|
CVE-2026-28318
|
7.5 High
|
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
Remote
Low complexity
No user interaction
|
SolarWinds
|
Serv-U
|
2 days ago
|
|
CVE-2026-7473
|
6.9 Medium
|
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
Remote
Low complexity
No user interaction
|
Arista Networks
|
EOS
|
2 days ago
|
|
CVE-2026-3300
|
9.8 Critical
|
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
Remote
Low complexity
No user interaction
|
WPEverest
|
Everest Forms Pro
|
2 days ago
|
|
CVE-2026-20245
|
7.8 High
|
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
Low complexity
No user interaction
|
Cisco
|
Cisco Catalyst SD-WAN Manager
|
2 days ago
|
|
CVE-2025-30567
|
7.5 High
|
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
Remote
Low complexity
No user interaction
|
WP01
|
WP01
|
3 days ago
|
|
CVE-2024-27564
|
5.8 Medium
|
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy...
Remote
Low complexity
No user interaction
|
dirk1983
|
mm1.ltd source code
|
3 days ago
|
|
CVE-2024-45309
|
8.7 High
|
OneDev vulnerable to arbitrary file reading for unauthenticated user
Remote
Low complexity
No user interaction
|
theonedev
|
onedev
|
3 days ago
|
|
CVE-2022-24716
|
7.5 High
|
Path traversal in Icinga Web 2
Remote
Low complexity
No user interaction
|
Icinga
|
icingaweb2
|
4 days ago
|
|
CVE-2023-6875
|
9.8 Critical
|
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to...
Remote
Low complexity
No user interaction
|
wpexpertsio
|
POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications
|
4 days ago
|
|
CVE-2025-67303
|
7.5 High
|
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was...
Remote
Low complexity
No user interaction
|
Comfy-Org
|
ComfyUI-Manager
|
4 days ago
|
|
CVE-2024-6671
|
9.8 Critical
|
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
Remote
Low complexity
No user interaction
|
Progress Software Corporation
|
WhatsUp Gold
|
4 days ago
|
|
CVE-2023-22620
|
7.5 High
|
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an...
Remote
|
SecurePoint
|
UTM
|
4 days ago
|
|
CVE-2020-13379
|
8.2 High
|
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated...
Remote
Low complexity
No user interaction
|
Grafana
|
Grafana
|
4 days ago
|
|
CVE-2026-45247
|
9.3 Critical
|
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
Remote
Low complexity
No user interaction
|
Mirasvit
|
Full Page Cache Warmer for Magento 2
|
4 days ago
|
|
CVE-2025-48827
|
10.0 Critical
|
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP...
Remote
Low complexity
No user interaction
|
vBulletin
|
vBulletin
|
4 days ago
|
|
CVE-2026-8206
|
9.8 Critical
|
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
Remote
Low complexity
No user interaction
|
themeum
|
Kirki – Freeform Page Builder, Website Builder & Customizer
|
4 days ago
|
|
CVE-2023-6909
|
7.5 High
|
Path Traversal: '\..\filename' in mlflow/mlflow
Remote
Low complexity
No user interaction
|
mlflow
|
mlflow/mlflow
|
5 days ago
|
|
CVE-2022-4059
|
9.8 Critical
|
Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi
Remote
Low complexity
No user interaction
|
Unknown
|
Cryptocurrency Widgets Pack
|
5 days ago
|
|
CVE-2025-9316
|
6.9 Medium
|
N-central unauthenticated sessionID generation
Remote
Low complexity
No user interaction
|
N-able
|
N-central
|
5 days ago
|
|
CVE-2026-41176
|
9.2 Critical
|
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
Remote
Low complexity
No user interaction
|
rclone
|
rclone
|
5 days ago
|
|
CVE-2022-0492
|
7.8 High
|
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain...
Low complexity
No user interaction
|
Linux
|
kernel
|
5 days ago
|
|
CVE-2025-48595
|
8.4 High
|
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of...
Low complexity
No user interaction
|
Google
|
Android
|
5 days ago
|
|
CVE-2026-41089
|
9.8 Critical
|
Windows Netlogon Remote Code Execution Vulnerability
Remote
Low complexity
No user interaction
|
Microsoft
|
Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)
|
5 days ago
|
|
CVE-2024-21182
|
7.5 High
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...
Remote
Low complexity
No user interaction
|
Oracle Corporation
|
WebLogic Server
|
6 days ago
|
|
CVE-2023-43000
|
8.8 High
|
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari...
Remote
Low complexity
|
Apple
|
macOS, iOS and iPadOS, Safari
|
6 days ago
|