|
cve-2026-41176
|
github.com/rclone/rclone: Rclone: Unauthorized access to administrative functions through unauthenticated Remote Control endpoint. |
CRITICAL
|
9.8
|
3.22%
|
cvelistv5 |
2026-06-30 |
|
cve-2026-41091
|
Microsoft Defender Link Following Vulnerability |
HIGH
|
N/A
|
0.44%
|
cvelistv5 |
2026-05-20 |
|
cve-2026-41089
|
Windows Netlogon Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
0.97%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-4020
|
Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API |
HIGH
|
7.5
|
2.24%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-39987
|
Marimo Remote Code Execution Vulnerability |
HIGH
|
N/A
|
37.87%
|
cvelistv5 |
2026-04-23 |
|
cve-2026-39813
|
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests. |
CRITICAL
|
9.8
|
0.72%
|
cvelistv5 |
2026-06-18 |
|
cve-2026-39808
|
Fortinet FortiSandbox OS Command Injection Vulnerability |
HIGH
|
N/A
|
47.36%
|
cvelistv5 |
2026-07-16 |
|
cve-2026-3965
|
whyour qinglong API express.ts protection mechanism |
MEDIUM
|
6.3
|
0.47%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-3910
|
chromium-browser: Inappropriate implementation in V8 |
HIGH
|
8.8
|
1.03%
|
cvelistv5 |
2026-06-28 |
|
cve-2026-3909
|
SUSE CVE CVE-2026-3909 |
HIGH
|
8.8
|
0.70%
|
cvelistv5 |
2026-09-02 |
|
cve-2026-35616
|
Fortinet FortiClient EMS Improper Access Control Vulnerability |
HIGH
|
N/A
|
9.10%
|
cvelistv5 |
2026-04-06 |
|
cve-2026-35273
|
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability |
CRITICAL
|
N/A
|
9.44%
|
cvelistv5 |
2026-06-12 |
|
cve-2026-3502
|
TrueConf Client Download of Code Without Integrity Check Vulnerability |
HIGH
|
N/A
|
0.33%
|
cvelistv5 |
2026-04-02 |
|
cve-2026-34926
|
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability |
HIGH
|
N/A
|
0.54%
|
cvelistv5 |
2026-05-21 |
|
cve-2026-34910
|
Ubiquiti UniFi OS Improper Input Validation Vulnerability |
HIGH
|
N/A
|
45.77%
|
cvelistv5 |
2026-06-23 |
|
cve-2026-34909
|
Ubiquiti UniFi OS Path Traversal Vulnerability |
HIGH
|
N/A
|
1.79%
|
cvelistv5 |
2026-06-23 |
|
cve-2026-34908
|
Ubiquiti UniFi OS Improper Access Control Vulnerability |
HIGH
|
N/A
|
15.21%
|
cvelistv5 |
2026-06-23 |
|
cve-2026-34621
|
Adobe Acrobat and Reader Prototype Pollution Vulnerability |
HIGH
|
8.6
|
2.18%
|
cvelistv5 |
2026-04-13 |
|
cve-2026-34234
|
CtrlPanel: Unauthenticated RCE using installer script |
CRITICAL
|
10.0
|
4.54%
|
cvelistv5 |
2026-07-24 |
|
cve-2026-34197
|
org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: RCE via crafted discovery URI in Jolokia JMX-HTTP bridge |
HIGH
|
8.8
|
15.49%
|
cvelistv5 |
2026-08-17 |
|
cve-2026-33825
|
Microsoft Defender Elevation of Privilege Vulnerability |
HIGH
|
7.8
|
0.40%
|
cvelistv5 |
2026-09-25 |
|
cve-2026-33634
|
Aquasecurity Trivy Embedded Malicious Code Vulnerability |
HIGH
|
N/A
|
1.68%
|
cvelistv5 |
2026-03-26 |
|
cve-2026-33017
|
Langflow Code Injection Vulnerability |
HIGH
|
N/A
|
24.75%
|
cvelistv5 |
2026-03-25 |
|
cve-2026-3300
|
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field |
CRITICAL
|
9.8
|
4.43%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-32202
|
Windows Shell Spoofing Vulnerability |
MEDIUM
|
4.3
|
4.90%
|
cvelistv5 |
2026-09-25 |
|
cve-2026-32201
|
Microsoft SharePoint Server Spoofing Vulnerability |
MEDIUM
|
6.5
|
0.98%
|
cvelistv5 |
2026-09-25 |
|
cve-2026-31431
|
kernel: crypto: algif_aead - Revert to operating out-of-place |
HIGH
|
7.8
|
3.44%
|
cvelistv5 |
2026-09-01 |
|
cve-2026-3055
|
Citrix NetScaler Out-of-Bounds Read Vulnerability |
HIGH
|
N/A
|
4.04%
|
cvelistv5 |
2026-03-30 |
|
cve-2026-28318
|
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability |
HIGH
|
N/A
|
1.94%
|
cvelistv5 |
2026-06-05 |
|
cve-2026-25815
|
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option. |
LOW
|
3.2
|
0.09%
|
cvelistv5 |
2026-06-17 |