<\/head>

Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

871
CISA KEV
256
Exploits
535
Proof-of-Concept
19.3%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

19 Aug/26
CVE-2026-72530
CRITICAL

This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.

CVSS 9.0
EPSS 1.8%
KEV Pred in 21d
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-94 PoC
17 Aug/26
CVE-2026-64849
CRITICAL

This vulnerability is a server-side request forgery (SSRF) caused by improper validation of webhook URLs in MLflow's webhook testing endpoint. The root cause lies in inconsistent URL validation: the _validate_webhook_url() function only checks the original URL, while subsequent HTTP requests follow redirects and re-resolve hostnames without enforcing address pinning. This flaw affects the POST /api/2.0/mlflow/webhooks/{id}/test endpoint, specifically in the webhook URL validation and delivery components.

CVSS 9.3
EPSS 16.4%
KEV Pred in 19d
Product mlflow mlflow
CVSS v3.1 KEV CWE-918 PoC
13 Aug/26
CVE-2026-73570
HIGH

This vulnerability is a command injection flaw rooted in improper sanitization of untrusted input within the SNMP notification processing component of Zimbra Collaboration Suite (ZCS). Specifically, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, maliciously crafted SMTP requests can inject operating system commands. The flaw arises from inadequate input validation during the handling of SNMP notifications in affected ZCS versions prior to 10.1.20.

CVSS 8.9
EPSS 20.5%
KEV Pred in 15d
Product Zimbra Collaboration zimbra
CVSS v3.1 KEV CWE-78 PoC
12 Aug/26
CVE-2026-66384
MEDIUM

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

CVSS 5.3
EPSS 0.5%
KEV Pred in 14d
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-22 PoC
06 Aug/26
CVE-2026-65400
CRITICAL

This vulnerability is an authentication bypass issue rooted in improper state management within the Screen Sharing service of Apple macOS. The flaw allows network-based attackers to circumvent authentication controls by exploiting how session state is handled during the authentication process. The affected component is the Screen Sharing feature across multiple macOS versions, where authentication validation does not adequately verify credential legitimacy.

CVSS 9.8
EPSS 9.9%
KEV Pred in 8d
Product Apple macOS apple
CVSS v3.1 KEV CWE-287 PoC
01 Aug/26
CVE-2026-18556
HIGH

This vulnerability is an authentication bypass in N-able N-central caused by improper validation of authentication mechanisms, allowing an attacker to circumvent normal authentication controls. The root cause lies in an alternate path or channel within the authentication process that fails to enforce required credentials. This flaw affects the authentication component of N-central versions through 2026.1, enabling unauthorized access through this bypass vector.

CVSS 7.4
EPSS 40.2%
KEV Pred in 3d
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
30 Jul/26
CVE-2026-59310
CRITICAL

This vulnerability is a directory traversal flaw within the VMware vCenter Syslog server component of VMware Cloud Foundation. The root cause lies in insufficient validation of file path inputs, allowing crafted requests to access arbitrary filesystem locations. This improper sanitization enables manipulation of file paths processed by the Syslog server, exposing underlying system directories.

CVSS 9.8
EPSS 45.9%
KEV Pred N/A
Product VMware Cloud Foundation vmware
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
17 Jul/26
CVE-2026-9198
CRITICAL

This vulnerability is a chained authentication bypass and arbitrary code execution flaw in IBM Langflow OSS versions 1.0.0 through 1.10.0. The root cause lies in the /api/v1/auto_login endpoint, which mints SUPERUSER tokens without authentication, combined with the /api/v1/validate/code endpoint that executes user-supplied code via the unsafe use of exec(). These two components together enable unauthorized execution of arbitrary commands on default Langflow deployments.

