// Threat Intel

CVE & exploit tracker

A searchable database of vulnerabilities — scored, tagged, and flagged when a public exploit or active exploitation is known. Enriched with community-verified research and PoCs.

296,161
CVEs tracked
296,161
Matching filters
CISA KEV
Known exploited
PoC-flagged
Public exploit
CVECVSSDetailsTypeStatus
CVE-2026-72530
9.0
Criticaltrueconf server
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the…
Aug 19, 2026
Code injection
KEV PoC
CVE-2026-72529
9.8
Criticaltrueconf server
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocume…
Aug 19, 2026
Auth bypass
KEV PoC
CVE-2026-19490
9.3
Critical—
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Aug 19, 2026
Auth bypass
KEV
CVE-2026-64849
9.3
Criticalmlflow
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_we…
Aug 17, 2026
SSRF
KEV PoC
CVE-2026-73570
8.9
Highzimbra collaboration suite
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untruste…
Aug 13, 2026
Command injection
KEV
CVE-2026-42018
7.5
High—
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Aug 12, 2026
Auth bypass
KEV
CVE-2026-66384
5.3
Medium—
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Aug 12, 2026
Path traversal
KEV
CVE-2026-71362
9.1
Critical—
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitat…
Aug 11, 2026
Authorization
KEV
CVE-2026-68820
7.0
Highwindows 10 1607
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Aug 11, 2026
Use-after-free
KEV
CVE-2026-65660
6.5
Mediumsharepoint server
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Aug 11, 2026
Code injection
KEV
CVE-2026-20349
8.6
Highadaptive security appliance software
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote …
Aug 11, 2026
Vulnerability
KEV
CVE-2026-72898
10.0
Criticalmetabase
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Aug 10, 2026
SQL injection
KEV
CVE-2026-65400
9.8
Criticalmacos
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Scr…
Aug 6, 2026
Auth bypass
KEV PoC
CVE-2026-5430
10.0
Criticalapi control plane
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrect…
Aug 6, 2026
Vulnerability
KEV
CVE-2026-18577
8.1
Highn-central
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Aug 2, 2026
Auth bypass
KEV
CVE-2026-18556
7.4
Highn-central
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Aug 1, 2026
Auth bypass
KEV
CVE-2026-59310
9.8
Criticalvcenter server
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Jul 30, 2026
Path traversal
KEV
CVE-2026-20316
5.3
Mediumsecure firewall management center
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access s…
Jul 29, 2026
Hardcoded creds
KEV
CVE-2026-42016
8.1
Highartifactory
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Jul 27, 2026
Authorization
KEV
CVE-2026-63077
9.8
Criticalteamcity
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Jul 27, 2026
Deserialization
KEV
CVE-2026-16812
10.0
Criticalvelocloud orchestrator
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the co…
Jul 27, 2026
Command injection
KEV
CVE-2026-16232
9.8
Criticalmulti-domain security management
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative p…
Jul 22, 2026
Auth bypass
KEV
CVE-2026-63030
9.8
Criticalwordpress
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attack…
Jul 17, 2026
Vulnerability
KEV
CVE-2026-60137
5.9
Mediumwordpress
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted inp…
Jul 17, 2026
SQL injection
KEV
CVE-2026-9198
9.8
Criticallangflow
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve f…
Jul 17, 2026
Code injection
KEV
CVE-2026-9586
9.3
Critical—
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled…
Jul 17, 2026
SQL injection
KEV
CVE-2021-27137
8.1
Highdd-wrt
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal…
Jul 16, 2026
Memory corruption
KEV PoC
CVE-2026-15410
7.2
Highsma6210 firmware
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a…
Jul 14, 2026
Code injection
KEV
CVE-2026-15409
10.0
Criticalsma6210 firmware
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to uninten…
Jul 14, 2026
SSRF
KEV
CVE-2026-55040
9.1
Criticalsharepoint server
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Jul 14, 2026
Vulnerability
KEV PoC
CVE-2026-58644
9.8
Criticalsharepoint server
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Jul 14, 2026
Deserialization
KEV
CVE-2026-56164
5.3
Mediumsharepoint server
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Jul 14, 2026
Auth bypass
KEV
CVE-2026-56155
7.8
Highwindows 10 1607
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Jul 14, 2026
Vulnerability
KEV
CVE-2026-50522
9.8
Criticalsharepoint server
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Jul 14, 2026
Deserialization
KEV
CVE-2026-56291
9.8
Criticalforms
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading exec…
Jul 9, 2026
File upload
KEV PoC
CVE-2026-59822
8.2
Highlitellm
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization heade…
Jul 8, 2026
Auth bypass
KEV
CVE-2026-53362
7.8
Highlinux kernel
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / l…
Jul 4, 2026
Vulnerability
KEV
CVE-2026-48282
10.0
Criticalcoldfusion
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the contex…
Jun 30, 2026
Path traversal
KEV
CVE-2026-8452
9.8
Criticalnetscaler application delivery controller
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) …
Jun 30, 2026
Memory corruption
KEV
CVE-2026-56290
9.8
Criticalpage builder ck
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading …
Jun 29, 2026
File upload
KEV PoC
Page 1 / 7405
Found something? Pro members publish their own verified CVE research with proof-of-concept — credited to you.
Submit a CVE