CVE Database
Every vulnerability CISA records as exploited in the wild — 1,722 of them — with severity, exploitation probability, remediation deadlines, and the ransomware groups recorded using each one.
Showing 61–120 of 1,722.
| CVE | Vulnerability | Severity | EPSS | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-20316 |
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC)
|
MEDIUM 5.3 | 11.2% | 29 Jul 2026 | CISA: known use |
| CVE-2025-68686 |
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS
|
MEDIUM 5.9 | 29.6% | 27 Jul 2026 | — |
| CVE-2026-16812 |
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista VeloCloud Orchestrator
|
CRITICAL 10 | 1.6% | 27 Jul 2026 | — |
| CVE-2026-16232 |
Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole
|
CRITICAL 9.1 | 72.1% | 22 Jul 2026 | — |
| CVE-2026-50522 |
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint
|
CRITICAL 9.8 | 85.4% | 22 Jul 2026 | — |
| CVE-2026-60137 |
WordPress Core SQL Injection Vulnerability
WordPress Core
|
MEDIUM 5.9 | 78.3% | 21 Jul 2026 | — |
| CVE-2026-63030 |
WordPress Core Interpretation Conflict Vulnerability
WordPress Core
|
CRITICAL 9.8 | 97.3% | 21 Jul 2026 | — |
| CVE-2026-0770 |
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Langflow Langflow
|
CRITICAL 9.8 | 63.8% | 21 Jul 2026 | — |
| CVE-2021-27137 |
DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT DD-WRT
|
HIGH 8.1 | 4% | 21 Jul 2026 | — |
| CVE-2026-58644 |
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint
|
CRITICAL 9.8 | 60.9% | 16 Jul 2026 | — |
| CVE-2026-25089 |
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox
|
CRITICAL 9.8 | 76.1% | 16 Jul 2026 | — |
| CVE-2026-39808 |
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox
|
CRITICAL 9.8 | 92.8% | 16 Jul 2026 | — |
| CVE-2026-46817 |
Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite
|
CRITICAL 9.8 | 13% | 15 Jul 2026 | — |
| CVE-2023-4346 |
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
KNX Association KNX Protocol Connection Authorization Option 1
|
HIGH 7.5 | 1.3% | 15 Jul 2026 | — |
| CVE-2026-56155 |
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services
|
HIGH 7.8 | 0.3% | 14 Jul 2026 | — |
| CVE-2026-56164 |
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint Server
|
MEDIUM 5.3 | 26.6% | 14 Jul 2026 | — |
| CVE-2026-15409 |
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances
|
CRITICAL 10 | 84.5% | 14 Jul 2026 | Incransom |
| CVE-2026-15410 |
SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall SMA1000 Appliances
|
HIGH 7.2 | 11.8% | 14 Jul 2026 | Incransom |
| CVE-2008-4128 |
Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS
|
MEDIUM 4.3 | 33.9% | 13 Jul 2026 | — |
| CVE-2026-56291 |
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Balbooa Forms
|
CRITICAL 9.8 | 14.9% | 10 Jul 2026 | — |
| CVE-2026-48939 |
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda iCagenda
|
CRITICAL 9.8 | 20.1% | 10 Jul 2026 | — |
| CVE-2026-48908 |
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder
|
CRITICAL 9.8 | 15.1% | 7 Jul 2026 | — |
| CVE-2026-55255 |
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Langflow Langflow
|
HIGH 8.4 | 0.9% | 7 Jul 2026 | — |
| CVE-2026-56290 |
Joomlack Page Builder Improper Access Control Vulnerability
Joomlack Page Builder
|
CRITICAL 9.8 | 30.9% | 7 Jul 2026 | — |
| CVE-2026-48282 |
Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion
|
CRITICAL 10 | 42.4% | 7 Jul 2026 | — |
| CVE-2026-45659 |
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server
|
HIGH 8.8 | 76.1% | 1 Jul 2026 | CISA: known use |
| CVE-2026-48558 |
SimpleHelp Authentication Bypass Vulnerability
SimpleHelp SimpleHelp
|
CRITICAL 10 | 64.3% | 29 Jun 2026 | — |
| CVE-2026-12569 |
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
PTC Windchill and FlexPLM
|
CRITICAL 9.8 | 40.6% | 25 Jun 2026 | CISA: known use |
| CVE-2026-20230 |
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Cisco Unified Communications Manager
|
HIGH 8.6 | 88.2% | 25 Jun 2026 | — |
| CVE-2025-67038 |
Lantronix EDS5000 Code Injection Vulnerability
Lantronix EDS5000
|
CRITICAL 9.8 | 19.3% | 23 Jun 2026 | — |
| CVE-2026-34910 |
