Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-46954 PUBLISHED HIGH 7.2 0.49% cvelistv5 2026-07-23
cve-2026-46948 PUBLISHED MEDIUM 4.6 0.21% cvelistv5 2026-07-23
cve-2026-46943 PUBLISHED HIGH 7.4 0.34% cvelistv5 2026-07-23
cve-2026-46941 Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance) HIGH 7.5 0.33% cvelistv5 2026-08-17
cve-2026-46936 SUSE CVE CVE-2026-46936 UNKNOWN N/A 0.33% cvelistv5 2026-08-25
cve-2026-46924 PUBLISHED CRITICAL 9.8 0.51% cvelistv5 2026-07-23
cve-2026-46923 PUBLISHED HIGH 8.0 0.38% cvelistv5 2026-07-23
cve-2026-46917 SUSE CVE CVE-2026-46917 MEDIUM 5.3 0.39% cvelistv5 2026-09-11
cve-2026-46876 PUBLISHED CRITICAL 9.8 0.51% cvelistv5 2026-07-23
cve-2026-46863 Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are MySQL Server: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). HIGH 7.5 0.47% cvelistv5 2026-06-18
cve-2026-44248 Netty is an asynchronous, event-driven network application framework MEDIUM 5.3 0.72% cvelistv5 2026-09-11
cve-2026-4424 A flaw was found in libarchive HIGH 7.5 1.07% cvelistv5 2026-08-31
cve-2026-42779 Apache MINA: Apache MINA: Arbitrary Code Execution via Classname Allowlist Bypass CRITICAL 9.8 0.76% cvelistv5 2026-08-26
cve-2026-42587 Netty is an asynchronous, event-driven network application framework HIGH 7.5 1.05% cvelistv5 2026-09-18
cve-2026-42404 Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API MEDIUM 5.3 0.58% cvelistv5 2026-07-30
cve-2026-42403 org.apache.neethi: Apache Neethi: Denial of Service via circular policy references MEDIUM 6.5 0.80% cvelistv5 2026-07-30
cve-2026-42402 org.apache.neethi: Apache Neethi: Denial of Service via algorithmic complexity in policy normalization MEDIUM 6.5 0.74% cvelistv5 2026-07-02
cve-2026-42198 pgjdbc is an open source postgresql JDBC Driver HIGH 7.5 4.12% cvelistv5 2026-09-11
cve-2026-41989 SUSE CVE CVE-2026-41989 MEDIUM 6.3 0.19% cvelistv5 2026-09-02
cve-2026-41855 spring-jms: Spring Framework: Arbitrary code execution via deserialization in JMS message converters HIGH 8.1 0.48% cvelistv5 2026-07-22
cve-2026-4176 SUSE CVE CVE-2026-4176 UNKNOWN N/A 0.81% cvelistv5 2026-06-27
cve-2026-41409 Apache MINA: Apache MINA: Arbitrary code execution via incomplete deserialization fix CRITICAL 9.8 0.75% cvelistv5 2026-08-26
cve-2026-41254 Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize MEDIUM 6.1 0.44% cvelistv5 2026-08-10
cve-2026-4111 SUSE CVE CVE-2026-4111 HIGH 7.5 0.88% cvelistv5 2026-09-01
cve-2026-41044 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: Apache ActiveMQ: Arbitrary code execution via improper input validation in admin console HIGH 7.2 1.15% cvelistv5 2026-07-15
cve-2026-40976 Spring Boot: Spring Boot: Security bypass due to ineffective default web security CRITICAL 9.1 0.54% cvelistv5 2026-06-30
cve-2026-40192 Pillow is a Python imaging library HIGH 8.7 0.87% cvelistv5 2026-09-10
cve-2026-40179 SUSE CVE CVE-2026-40179 MEDIUM 5.4 0.31% cvelistv5 2026-08-31
cve-2026-39892 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers MEDIUM 6.9 0.76% cvelistv5 2026-09-10
cve-2026-35554 Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management MEDIUM 6.8 0.65% cvelistv5 2026-08-12