Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability HIGH 8.8 1.61% cvelistv5 2026-08-26
cve-2022-0995 kernel: kernel bug in the watch_queue subsystem HIGH 7.8 9.44% cvelistv5 2026-08-27
cve-2021-23758 Deserialization of Untrusted Data HIGH 8.1 83.63% cvelistv5 2026-08-27
cve-2019-1068 A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. HIGH 8.8 52.84% cvelistv5 2026-08-27
cve-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability HIGH N/A 4.96% cvelistv5 2026-08-26
cve-2015-3246 Red Hat Libuser Race Condition Vulnerability HIGH N/A 8.80% cvelistv5 2026-08-26
cve-2024-12912 CVE-2024-12912 HIGH 7.2 1.24% cvelistv5
cve-2026-60004 Gitea Code Injection Vulnerability HIGH N/A 86.78% cvelistv5 2026-08-25
cve-2023-54359 CVE-2023-54359 HIGH 8.8 0.27% cvelistv5
cve-2026-21962 Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). CRITICAL 10.0 42.48% cvelistv5 2026-08-25
cve-2026-57739 CVE-2026-57739 CRITICAL 9.3 0.40% cvelistv5
cve-2026-27971 Qwik affected by unauthenticated RCE via server$ Deserialization CRITICAL 9.8 5.42% cvelistv5 2026-06-17
cve-2025-10164 CVE-2025-10164 HIGH 7.5 0.40% cvelistv5
cve-2021-27691 CVE-2021-27691 HIGH N/A 25.18% cvelistv5
cve-2019-12725 Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. CRITICAL 9.8 89.85% cvelistv5 2026-06-17
cve-2026-19598 Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router CRITICAL 9.8 2.79% cvelistv5 2026-08-20
cve-2025-71324 CVE-2025-71324 HIGH 8.7 1.57% cvelistv5
cve-2023-2825 CVE-2023-2825 CRITICAL 10.0 71.64% cvelistv5
cve-2026-77806 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in Aug... CRITICAL 9.8 4.20% cvelistv5 2026-09-08
cve-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab CRITICAL 9.4 5.81% cvelistv5 2026-09-02
cve-2026-77647 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in Aug... CRITICAL 9.8 2.62% cvelistv5 2026-09-08
cve-2026-72530 TrueConf Server Code Injection Vulnerability CRITICAL 9.5 1.83% cvelistv5 2026-08-20
cve-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability CRITICAL 9.3 1.55% cvelistv5 2026-08-20
cve-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab CRITICAL 9.4 5.81% cvelistv5 2026-09-02
cve-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability HIGH 8.9 32.38% cvelistv5 2026-08-21
cve-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability CRITICAL 10.0 1.55% cvelistv5 2026-09-24
cve-2023-25158 CVE-2023-25158 CRITICAL 9.8 1.09% cvelistv5
cve-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CRITICAL N/A 50.38% cvelistv5 2026-08-18
cve-2026-49049 CVE-2026-49049 HIGH 7.5 0.99% cvelistv5
cve-2026-12569 Remote Code Execution (RCE) vulnerability in Windchill PDMlink CRITICAL 9.8 40.59% cvelistv5 2026-08-01