CVSS 9.8
EPSS 34.7%
KEV Pred 66%
Product IBM Langflow OSS ibm
CVSS v3.1 KEV CWE-94 Exploit PoC
14 Jul/26
CVE-2026-15410
HIGH

This vulnerability is a post-authentication code injection flaw rooted in improper control over code generation within the SonicWall SMA1000 Appliance Management Console (AMC). The vulnerability arises due to insufficient validation of user-supplied input that is incorporated into command execution contexts. The affected component is the AMC interface, which processes administrative commands and configurations.

CVSS 7.2
EPSS 11.8%
KEV Pred 64%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-94 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-55040
CRITICAL

This vulnerability is an authentication bypass caused by weak authentication mechanisms within Microsoft Office SharePoint. The root cause lies in improper validation of authentication tokens or credentials, allowing unauthorized access. The affected component is the authentication subsystem of Microsoft SharePoint Enterprise Server 2016 and related versions, which fails to enforce proper security checks over network requests.

CVSS 9.1
EPSS 39.7%
KEV Pred 71%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-1390 PoC RANSOMWARE
14 Jul/26
CVE-2026-56164
MEDIUM

This vulnerability is an authentication bypass caused by missing authentication checks on critical functions within Microsoft Office SharePoint. The root cause stems from insufficient access control enforcement in the SharePoint Enterprise Server 2016 component, allowing unauthenticated network requests to invoke privileged operations. The flaw specifically affects the authentication mechanism protecting sensitive SharePoint server functions.

CVSS 5.3
EPSS 26.6%
KEV Pred 79%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-306 PoC RANSOMWARE
09 Jul/26
CVE-2026-56291
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the Balbooa Forms extension for Joomla. The root cause lies in insufficient validation and sanitization of uploaded files within the form submission handler, allowing executable files to be accepted and stored. The affected component is the file upload functionality of the Balbooa Forms Joomla extension, which fails to restrict file types or enforce authentication checks before processing uploads.

CVSS 9.8
EPSS 14.6%
KEV Pred 67%
Product balbooa.com Balbooa Forms extension for Joomla balbooa.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
30 Jun/26
CVE-2026-48282
CRITICAL

This vulnerability is a path traversal flaw caused by insufficient validation of user-supplied file path inputs within Adobe ColdFusion. The affected component improperly restricts pathname access, allowing attackers to traverse directories outside intended boundaries. This weakness occurs in ColdFusion versions 2023 and earlier, impacting the file handling mechanisms responsible for directory access control.

CVSS 10.0
EPSS 42.4%
KEV Pred 82%
Product Adobe ColdFusion adobe
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
30 Jun/26
CVE-2026-8452
CRITICAL

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

CVSS 9.8
EPSS 1.6%
KEV Pred 59%
Product NetScaler ADC netscaler
CVSS v3.1 CVSS v4.0 KEV CWE-119 PoC
29 Jun/26
CVE-2026-56290
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the JoomlaCK.fr Page Builder CK extension for Joomla. The root cause lies in insufficient validation and filtering of uploaded files within the extension's file upload functionality. The affected component is the file upload handler that processes incoming files without proper authentication or content-type restrictions, enabling malicious payloads to be uploaded.

CVSS 9.8
EPSS 30.4%
KEV Pred 60%
Product JoomlaCK.fr Page Builder CK extension for Joomla joomlack.fr
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
23 Jun/26
CVE-2026-55255
HIGH

The vulnerability is an Insecure Direct Object Reference (IDOR) affecting the /api/v1/responses endpoint of the langflow-ai langflow product. The root cause is insufficient authorization validation allowing authenticated users to specify arbitrary flow IDs belonging to other users. This flaw resides in the API's access control mechanism for flow execution requests prior to version 1.9.1.

CVSS 8.4
EPSS 0.9%
KEV Pred 65%
Product langflow-ai langflow langflow-ai
CVSS v3.1 KEV CWE-639 PoC
20 Jun/26
CVE-2026-48908
CRITICAL

This vulnerability is an unrestricted file upload flaw in the SP Page Builder extension for Joomla. The root cause is insufficient validation and sanitization of uploaded files, allowing unauthenticated users to upload arbitrary files, including executable PHP scripts. The affected component is the file upload functionality within the SP Page Builder extension.

