Request Smuggling (CWE-444, CWE-1289) | 6.5 | 0.91% |