Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-41176 github.com/rclone/rclone: Rclone: Unauthorized access to administrative functions through unauthenticated Remote Control endpoint. CRITICAL 9.8 3.22% cvelistv5 2026-06-30
cve-2026-41091 Microsoft Defender Link Following Vulnerability HIGH N/A 0.44% cvelistv5 2026-05-20
cve-2026-41089 Windows Netlogon Remote Code Execution Vulnerability CRITICAL 9.8 0.97% cvelistv5 2026-06-17
cve-2026-4020 Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API HIGH 7.5 2.24% cvelistv5 2026-06-17
cve-2026-39987 Marimo Remote Code Execution Vulnerability HIGH N/A 37.87% cvelistv5 2026-04-23
cve-2026-39813 A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests. CRITICAL 9.8 0.72% cvelistv5 2026-06-18
cve-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability HIGH N/A 47.36% cvelistv5 2026-07-16
cve-2026-3965 whyour qinglong API express.ts protection mechanism MEDIUM 6.3 0.47% cvelistv5 2026-06-17
cve-2026-3910 chromium-browser: Inappropriate implementation in V8 HIGH 8.8 1.03% cvelistv5 2026-06-28
cve-2026-3909 SUSE CVE CVE-2026-3909 HIGH 8.8 0.70% cvelistv5 2026-09-02
cve-2026-35616 Fortinet FortiClient EMS Improper Access Control Vulnerability HIGH N/A 9.10% cvelistv5 2026-04-06
cve-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability CRITICAL N/A 9.44% cvelistv5 2026-06-12
cve-2026-3502 TrueConf Client Download of Code Without Integrity Check Vulnerability HIGH N/A 0.33% cvelistv5 2026-04-02
cve-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability HIGH N/A 0.54% cvelistv5 2026-05-21
cve-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability HIGH N/A 45.77% cvelistv5 2026-06-23
cve-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability HIGH N/A 1.79% cvelistv5 2026-06-23
cve-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability HIGH N/A 15.21% cvelistv5 2026-06-23
cve-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability HIGH 8.6 2.18% cvelistv5 2026-04-13
cve-2026-34234 CtrlPanel: Unauthenticated RCE using installer script CRITICAL 10.0 4.54% cvelistv5 2026-07-24
cve-2026-34197 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: RCE via crafted discovery URI in Jolokia JMX-HTTP bridge HIGH 8.8 15.49% cvelistv5 2026-08-17
cve-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability HIGH 7.8 0.40% cvelistv5 2026-09-25
cve-2026-33634 Aquasecurity Trivy Embedded Malicious Code Vulnerability HIGH N/A 1.68% cvelistv5 2026-03-26
cve-2026-33017 Langflow Code Injection Vulnerability HIGH N/A 24.75% cvelistv5 2026-03-25
cve-2026-3300 Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field CRITICAL 9.8 4.43% cvelistv5 2026-06-17
cve-2026-32202 Windows Shell Spoofing Vulnerability MEDIUM 4.3 4.90% cvelistv5 2026-09-25
cve-2026-32201 Microsoft SharePoint Server Spoofing Vulnerability MEDIUM 6.5 0.98% cvelistv5 2026-09-25
cve-2026-31431 kernel: crypto: algif_aead - Revert to operating out-of-place HIGH 7.8 3.44% cvelistv5 2026-09-01
cve-2026-3055 Citrix NetScaler Out-of-Bounds Read Vulnerability HIGH N/A 4.04% cvelistv5 2026-03-30
cve-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability HIGH N/A 1.94% cvelistv5 2026-06-05
cve-2026-25815 Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option. LOW 3.2 0.09% cvelistv5 2026-06-17