{"filters":{"page":{"type":"integer","description":"Page number (default: 1)","default":1,"minimum":1},"per_page":{"type":"integer","description":"Items per page, 1-100 (default: 25)","default":25,"minimum":1,"maximum":100},"q":{"type":"string","description":"Search CVE ID, title, vendor, or product","example":"Apache"},"since":{"type":"string","description":"Added-date window: 24h, 7d, or 30d","enum":["24h","7d","30d"],"example":"7d"},"in_cisa_kev":{"type":"boolean","description":"Filter to CVEs listed in the CISA KEV catalog"},"not_in_cisa_kev":{"type":"boolean","description":"Filter to CVEs not yet in the CISA KEV catalog"},"remote":{"type":"boolean","description":"CVSS network attack vector (AV:N)"},"low_complexity":{"type":"boolean","description":"CVSS low attack complexity (AC:L)"},"no_user_interaction":{"type":"boolean","description":"CVSS no user interaction (UI:N)"},"unauthenticated":{"type":"boolean","description":"CVSS no privileges required (PR:N / Au:N)"}},"kevs":[{"cve_id":"CVE-2026-2699","title":"EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)","vendor":"Progress","product":"ShareFile Storage Zones Controller","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.49424,"epss_percentile":0.98755,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-07-10T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-48939","title":"Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15","vendor":"icagenda.com","product":"iCagenda extension for Joomla","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01505,"epss_percentile":0.71365,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-10T17:00:25.732Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-56291","title":"Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1","vendor":"balbooa.com","product":"balbooa.com Balbooa Forms extension for Joomla","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00836,"epss_percentile":0.53473,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-10T17:00:25.732Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2022-50992","title":"Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet","vendor":"Weaver Network Co., Ltd.","product":"E-cology","cvss_score":8.7,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00705,"epss_percentile":0.4902,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-06T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-1207","title":"Potential SQL injection via raster lookups on PostGIS","vendor":"djangoproject","product":"Django","cvss_score":5.4,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.09436,"epss_percentile":0.9484,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-07-09T16:15:55.777Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-1125","title":"D-Link DIR-823X set_wifidog_settings sub_412E7C command injection","vendor":"D-Link","product":"DIR-823X","cvss_score":6.9,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.1438,"epss_percentile":0.962,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-02T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-4631","title":"Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.142,"epss_percentile":0.96158,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-08T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-39361","title":"Unauthenticated SQL Injection in graph_view.php in Cacti","vendor":"Cacti","product":"cacti","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.87575,"epss_percentile":0.99737,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-08T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-56290","title":"Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0","vendor":"joomlack.fr","product":"JoomlaCK.fr Page Builder CK extension for Joomla","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.02912,"epss_percentile":0.85373,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-07T17:00:54.263Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-55255","title":"Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow","vendor":"langflow-ai","product":"langflow","cvss_score":8.4,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":false,"unauthenticated":false},"epss_score":0.00467,"epss_percentile":0.37303,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-07T17:00:54.263Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-48908","title":"Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2","vendor":"joomshaper.net","product":"SP Page Builder extension for Joomla","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01569,"epss_percentile":0.72455,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-07T17:00:54.263Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-48282","title":"ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)","vendor":"Adobe","product":"ColdFusion","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.28583,"epss_percentile":0.97907,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-07-02T18:20:12.605Z","ahead_of_cisa_kev":{"unit":"day","count":5},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-8451","title":"Insufficient input validation leading to memory overread","vendor":"NetScaler","product":"ADC, Gateway","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00502,"epss_percentile":0.39415,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-01T21:50:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-45659","title":"Microsoft SharePoint Remote Code Execution Vulnerability","vendor":"Microsoft","product":"Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.03219,"epss_percentile":0.86732,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-07-01T19:00:06.901Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-8037","title":"OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF","vendor":"Progress Software","product":"LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF","cvss_score":9.6,"cvss_severity":"CRITICAL","cvss_highlights":{"network":false,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.29641,"epss_percentile":0.97973,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-07-01T14:51:57.959Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-52813","title":"Gogs: Path Traversal in organization name results in RCE through Git hooks","vendor":"gogs","product":"gogs","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01107,"epss_percentile":0.61988,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-30T16:02:32.752Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-46817","title":"Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are...","vendor":"Oracle Corporation","product":"Oracle Payments","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00677,"epss_percentile":0.47967,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-29T15:45:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-48558","title":"SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification","vendor":"SimpleHelp","product":"SimpleHelp","cvss_score":9.5,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.0116,"epss_percentile":0.63396,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-29T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-8054","title":"Unauthenticated SQL Injection in dotCMS Publish Audit API","vendor":"dotCMS","product":"dotCMS Core","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01584,"epss_percentile":0.72695,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-27T14:36:50.219Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-6567","title":"The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including,...","vendor":"thimpress","product":"LearnPress – WordPress LMS Plugin","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.51394,"epss_percentile":0.98812,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-27T14:36:38.919Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-12569","title":"Remote Code Execution (RCE) vulnerability in Windchill PDMlink","vendor":"PTC","product":"Windchill PDMLink, FlexPLM","cvss_score":9.3,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01247,"epss_percentile":0.65828,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-25T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-20230","title":"Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability","vendor":"Cisco","product":"Cisco Unified Communications Manager","cvss_score":8.6,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.41694,"epss_percentile":0.9852,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-23T22:20:36.536Z","ahead_of_cisa_kev":{"unit":"day","count":2},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2025-67038","title":"An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication...","vendor":"Lantronix","product":"EDS5000","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00889,"epss_percentile":0.55116,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-23T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2021-30128","title":"Unsafe deserialization in Apache OFBiz","vendor":"Apache Software Foundation","product":"Apache OFBiz","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.81079,"epss_percentile":0.99588,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-12T00:32:50.259Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-4020","title":"Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API","vendor":"RocketGenius","product":"Gravity SMTP","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.39704,"epss_percentile":0.98451,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-12T00:35:27.121Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-27222","title":"TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't...","vendor":"Rocket Software","product":"TRUfusion Enterprise","cvss_score":8.6,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01895,"epss_percentile":0.77188,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-31059","title":"Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.","vendor":"Repetier","product":"Repetier Server","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.05574,"epss_percentile":0.91957,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2017-15363","title":"Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension...","vendor":"Luracast","product":"Restler","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.13649,"epss_percentile":0.96038,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2017-9833","title":"/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of \"../..\" using the FILECAMERA variable (sent by GET) to read files with root privileges....","vendor":"Boa","product":"Boa Web Server","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.68243,"epss_percentile":0.99248,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-32738","title":"CyberPower PowerPanel Enterprise SQL Injection","vendor":"CyberPower","product":"CyberPower PowerPanel Enterprise","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.04515,"epss_percentile":0.90407,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-25485","title":"CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.","vendor":"CuppaCMS","product":"CuppaCMS","cvss_score":7.8,"cvss_severity":"HIGH","cvss_highlights":{"network":false,"no_user_interaction":false,"low_complexity":true,"unauthenticated":true},"epss_score":0.07927,"epss_percentile":0.94042,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-27497","title":"Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.","vendor":"Linksys","product":"E2000","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":false,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.2646,"epss_percentile":0.97769,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-31750","title":"SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.","vendor":"f-logic","product":"datacube3","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.1942,"epss_percentile":0.97039,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2020-24949","title":"Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server...","vendor":"PHP-Fusion","product":"PHP-Fusion","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.67289,"epss_percentile":0.9922,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-25486","title":"CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.","vendor":"CuppaCMS","product":"CuppaCMS","cvss_score":7.8,"cvss_severity":"HIGH","cvss_highlights":{"network":false,"no_user_interaction":false,"low_complexity":true,"unauthenticated":true},"epss_score":0.09966,"epss_percentile":0.95047,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-48907","title":"Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5","vendor":"joomlacontenteditor.net","product":"Joomla Content Editor (JCE) extension for Joomla","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.80425,"epss_percentile":0.99576,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-16T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-39813","title":"A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to...","vendor":"Fortinet","product":"FortiSandbox, FortiSandbox Cloud","cvss_score":9.1,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.16739,"epss_percentile":0.96664,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-15T12:48:52.791Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-39796","title":"SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the...","vendor":"WBCE","product":"WBCE CMS","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.06096,"epss_percentile":0.92581,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-14T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-20262","title":"Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability","vendor":"Cisco","product":"Cisco Catalyst SD-WAN