Latest CVEs and vulnerabilities

New CVEs from the National Vulnerability Database, ranked by patch priority from CVSS severity, EPSS exploit likelihood, CISA's known exploited list, government advisories and news coverage.

Recently exploited

  • CVE-2026-88779 CVSS 8.7 high · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-102489 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Session Fixation Vulnerability
  • CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability
  • CVE-2026-104286 CVSS 9.8 critical · actively exploited Fortinet FortiMail Path Traversal Vulnerability
  • CVE-2026-76504 CVSS 9.8 critical · actively exploited Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
  • CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
  • CVE-2026-88771 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Input Validation Vulnerability
  • CVE-2026-88772 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-65660 CVSS 8.8 high · actively exploited Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-67279 CVSS 6.9 medium · actively exploited Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
  • CVE-2026-87902 CVSS 8.1 high · actively exploited WordPress Core Remote File Inclusion Vulnerability
  • CVE-2026-71362 CVSS 9.1 critical · actively exploited Adobe Commerce and Magento Incorrect Authorization Vulnerability
  • CVE-2026-5430 CVSS 10.0 critical · actively exploited WSO2 Multiple Products Path Traversal Vulnerability
  • CVE-2026-93616 CVSS 9.8 critical · actively exploited Check Point Multiple Products Path Traversal Vulnerability
  • CVE-2026-85102 CVSS 9.8 critical · actively exploited Check Point Multiple Products Improper Certificate Validation Vulnerability

Newest critical

  • CVE-2026-105285 CVSS 9.3 critical A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file…
  • CVE-2026-105284 CVSS 9.3 critical A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file…
  • CVE-2026-103510 CVSS 9.5 critical P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an…
  • CVE-2026-100103 CVSS 10.0 critical Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An…
  • CVE-2026-100102 CVSS 9.5 critical Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to…
  • CVE-2026-105294 CVSS 9.1 critical Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config…
  • CVE-2026-105293 CVSS 9.2 critical Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape…
  • CVE-2026-105223 CVSS 9.1 critical maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a…
  • CVE-2026-105222 CVSS 9.1 critical The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config…
  • CVE-2026-105221 CVSS 9.1 critical The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS…
  • CVE-2026-105218 CVSS 9.1 critical gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers…
  • CVE-2026-105216 CVSS 9.1 critical go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services…
  • CVE-2026-105089 CVSS 9.3 critical WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script…
  • CVE-2026-105086 CVSS 9.3 critical WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by…
  • CVE-2026-105215 CVSS 9.3 critical ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not…
  • CVE-2026-105211 CVSS 9.2 critical ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over…
  • CVE-2026-105209 CVSS 9.3 critical ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless…
  • CVE-2026-105207 CVSS 9.3 critical ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying…
  • CVE-2026-103355 CVSS 9.3 critical Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited…
  • CVE-2026-105135 CVSS 9.3 critical A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file…
  • CVE-2026-105134 CVSS 9.3 critical A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do…
  • CVE-2026-105105 CVSS 9.8 critical CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS…
  • CVE-2026-71885 CVSS 9.2 critical In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a…
  • CVE-2026-92084 CVSS 9.1 critical The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in…
  • CVE-2026-87115 CVSS 9.1 critical The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…

Newest

  • CVE-2026-92931 CVSS 8.8 high CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may…
  • CVE-2026-77805 CVSS 7.9 high In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper…
  • CVE-2026-77804 CVSS 6.6 medium In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race…
  • CVE-2026-77803 CVSS 3.6 low In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in…
  • CVE-2026-77802 CVSS 6.3 medium In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy…
  • CVE-2026-105315 CVSS 2.0 low A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file…
  • CVE-2026-63277 CVSS 8.5 high LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java…
  • CVE-2026-63270 CVSS 6.7 medium URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be…
  • CVE-2026-63269 CVSS 6.7 medium LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an…
  • CVE-2026-63268 CVSS 6.7 medium LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could…
  • CVE-2026-63267 CVSS 6.7 medium LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched…
  • CVE-2026-63266 CVSS 6.8 medium LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document…
  • CVE-2026-39783 CVSS 4.3 medium Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang…
  • CVE-2026-105396 CVSS 5.3 medium Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect…
  • CVE-2026-105307 CVSS 5.5 medium A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the…
  • CVE-2026-105073 CVSS 5.3 medium Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution…
  • CVE-2026-103684 CVSS 5.3 medium Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access…
  • CVE-2026-94669 CVSS 5.3 medium Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly…
  • CVE-2026-59788 CVSS 5.7 medium The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a…
  • CVE-2026-59787 CVSS 5.3 medium The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This…
  • CVE-2026-59786 CVSS 6.9 medium Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This…
  • CVE-2026-59785 CVSS 5.1 medium Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read…
  • CVE-2026-59783 CVSS 2.3 low The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential…
  • CVE-2026-59782 CVSS 6.9 medium The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap…
  • CVE-2026-39763 CVSS 4.3 medium Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly…