Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-33825 Microsoft Defender Insufficient Granularity of Access Control Vulnerability HIGH 7.8 0.40% cvelistv5 2026-04-22
cve-2026-33824 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. CRITICAL 9.8 1.62% cvelistv5 2026-09-25
cve-2026-33634 SUSE CVE CVE-2026-33634 UNKNOWN N/A 1.68% cvelistv5 2026-04-07
cve-2026-33497 Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading HIGH 7.5 2.03% cvelistv5 2026-06-17
cve-2026-3300 Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field CRITICAL 9.8 4.43% cvelistv5 2026-06-17
cve-2026-32475 WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability CRITICAL 9.0 1.71% cvelistv5 2026-08-20
cve-2026-32202 Microsoft Windows Protection Mechanism Failure Vulnerability MEDIUM 4.3 4.90% cvelistv5 2026-04-28
cve-2026-32201 Microsoft SharePoint Server Improper Input Validation Vulnerability MEDIUM 6.5 0.98% cvelistv5 2026-04-14
cve-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-... HIGH 7.8 3.44% cvelistv5 2026-09-08
cve-2026-3055 Citrix NetScaler Out-of-Bounds Read Vulnerability HIGH N/A 4.04% cvelistv5 2026-03-30
cve-2026-29059 Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly HIGH 7.5 2.12% cvelistv5 2026-06-17
cve-2026-28496 CVE-2026-28496 CRITICAL 9.4 1.91% cvelistv5
cve-2026-28409 WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection CRITICAL 10.0 3.85% cvelistv5 2026-06-17
cve-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability HIGH N/A 1.94% cvelistv5 2026-06-05
cve-2026-27971 Qwik affected by unauthenticated RCE via server$ Deserialization CRITICAL 9.8 2.88% cvelistv5 2026-06-17
cve-2026-2699 EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC) CRITICAL 9.8 3.18% cvelistv5 2026-06-17
cve-2026-2652 mlflow: mlflow: Authentication bypass allows unauthorized job management and data injection HIGH 8.6 1.41% cvelistv5 2026-07-08
cve-2026-26190 SUSE CVE CVE-2026-26190 UNKNOWN N/A 4.05% cvelistv5 2026-03-04
cve-2026-2614 mlflow: mlflow: Arbitrary file read via bypassed source path validation HIGH 7.5 3.21% cvelistv5 2026-08-27
cve-2026-25815 Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers "are supposed to enable" a non-default option that eliminates the weakness. However, that non-default option can disrupt functionality as shown in the "Managing FortiGates with private data encryption" document, and is therefore intentionally not a default option. LOW 3.2 0.09% cvelistv5 2026-06-17
cve-2026-25108 Soliton Systems K.K FileZen OS Command Injection Vulnerability HIGH N/A 5.07% cvelistv5 2026-02-24
cve-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability HIGH N/A 85.80% cvelistv5 2026-01-27
cve-2026-24423 SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability CRITICAL N/A 88.18% cvelistv5 2026-02-05
cve-2026-2441 chromium-browser: Use after free in CSS HIGH 8.8 55.10% cvelistv5 2026-06-28
cve-2026-24061 SUSE CVE CVE-2026-24061 UNKNOWN N/A 98.98% cvelistv5 2026-03-13
cve-2026-23760 SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability CRITICAL N/A 96.54% cvelistv5 2026-01-26
cve-2026-23744 REC in MCPJam inspector due to HTTP Endpoint exposes CRITICAL 9.8 67.52% cvelistv5 2026-06-17
cve-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability HIGH N/A 13.35% cvelistv5 2026-02-18
cve-2026-22679 CVE-2026-22679 CRITICAL 9.8 20.36% cvelistv5
cve-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability HIGH N/A 70.91% cvelistv5 2026-08-24