Manager","cvss_score":6.5,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.07683,"epss_percentile":0.93889,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2021-31805","title":"Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.","vendor":"Apache Software Foundation","product":"Apache Struts","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.85315,"epss_percentile":0.9969,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-12T00:32:51.325Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-53435","title":"In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins...","vendor":"Jenkins Project","product":"Jenkins","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.14907,"epss_percentile":0.96309,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-15T09:02:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-20253","title":"Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise","vendor":"Splunk","product":"Splunk Enterprise","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.88171,"epss_percentile":0.99749,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-15T05:15:25.399Z","ahead_of_cisa_kev":{"unit":"day","count":3},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2022-38296","title":"Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.","vendor":"Cuppa CMS","product":"Cuppa CMS","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.0373,"epss_percentile":0.88535,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-13T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-54420","title":"LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web...","vendor":"LiteSpeed Technologies","product":"cPanel Plugin","cvss_score":8.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":false,"unauthenticated":false},"epss_score":0.01261,"epss_percentile":0.66182,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-14T04:01:15.820Z","ahead_of_cisa_kev":{"unit":"hour","count":20},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2020-6286","title":"The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,...","vendor":"SAP SE","product":"SAP NetWeaver AS JAVA (LM Configuration Wizard)","cvss_score":5.3,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.28312,"epss_percentile":0.97889,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-12T00:32:46.583Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-39808","title":"A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through...","vendor":"Fortinet","product":"FortiSandbox, FortiSandbox PaaS","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.48668,"epss_percentile":0.98733,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-12T13:59:12.791Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-35273","title":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions...","vendor":"Oracle Corporation","product":"PeopleSoft Enterprise PeopleTools","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.9233,"epss_percentile":0.99811,"used_in_malware":"yes","virtual_patch":true,"added_date":"2026-06-11T20:20:23.651Z","ahead_of_cisa_kev":{"unit":"hour","count":4},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-10795","title":"UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc","vendor":"davidanderson","product":"UpdraftPlus: WP Backup & Migration Plugin","cvss_score":8.1,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":false,"unauthenticated":true},"epss_score":0.03578,"epss_percentile":0.88024,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-11T07:20:32.076Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-5821","title":"Case Theme User <= 1.0.3 - Authentication Bypass via Social Login","vendor":"Case-Themes","product":"Case Theme User","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00714,"epss_percentile":0.49301,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-11T00:20:49.551Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-5027","title":"Langflow - Path Traversal Arbitrary File Write via upload_user_file","vendor":"langflow-ai","product":"langflow","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.02104,"epss_percentile":0.79556,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-10T16:20:36.494Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-10520","title":"An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to...","vendor":"ivanti","product":"Sentry","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.99041,"epss_percentile":0.99926,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-10T09:50:00.000Z","ahead_of_cisa_kev":{"unit":"day","count":1},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2021-33544","title":"UDP Technology/Geutebrück camera devices: command injection leading to RCE","vendor":"Geutebrück","product":"E2 Series, Encoder G-Code","cvss_score":7.2,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.94622,"epss_percentile":0.99846,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-08T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-8085","title":"Ditty < 3.1.58 - Unauthenticated SSRF","vendor":"Unknown","product":"Ditty","cvss_score":8.6,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.16399,"epss_percentile":0.96593,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-08T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-61666","title":"Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File","vendor":"traccar","product":"traccar","cvss_score":8.7,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01196,"epss_percentile":0.64368,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-08T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-11645","title":"Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox...","vendor":"Google","product":"Chrome","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":false,"low_complexity":true,"unauthenticated":true},"epss_score":0.01654,"epss_percentile":0.73745,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-09T13:20:17.736Z","ahead_of_cisa_kev":{"unit":"hour","count":5},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-34910","title":"A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a...","vendor":"Ubiquiti Inc","product":"UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.78555,"epss_percentile":0.99538,"used_in_malware":"unknown","virtual_patch":true,"added_date":"2026-06-09T08:18:00.000Z","ahead_of_cisa_kev":{"unit":"day","count":14},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-34909","title":"A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the...","vendor":"Ubiquiti Inc","product":"UniFi OS Server, Express, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.02269,"epss_percentile":0.80999,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-09T07:29:00.000Z","ahead_of_cisa_kev":{"unit":"day","count":14},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-34908","title":"A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized...","vendor":"Ubiquiti