CVSS 9.8
EPSS 14.8%
KEV Pred 58%
Product joomshaper.net SP Page Builder extension for Joomla joomshaper.net
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
20 Jun/26
CVE-2026-48939
CRITICAL

The vulnerability is an arbitrary file upload flaw rooted in improper validation of file attachments within the iCagenda extension for Joomla. The file attachment feature lacks sufficient sanitization and filtering controls, enabling the upload of malicious files. This weakness resides specifically in the file handling component of the iCagenda extension, allowing attackers to bypass restrictions on executable content types.

CVSS 9.8
EPSS 19.7%
KEV Pred 59%
Product icagenda.com iCagenda extension for Joomla icagenda.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
15 Jun/26
CVE-2026-20262
MEDIUM

This vulnerability is a path traversal flaw (CWE-22) in the file upload functionality of Cisco Catalyst SD-WAN Manager's web UI. The root cause is improper validation of user-supplied input during the file upload process, allowing crafted input to manipulate file paths. The affected component is the API endpoint handling file uploads within the web management interface.

CVSS 6.5
EPSS 28.2%
KEV Pred 69%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-22 PoC
14 Jun/26
CVE-2026-54420
HIGH

This vulnerability is a symbolic link (symlink) traversal issue in the LiteSpeed cPanel plugin and LiteSpeed WHM plugin components. The root cause lies in improper validation and handling of user-supplied symlink paths within the plugin's file management routines. Specifically, the plugin fails to correctly restrict symlink resolution for users with FTP or web shell access on shared hosting environments using CloudLinux/CageFS, enabling unauthorized access to filesystem locations outside intended boundaries.

CVSS 8.5
EPSS 1.4%
KEV Pred 66%
Product LiteSpeed Technologies cPanel Plugin litespeed
CVSS v3.1 KEV CWE-61 PoC
12 Jun/26
CVE-2026-48558
CRITICAL

This vulnerability is an authentication bypass caused by improper validation of OIDC identity tokens within SimpleHelp's authentication flow. The flaw arises because the system accepts identity tokens without verifying their cryptographic signatures. The affected component is the OIDC authentication mechanism in SimpleHelp versions 5.5.15 and earlier, as well as 6.0 pre-release versions.

CVSS 10.0
EPSS 12.4%
KEV Pred 68%
Product SimpleHelp simplehelp
CVSS v3.1 CVSS v4.0 KEV CWE-347 PoC RANSOMWARE
08 Jun/26
CVE-2026-11645
HIGH

This vulnerability is an out-of-bounds read and write flaw occurring within the V8 JavaScript engine of Google Chrome. The root cause lies in improper bounds checking during memory operations, allowing access beyond allocated buffer limits. The affected component is the V8 engine, which handles JavaScript execution within the browser sandbox environment.

CVSS 8.8
EPSS 2.2%
KEV Pred 68%
Product Google Chrome google
CVSS v3.1 KEV CWE-125 PoC
05 Jun/26
CVE-2026-7473
MEDIUM

This vulnerability is a protocol decapsulation validation flaw affecting Arista Networks EOS tunnel processing components. Specifically, the switch fails to verify the tunnel protocol type when decapsulating packets on VXLAN, decap-groups, or GRE tunnel interfaces. This improper validation causes the device to incorrectly process tunneled packets with a destination IP matching its configured decapsulation IP regardless of the actual tunnel protocol, leading to unintended packet forwarding behavior.

CVSS 5.8
EPSS 1.1%
KEV Pred 69%
Product Arista Networks EOS arista
CVSS v3.1 CVSS v4.0 KEV CWE-1023 PoC
04 Jun/26
CVE-2026-28318
HIGH

This vulnerability is a denial-of-service condition caused by improper handling of HTTP POST requests with Content-Encoding set to deflate. The root cause lies in the Serv-U service's inability to correctly process specially crafted compressed payloads, leading to resource exhaustion or crash. The affected component is the Serv-U FTP server's HTTP request parsing logic, which does not require authentication to be triggered.

