Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-0768 Langflow code Code Injection Remote Code Execution Vulnerability CRITICAL 9.8 7.78% cvelistv5 2026-06-17
cve-2026-2614 mlflow: mlflow: Arbitrary file read via bypassed source path validation HIGH 7.5 3.61% cvelistv5 2026-08-27
cve-2023-7330 CVE-2023-7330 CRITICAL 9.3 0.62% cvelistv5
cve-2024-58374 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allow... HIGH 8.7 0.47% cvelistv5 2026-09-09
cve-2024-58374 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allow... HIGH 8.7 0.47% cvelistv5 2026-09-09
cve-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability HIGH N/A 3.57% cvelistv5 2026-08-31
cve-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability MEDIUM 5.3 0.58% cvelistv5 2026-08-27
cve-2026-53362 Linux Kernel Unspecified Vulnerability HIGH N/A 0.51% cvelistv5 2026-08-27
cve-2023-49105 ownCloud Improper Authentication Vulnerability CRITICAL 9.8 43.20% cvelistv5 2026-08-27
cve-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability HIGH N/A 3.29% cvelistv5 2026-08-31
cve-2026-61511 CVE-2026-61511 CRITICAL 9.8 70.77% cvelistv5
cve-2023-34124 The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. CRITICAL 9.8 50.48% cvelistv5 2026-06-17
cve-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability HIGH N/A 9.44% cvelistv5 2026-08-26
cve-2021-23758 Deserialization of Untrusted Data HIGH 8.1 83.63% cvelistv5 2026-08-27
cve-2019-1068 A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. HIGH 8.8 52.84% cvelistv5 2026-08-27
cve-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability HIGH N/A 4.96% cvelistv5 2026-08-26
cve-2015-3246 Red Hat Libuser Race Condition Vulnerability HIGH N/A 8.80% cvelistv5 2026-08-26
cve-2023-34132 CVE-2023-34132 HIGH N/A 7.68% cvelistv5
cve-2025-55583 CVE-2025-55583 CRITICAL 9.8 6.97% cvelistv5
cve-2021-2109 CVE-2021-2109 HIGH 7.2 70.45% cvelistv5
cve-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability MEDIUM 5.3 0.58% cvelistv5 2026-08-27
cve-2026-53362 Linux Kernel Unspecified Vulnerability HIGH N/A 0.51% cvelistv5 2026-08-27
cve-2023-49105 ownCloud Improper Authentication Vulnerability CRITICAL 9.8 43.20% cvelistv5 2026-08-27
cve-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability CRITICAL 10.0 42.48% cvelistv5 2026-08-24
cve-2026-18963 keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass CRITICAL 9.1 3.18% cvelistv5 2026-08-20
cve-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability HIGH 8.1 2.89% cvelistv5 2026-09-24
cve-2026-60004 Gitea Code Injection Vulnerability HIGH N/A 86.78% cvelistv5 2026-08-25
cve-2025-55583 CVE-2025-55583 CRITICAL 9.8 6.97% cvelistv5
cve-2026-77136 The extension passes the raw value of a form field configured as "This field contains the name of the sender" directl... CRITICAL 9.5 0.55% cvelistv5 2026-08-26
cve-2026-76904 GeoTools is an open source Java library that provides tools for geospatial data CRITICAL 9.8 1.79% cvelistv5 2026-09-09