Inc","product":"UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.02452,"epss_percentile":0.82491,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-09T07:27:00.000Z","ahead_of_cisa_kev":{"unit":"day","count":14},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2017-10974","title":"Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of...","vendor":"Yaws","product":"Yaws","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.81028,"epss_percentile":0.99586,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-3577","title":"An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker...","vendor":"Motorola","product":"Binatone Hubble Cameras","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":false,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.59893,"epss_percentile":0.99019,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-8752","title":"WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability","vendor":"Smart HMI","product":"WebIQ","cvss_score":9.3,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.11759,"epss_percentile":0.95561,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-4490","title":"WP Job Portal < 2.0.6 - Unauthenticated SQLi","vendor":"Unknown","product":"WP Job Portal","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.03122,"epss_percentile":0.86263,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-20166","title":"Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router...","vendor":"Netgear","product":"RAX43","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":false,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.02195,"epss_percentile":0.80313,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-3801","title":"IBAX go-ibax rowsInfo sql injection","vendor":"IBAX","product":"go-ibax","cvss_score":6.3,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.30082,"epss_percentile":0.97989,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-27358","title":"The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API...","vendor":"Grafana Labs","product":"Grafana","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.83042,"epss_percentile":0.99636,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-34121","title":"Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.","vendor":"Cuppa CMS","product":"Cuppa CMS","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.03059,"epss_percentile":0.86001,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-34753","title":"A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote...","vendor":"Schneider Electric","product":"SpaceLogic C-Bus Home Controller","cvss_score":8.8,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.71084,"epss_percentile":0.99328,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-1405","title":"Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload","vendor":"franchidesign","product":"Slider Future","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.03177,"epss_percentile":0.86493,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-24227","title":"Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure","vendor":"Unknown","product":"Patreon WordPress","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.05879,"epss_percentile":0.92323,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-41569","title":"SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows...","vendor":"SAS Institute Inc.","product":"SAS/Intrnet","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.07845,"epss_percentile":0.93973,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-55457","title":"MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by...","vendor":"MasterSAM","product":"Star Gate 11","cvss_score":6.5,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.03012,"epss_percentile":0.8579,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-39713","title":"A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.","vendor":"Rocket.Chat","product":"Rocket.Chat","cvss_score":8.6,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.03201,"epss_percentile":0.86581,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-07T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-42271","title":"LiteLLM: Authenticated command execution via MCP stdio test endpoints","vendor":"BerriAI","product":"litellm","cvss_score":8.7,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.80188,"epss_percentile":0.99572,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-08T18:00:45.030Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-50751","title":"User Authentication Bypass in VPN Remote Access and Mobile Access","vendor":"checkpoint","product":"Quantum Security Gateway, Spark Firewalls","cvss_score":9.3,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.70099,"epss_percentile":0.99298,"used_in_malware":"yes","virtual_patch":false,"added_date":"2026-06-08T14:20:34.968Z","ahead_of_cisa_kev":{"unit":"hour","count":6},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2022-1390","title":"Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read","vendor":"Unknown","product":"Admin Word Count Column","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.22133,"epss_percentile":0.97377,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-06T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-29078","title":"The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view...","vendor":"mde","product":"ejs","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.32386,"epss_percentile":0.98121,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-06T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-27670","title":"Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.","vendor":"Appspace","product":"Appspace 6.2.4","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.61274,"epss_percentile":0.99051,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-06T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-21805","title":"An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted...","vendor":"Advantech","product":"R-SeeNet","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.69631,"epss_percentile":0.99283,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-06T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2021-4458","title":"Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection","vendor":"webnus","product":"Modern Events Calendar Lite","cvss_score":5.9,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":false,"unauthenticated":true},"epss_score":0.00354,"epss_percentile":0.27413,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-06T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-30567","title":"WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability","vendor":"WP01","product":"WP01","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.02628,"epss_percentile":0.8364,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-27564","title":"pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy...","vendor":"dirk1983","product":"mm1.ltd source