CVSS 7.5
EPSS 40.0%
KEV Pred 63%
Product SolarWinds Serv-U solarwinds
CVSS v3.1 KEV CWE-400 PoC
28 May/26
CVE-2026-46817
CRITICAL

This vulnerability is an authentication bypass in the File Transmission component of Oracle Payments within Oracle E-Business Suite. The root cause lies in insufficient access controls on network-accessible HTTP endpoints, allowing unauthenticated users to interact with sensitive functions. The affected component fails to properly verify credentials or session state before processing requests, enabling unauthorized access to critical payment processing features.

CVSS 9.8
EPSS 13.0%
KEV Pred 74%
Product Oracle Corporation Oracle Payments oracle
CVSS v3.1 KEV CWE-269 PoC RANSOMWARE
26 May/26
CVE-2026-45247
CRITICAL

This vulnerability is a PHP object injection caused by the unsafe use of PHP's native unserialize() function on user-controlled input. Specifically, the CacheWarmer cookie in Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12 is processed without validation, allowing deserialization of crafted serialized PHP objects. The flaw resides in the cache warming component responsible for handling cache refresh requests and related cookie data.

CVSS 9.8
EPSS 27.5%
KEV Pred 69%
Product Mirasvit Full Page Cache Warmer for Magento 2 mirasvit
CVSS v3.1 CVSS v4.0 KEV CWE-502 PoC
21 May/26
CVE-2026-48172
CRITICAL

This vulnerability is a privilege escalation flaw rooted in improper handling of Redis enable/disable features within the LiteSpeed User-End cPanel Plugin. The affected component mismanages internal API calls related to the "cpanel_jsonapi_func=redisAble" parameter, allowing unauthorized elevation of privileges. The flaw resides in the plugin's logic that controls Redis functionality toggling, leading to escalation beyond intended permission boundaries.

CVSS 9.8
EPSS 18.9%
KEV Pred 58%
Product LiteSpeed Technologies cPanel Plugin litespeed
CVSS v3.1 CVSS v4.0 KEV CWE-266 PoC RANSOMWARE
12 May/26
CVE-2026-45321
CRITICAL

This vulnerability involves a supply chain compromise through abuse of GitHub Actions OIDC token authentication. The root cause is a misconfiguration of the pull_request_target event combined with cache poisoning across fork-to-base trust boundaries, enabling extraction of OIDC tokens at runtime. The affected components are multiple @tanstack/* npm packages published via the TanStack/router GitHub Actions workflow.

CVSS 9.6
EPSS 2.3%
KEV Pred 68%
Product @tanstack arktype-adapter @tanstack
CVSS v3.1 KEV CWE-506 PoC RANSOMWARE
06 May/26
CVE-2026-0300
CRITICAL

This vulnerability is a buffer overflow in the User-ID™ Authentication Portal component of Palo Alto Networks PAN-OS software. The root cause is improper handling of specially crafted packets within the Captive Portal service, leading to memory corruption. The flaw exists in the packet processing logic of the User-ID Authentication Portal on PA-Series and VM-Series firewalls running affected PAN-OS versions.

CVSS 9.8
EPSS 31.7%
KEV Pred 69%
Product Palo Alto Networks Cloud NGFW palo
CVSS v3.1 CVSS v4.0 KEV CWE-787 PoC
14 Apr/26
CVE-2026-32201
MEDIUM

This vulnerability is an improper input validation flaw within Microsoft Office SharePoint, specifically affecting the SharePoint Enterprise Server 2016 component. The root cause lies in insufficient sanitization of user-supplied input, enabling an attacker to manipulate data processed by the SharePoint server. The flaw resides in the network-facing interface responsible for handling incoming requests, allowing crafted input to bypass validation checks.

