Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2026-45536 netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling MEDIUM 4.0 N/A cvelistv5 2026-08-04
cve-2026-45416 netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake HIGH 7.5 N/A cvelistv5 2026-09-03
cve-2026-44249 netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation HIGH 8.1 N/A cvelistv5 2026-09-04
cve-2026-44161 Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http` HIGH 7.2 N/A cvelistv5 2026-07-09
cve-2026-44160 Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward` HIGH 7.5 N/A cvelistv5 2026-07-09
cve-2026-44025 Fluentd: Exposure of Sensitive Information via Monitor Agent API HIGH 7.5 N/A cvelistv5 2026-07-09
cve-2026-44024 fluentd: Fluentd: Remote Code Execution via arbitrary file write due to insufficient tag validation CRITICAL 9.8 N/A cvelistv5 2026-07-13
cve-2026-42505 SUSE CVE CVE-2026-42505 MEDIUM 5.3 N/A cvelistv5 2026-09-11
cve-2026-41990 SUSE CVE CVE-2026-41990 LOW 3.6 N/A cvelistv5 2026-08-31
cve-2026-41635 Apache MINA: Apache MINA: Arbitrary code execution via classname allowlist bypass CRITICAL 9.8 N/A cvelistv5 2026-08-26
cve-2026-4035 python-mlflow: MLflow: Sensitive credential exfiltration via environment variable resolution in AI Gateway secrets HIGH 7.7 N/A cvelistv5 2026-08-13
cve-2026-34479 org.apache.logging.log4j/log4j-1.2-api: Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping MEDIUM 5.3 N/A cvelistv5 2026-09-04
cve-2026-34477 org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification MEDIUM 6.8 N/A cvelistv5 2026-09-04
cve-2026-3198 mlflow: MLflow: Information disclosure via insufficient authorization checks in Gateway API endpoints MEDIUM 6.5 N/A cvelistv5 2026-06-08
cve-2026-19880 ch.qos.logback/logback-classic: Logback-classic: Path traversal allows arbitrary log file creation MEDIUM 6.5 0.33% cvelistv5 2026-08-31
cve-2026-17544 SUSE CVE CVE-2026-17544 CRITICAL 9.1 0.43% cvelistv5 2026-08-21
cve-2026-14456 openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server HIGH 7.5 0.73% cvelistv5 2026-08-27
cve-2026-14363 Cargo: Mediawiki Cargo Extension: SQL Injection vulnerability HIGH 7.3 0.52% cvelistv5 2026-07-07
cve-2026-14358 Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title MEDIUM 6.9 0.30% cvelistv5 2026-07-10
cve-2026-13758 CryptX: CryptX for Perl: Message forgery via non-constant time AEAD tag comparison MEDIUM 5.3 0.40% cvelistv5 2026-06-30
cve-2026-13707 Session fixation attacks on improperly configured OAuth 1.0a tools NONE N/A 0.34% cvelistv5 2026-07-01
cve-2026-13706 UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG NONE N/A 0.48% cvelistv5 2026-07-01
cve-2026-13484 mlflow: MLflow: Unauthorized access and data manipulation via missing API authorization MEDIUM 5.0 0.50% cvelistv5 2026-07-01
cve-2026-13006 logback-core: Logback-core: Arbitrary Code Execution via Malicious Configuration or Environment Variable MEDIUM 6.0 0.18% cvelistv5 2026-06-27
cve-2026-12590 body-parser: body-parser: Denial of Service via invalid limit option MEDIUM 5.9 0.41% cvelistv5 2026-07-10
cve-2026-10803 mlflow: MLflow: Use of weak hash in Dataset Digest Computation LOW 2.5 0.10% cvelistv5 2026-06-28
cve-2023-6918 libssh: Missing checks for return values for digests LOW 3.7 1.41% cvelistv5 2025-11-21
cve-2023-48795 ssh: Prefix truncation attack on Binary Packet Protocol (BPP) MEDIUM 5.9 93.31% cvelistv5 2026-09-02
cve-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability HIGH N/A N/A cvelistv5 2026-09-14
cve-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability CRITICAL 10.0 N/A cvelistv5 2026-09-11