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Ubiquiti UniFi OS
|
CRITICAL 10 | 87.5% | 23 Jun 2026 | — |
| CVE-2026-34909 |
Ubiquiti UniFi OS Path Traversal Vulnerability
Ubiquiti UniFi OS
|
CRITICAL 10 | 65% | 23 Jun 2026 | — |
| CVE-2026-34908 |
Ubiquiti UniFi OS Improper Access Control Vulnerability
Ubiquiti UniFi OS
|
CRITICAL 10 | 85.2% | 23 Jun 2026 | — |
| CVE-2026-20253 |
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Splunk Enterprise
|
CRITICAL 9.8 | 96.9% | 18 Jun 2026 | — |
| CVE-2026-48907 |
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory Joomla Content Editor
|
CRITICAL 9.8 | 78.1% | 16 Jun 2026 | — |
| CVE-2026-54420 |
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
LiteSpeed cPanel Plugin
|
HIGH 8.5 | 1.4% | 15 Jun 2026 | — |
| CVE-2026-20262 |
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Cisco Catalyst SD-WAN Manager
|
MEDIUM 6.5 | 28.2% | 15 Jun 2026 | — |
| CVE-2026-35273 |
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools
|
CRITICAL 9.8 | 95.5% | 12 Jun 2026 | CISA: known use |
| CVE-2026-10520 |
Ivanti Sentry OS Command Injection Vulnerability
Ivanti Sentry
|
CRITICAL 10 | 99.9% | 11 Jun 2026 | — |
| CVE-2026-11645 |
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8
|
HIGH 8.8 | 2.2% | 9 Jun 2026 | — |
| CVE-2026-7473 |
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Arista Extensible Operating System
|
MEDIUM 5.8 | 1.1% | 9 Jun 2026 | — |
| CVE-2026-20245 |
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Cisco Catalyst SD-WAN Manager
|
HIGH 7.8 | 25.3% | 9 Jun 2026 | — |
| CVE-2026-42271 |
BerriAI LiteLLM Command Injection Vulnerability
BerriAI LiteLLM
|
HIGH 8.8 | 83.6% | 8 Jun 2026 | — |
| CVE-2026-50751 |
Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway
|
CRITICAL 9.3 | 83.8% | 8 Jun 2026 | Qilin Rhysida +4 |
| CVE-2026-28318 |
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
SolarWinds Serv-U
|
HIGH 7.5 | 40% | 5 Jun 2026 | — |
| CVE-2026-45247 |
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit Full Page Cache Warmer
|
CRITICAL 9.8 | 27.5% | 3 Jun 2026 | — |
| CVE-2022-0492 |
Linux Kernel Improper Authentication Vulnerability
Linux Kernel
|
HIGH 7.8 | 5.5% | 2 Jun 2026 | — |
| CVE-2025-48595 |
Android Framework Integer Overflow Vulnerability
Android Framework
|
HIGH 8.4 | 1.7% | 2 Jun 2026 | — |
| CVE-2024-21182 |
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server
|
HIGH 7.5 | 74.2% | 1 Jun 2026 | — |
| CVE-2026-0257 |
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS
|
CRITICAL 9.1 | 95.2% | 29 May 2026 | Qilin |
| CVE-2026-48027 |
Nx Console Embedded Malicious Code Vulnerability
Nx Console
|
CRITICAL 9.8 | 1.9% | 27 May 2026 | Rhysida Spacebears +2 |
| CVE-2026-45321 |
TanStack Unspecified Vulnerability
TanStack TanStack
|
CRITICAL 9.6 | 2.3% | 27 May 2026 | CISA: known use |
| CVE-2026-8398 |
Daemon Tools Lite Embedded Malicious Code Vulnerability
Daemon Tools Lite
|
CRITICAL 9.8 | 1.5% | 27 May 2026 | — |
| CVE-2026-48172 |
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
LiteSpeed cPanel Plugin
|
CRITICAL 9.8 | 18.9% | 26 May 2026 | — |
| CVE-2026-9082 |
Drupal Core SQL Injection Vulnerability
Drupal Core
|
CRITICAL 9.8 | 90% | 22 May 2026 | — |
| CVE-2025-34291 |
Langflow Origin Validation Error Vulnerability
Langflow Langflow
|
HIGH 8.8 | 83.6% | 21 May 2026 | — |
| CVE-2026-34926 |
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Trend Micro Apex One
|
MEDIUM 6.7 | 12.7% | 21 May 2026 | — |
| CVE-2008-4250 |
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows
|
CRITICAL 9.8 | 98.8% | 20 May 2026 | — |
| CVE-2009-1537 |
Microsoft DirectX NULL Byte Overwrite Vulnerability
Microsoft DirectX
|
HIGH 8.8 | 51.2% | 20 May 2026 | — |
| CVE-2009-3459 |
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Adobe Acrobat and Reader
|
HIGH 8.8 | 86.6% | 20 May 2026 | — |
Catalogue and remediation deadlines from the CISA Known Exploited Vulnerabilities list; severity from NVD; exploitation probability from FIRST EPSS; ransomware group attribution from ransomware.live. Where a severity or EPSS score is missing, that vulnerability has not been enriched yet — the catalogue entry itself is still authoritative.