CVSS 6.5
EPSS 42.8%
KEV Pred 78%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-20 PoC RANSOMWARE
01 Apr/26
CVE-2026-5281
HIGH

This vulnerability is a use-after-free condition occurring within the Dawn graphics component of Google Chrome. The flaw arises due to improper management of memory lifecycle for objects in the renderer process, leading to dereferencing of freed memory. The affected component is the Dawn WebGPU implementation used for rendering operations in Chrome versions prior to 146.0.7680.178.

CVSS 8.8
EPSS 4.9%
KEV Pred 69%
Product Google Chrome google
CVSS v3.1 KEV CWE-416 PoC
30 Mar/26
CVE-2026-3502
HIGH

The vulnerability in TrueConf Client is an insecure update mechanism classified under CWE-494 (Download of Code Without Integrity Check). The client downloads and applies update code without verifying its authenticity or integrity, affecting the update delivery component. This lack of verification allows substitution of the update payload during transmission.

CVSS 7.8
EPSS 5.7%
KEV Pred 61%
Product TrueConf Client trueconf
CVSS v3.1 KEV CWE-494 PoC
12 Mar/26
CVE-2026-3910
HIGH

This vulnerability is a code injection flaw rooted in improper handling of script evaluation within the V8 JavaScript engine used by Google Chrome. Specifically, the issue arises from unsafe execution of dynamically generated code inside the sandbox environment, allowing crafted HTML content to trigger arbitrary code execution. The affected component is the V8 engine prior to version 146.0.7680.75, which fails to adequately sanitize or restrict the execution context of injected scripts.

CVSS 8.8
EPSS 2.0%
KEV Pred 70%
Product Google Chrome google
CVSS v3.1 KEV CWE-94 PoC
12 Mar/26
CVE-2026-3909
HIGH

This vulnerability is an out-of-bounds write occurring within the Skia graphics library component of Google Chrome. The root cause is improper bounds checking during memory operations, leading to memory corruption when processing crafted graphical data. The flaw specifically affects versions of Google Chrome prior to 146.0.7680.75, impacting the rendering engine's handling of certain HTML content.

CVSS 8.8
EPSS 1.6%
KEV Pred 73%
Product Google Chrome google
CVSS v3.1 KEV CWE-787 PoC
11 Mar/26
CVE-2025-67038
CRITICAL

This vulnerability is a command injection flaw rooted in improper input sanitization within the HTTP RPC module of Lantronix EDS5000 firmware version 2.1.0.0R3. Specifically, the username parameter used during authentication failure handling is concatenated directly into a shell command without validation or escaping. This unsafe string concatenation occurs in the log-writing function, enabling injection of arbitrary operating system commands executed with root privileges.

CVSS 9.8
EPSS 15.7%
KEV Pred 78%
Product N/A
CVSS v3.1 KEV CWE-94 PoC
04 Mar/26
CVE-2026-20131
CRITICAL

This vulnerability is an insecure deserialization flaw within the web-based management interface of Cisco Secure Firewall Management Center (FMC). It arises from improper handling of user-supplied serialized Java byte streams, allowing crafted objects to be processed without validation. The affected component is the Java deserialization mechanism in the FMC software versions 6.4.0.13 through 6.4.0.17.

CVSS 10.0
EPSS 31.2%
KEV Pred 80%
Product Cisco Secure Firewall Management Center (FMC) cisco
CVSS v3.1 KEV CWE-502 PoC RANSOMWARE
13 Feb/26
CVE-2026-2441
HIGH

This vulnerability is a use-after-free condition within the CSS processing component of Google Chrome. The flaw arises from improper memory management when handling CSS objects, leading to dereferencing of freed memory. The affected component is the CSS engine in versions of Google Chrome prior to 145.0.7632.75, which fails to maintain valid references during CSS parsing and rendering.

