CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

CVE-2026-42208

Critical KEV

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An…

Published: May 08, 2026
Modified: May 08, 2026
Product: litellm litellm
EPSS: 37.37%
View Details
7.2

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

Published: May 07, 2026
Modified: May 07, 2026
Product: ivanti endpoint_manager_mobile
EPSS: 5.01%
View Details
9.8

CVE-2026-0300

Critical KEV

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if…

Published: May 06, 2026
Modified: May 07, 2026
Product: paloaltonetworks pan-os
EPSS: 5.29%
View Details
9.8

CVE-2026-41940

Critical KEV

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Published: Apr 29, 2026
Modified: May 04, 2026
Product: cpanel cpanel
EPSS: 67.01%
View Details
7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid…

Published: Apr 22, 2026
Modified: May 11, 2026
Product: suse manager_retail_branch_server
EPSS: 3.91%
View Details
7.8

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Published: Apr 14, 2026
Modified: Apr 23, 2026
EPSS: 4.85%
View Details
4.3

CVE-2026-32202

Medium KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Modified: Apr 28, 2026
Product: microsoft windows_server_2012
EPSS: 7.19%
View Details
6.5

CVE-2026-32201

Medium KEV

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Modified: Apr 14, 2026
Product: microsoft sharepoint_server
EPSS: 6.87%
View Details
8.6

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

Published: Apr 11, 2026
Modified: Apr 13, 2026
Product: adobe acrobat_dc
EPSS: 9.90%
View Details
9.8

CVE-2026-39987

Critical KEV

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication,…

Published: Apr 09, 2026
Modified: Apr 23, 2026
EPSS: 79.61%
View Details
8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An…

Published: Apr 07, 2026
Modified: Apr 16, 2026
Product: apache activemq
EPSS: 69.38%
View Details
9.8

CVE-2026-35616

Critical KEV

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Published: Apr 04, 2026
Modified: Apr 06, 2026
Product: fortinet forticlientems
EPSS: 43.21%
View Details
8.8

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Published: Apr 01, 2026
Modified: Apr 02, 2026
Product: google chrome
EPSS: 1.07%
View Details
7.8

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of…

Published: Mar 30, 2026
Modified: Apr 03, 2026
Product: trueconf trueconf
EPSS: 2.58%
View Details
8.8

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the…

Published: Mar 23, 2026
Modified: Mar 30, 2026
Product: telnyx telnyx
EPSS: 15.32%
View Details
9.8

CVE-2026-3055

Critical KEV

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Published: Mar 23, 2026
Modified: Mar 31, 2026
Product: citrix netscaler_application_delivery_controller
EPSS: 74.09%
View Details
9.8

CVE-2026-33017

Critical KEV

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of…

Published: Mar 20, 2026
Modified: Mar 26, 2026
Product: langflow langflow
EPSS: 45.69%
View Details
8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Published: Mar 13, 2026
Modified: Mar 13, 2026
Product: google chrome
EPSS: 0.69%
View Details
8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Published: Mar 13, 2026
Modified: Mar 25, 2026
Product: google chrome
EPSS: 0.39%
View Details
10.0

CVE-2026-20131

Critical KEV

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability…

Published: Mar 04, 2026
Modified: Mar 25, 2026
Product: cisco secure_firewall_management_center
EPSS: 1.72%
View Details
7.8

Memory corruption while using alignments for memory allocation.

Published: Mar 02, 2026
Modified: Mar 04, 2026
Product: qualcomm sxr2250p_firmware
EPSS: 0.23%
View Details
8.1

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column…

Published: Feb 25, 2026
Modified: Mar 04, 2026
Product: vmware aria_operations
EPSS: 2.10%
View Details
6.5

CVE-2026-20133

Medium KEV

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful…

Published: Feb 25, 2026
Modified: Apr 22, 2026
Product: cisco catalyst_sd-wan_manager
EPSS: 1.27%
View Details
7.5

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker…

Published: Feb 25, 2026
Modified: Apr 21, 2026
Product: cisco catalyst_sd-wan_manager
EPSS: 0.04%
View Details
Page 1 Next