code","cvss_score":5.8,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.40637,"epss_percentile":0.98477,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-45309","title":"OneDev vulnerable to arbitrary file reading for unauthenticated user","vendor":"theonedev","product":"onedev","cvss_score":8.7,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.24822,"epss_percentile":0.97638,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-6875","title":"The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to...","vendor":"wpexpertsio","product":"POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.90339,"epss_percentile":0.99785,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-04T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-24716","title":"Path traversal in Icinga Web 2","vendor":"Icinga","product":"icingaweb2","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.89378,"epss_percentile":0.99766,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-04T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2020-13379","title":"The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated...","vendor":"Grafana","product":"Grafana","cvss_score":8.2,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.99856,"epss_percentile":0.9996,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-04T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-22620","title":"An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an...","vendor":"SecurePoint","product":"UTM","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":false,"low_complexity":false,"unauthenticated":true},"epss_score":0.03888,"epss_percentile":0.88957,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-04T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-67303","title":"An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was...","vendor":"Comfy-Org","product":"ComfyUI-Manager","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.01361,"epss_percentile":0.68363,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-04T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2024-6671","title":"WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability","vendor":"Progress Software Corporation","product":"WhatsUp Gold","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.14886,"epss_percentile":0.9629,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-04T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-28318","title":"SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability","vendor":"SolarWinds","product":"Serv-U","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.10659,"epss_percentile":0.95258,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T18:00:36.180Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-7473","title":"Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass","vendor":"Arista Networks","product":"EOS","cvss_score":6.9,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.00836,"epss_percentile":0.5333,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T16:40:23.554Z","ahead_of_cisa_kev":{"unit":"day","count":4},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2026-3300","title":"Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field","vendor":"WPEverest","product":"Everest Forms Pro","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.40992,"epss_percentile":0.98489,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T09:20:13.225Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-20245","title":"Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability","vendor":"Cisco","product":"Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager","cvss_score":7.8,"cvss_severity":"HIGH","cvss_highlights":{"network":false,"no_user_interaction":true,"low_complexity":true,"unauthenticated":false},"epss_score":0.25323,"epss_percentile":0.97692,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-05T06:24:20.000Z","ahead_of_cisa_kev":{"unit":"day","count":4},"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2025-9316","title":"N-central unauthenticated sessionID generation","vendor":"N-able","product":"N-central","cvss_score":6.9,"cvss_severity":"MEDIUM","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.37335,"epss_percentile":0.98338,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2022-4059","title":"Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi","vendor":"Unknown","product":"Cryptocurrency Widgets Pack","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.04756,"epss_percentile":0.90783,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2023-6909","title":"Path Traversal: '\\..\\filename' in mlflow/mlflow","vendor":"mlflow","product":"mlflow/mlflow","cvss_score":7.5,"cvss_severity":"HIGH","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.89716,"epss_percentile":0.99773,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-41176","title":"Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution","vendor":"rclone","product":"rclone","cvss_score":9.2,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.34734,"epss_percentile":0.98221,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T00:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-45247","title":"Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection","vendor":"Mirasvit","product":"Full Page Cache Warmer for Magento 2","cvss_score":9.3,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.27546,"epss_percentile":0.97834,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T18:00:21.829Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":false},{"cve_id":"CVE-2025-48828","title":"Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting...","vendor":"vBulletin","product":"vBulletin","cvss_score":9.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":false,"unauthenticated":true},"epss_score":0.48358,"epss_percentile":0.98719,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2025-05-27T12:00:00.000Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2025-48827","title":"vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP...","vendor":"vBulletin","product":"vBulletin","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.69649,"epss_percentile":0.99282,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T10:06:54.268Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true},{"cve_id":"CVE-2026-8206","title":"Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'","vendor":"themeum","product":"Kirki – Freeform Page Builder, Website Builder & Customizer","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_highlights":{"network":true,"no_user_interaction":true,"low_complexity":true,"unauthenticated":true},"epss_score":0.0126,"epss_percentile":0.66006,"used_in_malware":"unknown","virtual_patch":false,"added_date":"2026-06-03T08:20:48.478Z","ahead_of_cisa_kev":null,"not_yet_in_cisa_kev":true}],"pagination":{"current_page":1,"total_pages":27,"total_count":2662,"per_page":100,"next_page":2,"prev_page":null,"first_page":1,"last_page":27}}