CVSS 8.8
EPSS 22.0%
KEV Pred 75%
Product Google Chrome google
CVSS v3.1 KEV CWE-416 PoC
10 Feb/26
CVE-2026-21510
HIGH

This vulnerability is a protection mechanism failure within the Windows Shell component of Microsoft Windows 10 versions 1607, 1809, and 21H2. The root cause lies in improper enforcement of security controls that allow bypassing of intended restrictions during network-based interactions with the shell. The flaw specifically affects the Windows Shell's handling of security features designed to prevent unauthorized access or execution of privileged operations.

CVSS 8.8
EPSS 25.8%
KEV Pred 80%
Product Microsoft Windows 10 Version 1607 microsoft
CVSS v3.1 KEV CWE-693 PoC RANSOMWARE
03 Feb/26
CVE-2025-15556
HIGH

This vulnerability is an update integrity verification flaw in the WinGUp updater component of Notepad++ prior to version 8.8.9. The root cause is the absence of cryptographic verification for downloaded update metadata and installer files, allowing tampered or malicious update packages to be accepted and executed. The affected feature is the automatic update mechanism responsible for fetching and applying software updates.

CVSS 7.5
EPSS 1.7%
KEV Pred 69%
Product notepad-plus-plus notepad-plus-plus
CVSS v3.1 CVSS v4.0 KEV CWE-494 PoC
21 Jan/26
CVE-2026-20045
CRITICAL

This vulnerability is a command injection flaw caused by improper validation of user-supplied input within HTTP requests processed by the web-based management interface of Cisco Unified Communications Manager and related components. The root cause lies in the failure to sanitize or restrict input parameters, allowing crafted HTTP requests to invoke unauthorized command execution on the underlying operating system. Affected components include Unified Communications Manager, Session Management Edition, IM & Presence Service, Unity Connection, and Webex Calling Dedicated Instance.

CVSS 9.8
EPSS 4.4%
KEV Pred 78%
Product Cisco Unified Communications Manager cisco
CVSS v3.1 KEV CWE-94 PoC RANSOMWARE
20 Jan/26
CVE-2026-21962
CRITICAL

This vulnerability is an authentication bypass in the Oracle Weblogic Server Proxy Plug-in components for Apache HTTP Server and IIS. It arises from improper access control enforcement in the proxy plug-in, allowing unauthenticated network requests via HTTP to interact with internal server functions. The affected components include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and Weblogic Server Proxy Plug-in versions 12.2.1.4.0 and 14.1.1.0.0.

CVSS 10.0
EPSS 42.0%
KEV Pred 64%
Product Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in oracle
CVSS v3.1 KEV CWE-284 PoC RANSOMWARE
13 Jan/26
CVE-2026-20963
CRITICAL

This vulnerability is a deserialization flaw occurring in Microsoft Office SharePoint Enterprise Server 2016. It arises from improper handling of untrusted serialized data within SharePoint's object deserialization routines. The affected component is the SharePoint server's deserialization mechanism that processes incoming data objects over the network, allowing manipulation of internal state during deserialization.

CVSS 9.8
EPSS 31.6%
KEV Pred 81%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 PoC RANSOMWARE
22 Dec/25
CVE-2025-68645
HIGH

This vulnerability is a Local File Inclusion (LFI) flaw caused by improper validation and sanitization of user-supplied parameters within the RestFilter servlet of the Webmail Classic UI in Zimbra Collaboration Suite versions 10.0 and 10.1. The servlet fails to correctly handle request parameters, allowing manipulation of internal request dispatching logic. This flaw affects the /h/rest endpoint, enabling unauthorized access to internal file inclusion mechanisms within the WebRoot directory.

CVSS 8.8
EPSS 49.4%
KEV Pred 82%
Product Synacor Zimbra Collaboration Suite (ZCS) synacor
CVSS v3.1 KEV CWE-98 PoC
19 Dec/25
CVE-2025-14733
CRITICAL

This vulnerability is an out-of-bounds write in the WatchGuard Fireware OS VPN components. The root cause lies in improper bounds checking when processing IKEv2 packets for Mobile User VPN and Branch Office VPN configured with dynamic gateway peers. The flaw occurs within the Fireware OS VPN protocol handling code, leading to memory corruption due to writing outside allocated buffers.

