Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2026-48282 | Adobe ColdFusion Path Traversal Vulnerability | CRITICAL | 10.0 | N/A | cvelistv5 | 2026-07-07 |
| cve-2026-4631 | cockpit: Cockpit: Unauthenticated remote code execution due to SSH command-line argument injection | CRITICAL | 9.8 | N/A | cvelistv5 | 2026-08-04 |
| cve-2026-45298 | SUSE CVE CVE-2026-45298 | UNKNOWN | N/A | N/A | cvelistv5 | 2026-07-30 |
| cve-2026-42271 | litellm: LiteLLM: Authenticated command execution via MCP stdio test endpoints | HIGH | 8.8 | N/A | cvelistv5 | 2026-06-30 |
| cve-2026-3836 | dnf5: dnf5: Denial of Service via path traversal in D-Bus locale configuration | MEDIUM | 5.5 | N/A | cvelistv5 | 2026-06-28 |
| cve-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | CRITICAL | 9.8 | N/A | cvelistv5 | 2026-06-12 |
| cve-2026-34910 | Ubiquiti UniFi OS Improper Input Validation Vulnerability | CRITICAL | 10.0 | N/A | cvelistv5 | 2026-06-23 |
| cve-2026-29059 | CVE-2026-29059 | MEDIUM | 6.9 | N/A | cvelistv5 | |
| cve-2026-28496 | CVE-2026-28496 | CRITICAL | 9.4 | N/A | cvelistv5 | |
| cve-2026-28409 | CVE-2026-28409 | CRITICAL | 10.0 | N/A | cvelistv5 | |
| cve-2026-2699 | CVE-2026-2699 | CRITICAL | 9.8 | N/A | cvelistv5 | |
| cve-2026-2652 | mlflow: mlflow: Authentication bypass allows unauthorized job management and data injection | HIGH | 8.6 | N/A | cvelistv5 | 2026-07-08 |
| cve-2026-22679 | CVE-2026-22679 | CRITICAL | 9.8 | N/A | cvelistv5 | |
| cve-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | CRITICAL | 9.8 | N/A | cvelistv5 | 2026-06-18 |
| cve-2026-1547 | Totolink A7000R cstecgi.cgi setUnloadUserData command injection | MEDIUM | 6.3 | N/A | cvelistv5 | 2026-06-17 |
| cve-2026-1207 | SUSE CVE CVE-2026-1207 | HIGH | 8.1 | N/A | cvelistv5 | 2026-08-21 |
| cve-2025-60702 | CVE-2025-60702 | MEDIUM | 6.5 | N/A | cvelistv5 | |
| cve-2025-10164 | CVE-2025-10164 | HIGH | 7.5 | 0.40% | cvelistv5 | |
| cve-2024-12912 | CVE-2024-12912 | HIGH | 7.2 | 1.24% | cvelistv5 | |
| cve-2024-0250 | CVE-2024-0250 | MEDIUM | 6.1 | 1.25% | cvelistv5 | |
| cve-2023-39470 | CVE-2023-39470 | HIGH | 7.2 | 1.76% | cvelistv5 | |
| cve-2023-39361 | cacti: Unauthenticated SQL Injection when viewing graphs | CRITICAL | 9.8 | 88.79% | cvelistv5 | 2025-11-21 |
| cve-2023-3722 | CVE-2023-3722 | HIGH | 8.6 | 3.86% | cvelistv5 | |
| cve-2022-50997 | Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint... | HIGH | 8.7 | 0.46% | cvelistv5 | 2026-09-08 |
| cve-2022-50992 | CVE-2022-50992 | HIGH | 8.7 | 0.70% | cvelistv5 | |
| cve-2022-4995 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauth... | CRITICAL | 9.3 | 0.69% | cvelistv5 | 2026-09-16 |
| cve-2021-27691 | CVE-2021-27691 | HIGH | N/A | 25.18% | cvelistv5 | |
| cve-2019-25765 | ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote att... | HIGH | 8.7 | 0.59% | cvelistv5 | 2026-09-10 |
| cve-2019-12725 | Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. | CRITICAL | 9.8 | 89.85% | cvelistv5 | 2026-06-17 |
| cve-2018-14013 | Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. | MEDIUM | 6.1 | 7.44% | cvelistv5 | 2026-06-17 |