Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2025-8943 Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers CRITICAL 9.8 65.77% cvelistv5 2026-06-17
cve-2024-58274 Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025. HIGH 8.3 19.09% cvelistv5 2026-06-17
cve-2026-63077 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol CRITICAL 9.8 86.52% cvelistv5 2026-08-06
cve-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation CRITICAL 9.8 60.60% cvelistv5 2026-08-17
cve-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor HIGH 7.5 98.62% cvelistv5 2026-09-21
cve-2026-54066 SUSE CVE CVE-2026-54066 UNKNOWN N/A 2.39% cvelistv5 2026-07-30
cve-2026-48313 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted ... CRITICAL 9.3 2.95% cvelistv5 2026-08-28
cve-2026-38992 Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator. CRITICAL 9.8 0.43% cvelistv5 2026-06-17
cve-2026-28496 CVE-2026-28496 CRITICAL 9.4 1.91% cvelistv5
cve-2026-59800 CVE-2026-59800 CRITICAL 9.8 2.04% cvelistv5
cve-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation CRITICAL 9.8 60.60% cvelistv5 2026-08-17
cve-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor HIGH 7.5 98.62% cvelistv5 2026-09-21
cve-2026-18556 Unauthenticated administrative account takeover HIGH 7.4 40.16% cvelistv5 2026-08-05
cve-2026-18577 Incomplete patch leads to administrative account takeover HIGH 8.1 54.07% cvelistv5 2026-08-04
cve-2025-71324 CVE-2025-71324 HIGH 8.7 1.57% cvelistv5
cve-2023-2825 CVE-2023-2825 CRITICAL 10.0 71.64% cvelistv5
cve-2023-54359 CVE-2023-54359 HIGH 8.8 0.27% cvelistv5
cve-2026-18577 Incomplete patch leads to administrative account takeover HIGH 8.1 54.07% cvelistv5 2026-08-04
cve-2026-18556 Unauthenticated administrative account takeover HIGH 7.4 40.16% cvelistv5 2026-08-05
cve-2019-17558 solr: Remote Code Execution through the VelocityResponseWriter HIGH 7.5 98.57% cvelistv5 2026-08-04
cve-2026-59800 CVE-2026-59800 CRITICAL 9.8 2.04% cvelistv5
cve-2024-37014 Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script. CRITICAL 9.8 63.04% cvelistv5 2026-06-17
cve-2021-1472 Cisco Small Business RV Series Routers Vulnerabilities MEDIUM 5.3 72.03% cvelistv5 2026-06-17
cve-2019-8942 SUSE CVE CVE-2019-8942 UNKNOWN N/A 82.74% cvelistv5 2025-02-17
cve-2026-1623 Totolink A7000R cstecgi.cgi setUpgradeFW command injection MEDIUM 6.3 2.27% cvelistv5 2026-06-17
cve-2026-20316 Cisco Secure Firewall Management Center Software Static Credential Vulnerability MEDIUM 5.3 11.15% cvelistv5 2026-09-16
cve-2026-16232 Authentication Bypass in the SmartConsole Login Process Using an Application Token CRITICAL 9.8 72.05% cvelistv5 2026-08-10
cve-2026-20316 Cisco Secure Firewall Management Center Software Static Credential Vulnerability MEDIUM 5.3 11.15% cvelistv5 2026-09-16
cve-2025-71334 CVE-2025-71334 CRITICAL 9.8 4.36% cvelistv5
cve-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability HIGH N/A 29.60% cvelistv5 2026-07-27