Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-24308 Apache ZooKeeper: Apache ZooKeeper: Information disclosure via improper handling of configuration values LOW 3.3 1.18% cvelistv5 2026-07-14
cve-2026-24281 Apache ZooKeeper: Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing HIGH 7.4 0.63% cvelistv5 2026-07-03
cve-2026-24051 SUSE CVE CVE-2026-24051 UNKNOWN N/A 0.17% cvelistv5 2026-06-25
cve-2026-23903 org.apache.shiro/shiro-web: Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems MEDIUM 5.3 0.36% cvelistv5 2026-08-20
cve-2026-23865 SUSE CVE CVE-2026-23865 MEDIUM 5.3 0.14% cvelistv5 2026-08-28
cve-2026-2332 In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to t... HIGH 7.4 1.31% cvelistv5 2026-09-10
cve-2026-22747 Spring Security: Spring Security: User impersonation via malformed X.509 certificate Common Name (CN) values HIGH 8.1 0.30% cvelistv5 2026-06-30
cve-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views MEDIUM 6.5 0.39% cvelistv5 2026-07-02
cve-2026-22732 Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers MEDIUM 6.5 0.48% cvelistv5 2026-06-28
cve-2026-22029 SUSE CVE CVE-2026-22029 HIGH 8.0 0.88% cvelistv5 2026-06-03
cve-2026-21954 PUBLISHED MEDIUM 4.3 0.27% cvelistv5 2026-07-23
cve-2026-21953 PUBLISHED LOW 3.3 0.14% cvelistv5 2026-07-23
cve-2026-21452 MessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggering Unbounded EXT Payload Allocation HIGH 7.5 0.61% cvelistv5 2026-01-02
cve-2026-21441 urllib3 is an HTTP client library for Python HIGH 8.9 2.96% cvelistv5 2026-09-15
cve-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests HIGH 7.5 0.67% cvelistv5 2026-09-04
cve-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability HIGH 7.2 11.79% cvelistv5 2026-07-14
cve-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CRITICAL N/A 6.79% cvelistv5 2026-07-14
cve-2026-1229 github.com/cloudflare/circl/ecc/p384: CIRCL ecc/p384: Incorrect cryptographic calculations via specific inputs MEDIUM 5.6 0.39% cvelistv5 2026-06-28
cve-2026-1225 SUSE CVE CVE-2026-1225 MEDIUM 6.4 0.17% cvelistv5 2026-02-03
cve-2026-1002 io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files MEDIUM 5.3 0.39% cvelistv5 2026-09-02
cve-2026-0861 glibc: Integer overflow in memalign leads to heap corruption HIGH 8.1 0.39% cvelistv5 2026-08-31
cve-2026-0540 SUSE CVE CVE-2026-0540 UNKNOWN N/A 0.34% cvelistv5 2026-04-23
cve-2025-9900 SUSE CVE CVE-2025-9900 HIGH 7.8 0.97% cvelistv5 2026-08-29
cve-2025-9624 OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS HIGH 8.3 0.51% cvelistv5 2025-12-15
cve-2025-8916 org.bouncycastle: BouncyCastle denial of service MEDIUM 5.3 0.46% cvelistv5 2026-06-30
cve-2025-8869 pip: pip missing checks on symbolic link extraction MEDIUM 5.3 0.47% cvelistv5 2026-06-28
cve-2025-8837 SUSE CVE CVE-2025-8837 MEDIUM 6.6 0.23% cvelistv5 2026-08-30
cve-2025-7962 com.sun.mail/jakarta.mail: Jakarta Mail SMTP Injection Vulnerability MEDIUM 5.3 0.74% cvelistv5 2026-08-08
cve-2025-70873 SUSE CVE CVE-2025-70873 MEDIUM 4.3 0.30% cvelistv5 2026-09-01
cve-2025-68480 SUSE CVE CVE-2025-68480 MEDIUM 5.3 0.30% cvelistv5 2026-09-01