CVSS 9.8
EPSS 26.5%
KEV Pred 80%
Product WatchGuard Fireware OS watchguard
CVSS v3.1 CVSS v4.0 KEV CWE-787 PoC
18 Dec/25
CVE-2025-40602
MEDIUM

This vulnerability is a local privilege escalation caused by insufficient authorization checks within the SonicWall SMA1000 appliance management console (AMC). The flaw arises from improper enforcement of access control mechanisms, allowing users with limited privileges to perform actions reserved for higher privilege levels. The affected component is the AMC interface responsible for managing device configurations and operations.

CVSS 6.6
EPSS 2.1%
KEV Pred 80%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-250 PoC
18 Dec/25
CVE-2025-68461
MEDIUM

This vulnerability is a Cross-Site Scripting (XSS) flaw rooted in improper sanitization of SVG documents, specifically within the animate tag. The Roundcube Webmail rendering engine fails to correctly validate or escape user-supplied SVG content, allowing malicious scripts to be injected and executed. The affected component is the SVG handling functionality in Roundcube Webmail versions prior to 1.5.12 and 1.6.12.

CVSS 6.1
EPSS 26.8%
KEV Pred 80%
Product Roundcube Webmail roundcube
CVSS v3.1 KEV CWE-79 PoC
17 Dec/25
CVE-2025-43529
HIGH

This vulnerability is a use-after-free flaw arising from improper memory management within the Apple Safari web content processing engine. Specifically, the issue occurs when handling certain crafted web content, leading to the premature release of memory objects that are subsequently accessed. The affected components include Safari browser and WebKit-based rendering on multiple Apple operating systems such as iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

CVSS 8.8
EPSS 8.9%
KEV Pred 82%
Product Apple Safari apple
CVSS v3.1 KEV CWE-416 PoC
17 Dec/25
CVE-2025-20393
CRITICAL

This vulnerability is a command injection flaw caused by insufficient validation of HTTP requests processed by the Spam Quarantine feature in Cisco AsyncOS Software. The root cause lies in the improper sanitization of input parameters within the HTTP request handling logic, allowing crafted requests to reach system-level command execution functions. The affected component is the Spam Quarantine feature of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager running AsyncOS.

CVSS 10.0
EPSS 29.9%
KEV Pred 64%
Product Cisco Secure Email cisco
CVSS v3.1 KEV CWE-20 PoC RANSOMWARE
12 Dec/25
CVE-2025-14174
HIGH

This vulnerability is an out-of-bounds memory access flaw rooted in improper bounds checking within the ANGLE graphics engine component of Google Chrome on macOS. Specifically, malformed HTML content triggers the flaw during the processing of graphics rendering commands, causing memory reads or writes beyond allocated buffers. The affected component is ANGLE, a graphics abstraction layer used by Chrome to translate OpenGL ES calls to native APIs.

CVSS 8.8
EPSS 22.6%
KEV Pred 83%
Product Google Chrome google
CVSS v3.1 KEV CWE-787 PoC
26 Nov/25
CVE-2025-62593
HIGH

This vulnerability is a remote code execution (RCE) flaw rooted in an insufficient security control within the Ray AI compute engine's development tool. The affected component relies on the User-Agent HTTP header starting with "Mozilla" as a defense against browser-based attacks, which is inadequate because the fetch specification permits modification of this header. This weakness, combined with the potential for DNS rebinding attacks, allows malicious web content to bypass the User-Agent check and exploit the Ray development environment.

CVSS 8.8
EPSS 16.9%
KEV Pred 62%
Product ray-project ray ray-project
CVSS v3.1 CVSS v4.0 KEV CWE-94 PoC
Page 1 of 3 (134 total)