Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2022-26134 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability CRITICAL 9.8 100.00% cvelistv5 2022-06-02
cve-2025-52907 CVE-2025-52907 HIGH 7.3 0.85% cvelistv5
cve-2026-72530 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. CRITICAL 9.0 1.83% cvelistv5 2026-08-21
cve-2026-72529 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. CRITICAL 9.8 1.55% cvelistv5 2026-08-21
cve-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability HIGH 8.9 32.38% cvelistv5 2026-08-21
cve-2026-42897 Microsoft Exchange Server Spoofing Vulnerability HIGH 8.1 71.77% cvelistv5 2026-06-17
cve-2026-41679 Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass CRITICAL 10.0 18.85% cvelistv5 2026-06-17
cve-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CRITICAL 9.3 16.41% cvelistv5 2026-08-20
cve-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability CRITICAL 9.8 72.69% cvelistv5 2026-08-19
cve-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CRITICAL 9.3 16.41% cvelistv5 2026-08-20
cve-2025-52907 CVE-2025-52907 HIGH 7.3 0.85% cvelistv5
cve-2022-50973 CVE-2022-50973 CRITICAL 9.8 1.52% cvelistv5
cve-2026-38992 Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. CRITICAL 9.8 0.43% cvelistv5 2026-06-17
cve-2026-65400 An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. CRITICAL 9.8 10.46% cvelistv5 2026-09-15
cve-2026-59310 vCenter directory-traversal vulnerability CRITICAL 9.8 50.38% cvelistv5 2026-08-19
cve-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability CRITICAL 9.1 50.59% cvelistv5 2026-08-19
cve-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability CRITICAL 9.8 72.69% cvelistv5 2026-08-19
cve-2025-62593 Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack HIGH 8.8 16.89% cvelistv5 2026-08-18
cve-2025-62593 Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack HIGH 8.8 16.89% cvelistv5 2026-08-18
cve-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability HIGH 8.8 1.61% cvelistv5 2026-08-26
cve-2026-56270 CVE-2026-56270 HIGH 8.7 2.05% cvelistv5
cve-2026-52806 SUSE CVE CVE-2026-52806 UNKNOWN N/A 7.93% cvelistv5 2026-07-30
cve-2021-2109 CVE-2021-2109 HIGH 7.2 70.45% cvelistv5
cve-2016-5312 Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream. MEDIUM 6.5 53.70% cvelistv5 2026-06-17
cve-2026-45298 Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) HIGH 8.6 1.49% cvelistv5 2026-07-24
cve-2016-20097 Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad HIGH 7.5 0.47% cvelistv5 2026-09-08
cve-2026-73533 Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build serv... CRITICAL 9.3 0.45% cvelistv5 2026-09-09
cve-2026-73532 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build serve... CRITICAL 9.3 0.46% cvelistv5 2026-09-09
cve-2026-67595 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php HIGH 8.1 0.53% cvelistv5 2026-07-30
cve-2022-50997 Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp HIGH 7.5 0.46% cvelistv5 2026-09-08