CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-85706 KEV CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

CVSS 10.0 EPSS 92.96% Sep 12, 2026
CVE-2026-82078 KEV CRITICAL

PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

CVSS 9.4 EPSS 61.39% Aug 28, 2026
CVE-2026-81578 KEV HIGH

PaperCut MF/NG: Authentication Bypass

CVSS 8.8 EPSS 85.17% Aug 28, 2026
CVE-2026-19478 CRITICAL

Improper Control of Generation of Code ('Code Injection') in GitLab

CVSS 9.4 EPSS 60.20% Aug 17, 2026
CVE-2026-71362 KEV CRITICAL

Adobe Commerce | Incorrect Authorization (CWE-863)

CVSS 9.1 EPSS 87.51% Aug 11, 2026
CVE-2026-63077 KEV CRITICAL

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8 EPSS 89.57% Jul 27, 2026
CVE-2026-16232 KEV CRITICAL

Authentication Bypass in the SmartConsole Login Process Using an Application Token

CVSS 9.3 EPSS 77.97% Jul 22, 2026
CVE-2026-48908 KEV CRITICAL

Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2

CVSS 10.0 EPSS 88.51% Jun 20, 2026
CVE-2026-20253 KEV CRITICAL

Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

CVSS 9.8 EPSS 96.94% Jun 10, 2026
CVE-2026-25089 KEV CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiS…

CVSS 9.8 EPSS 76.11% Jun 9, 2026
CVE-2026-10523 CRITICAL

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to…

CVSS 9.9 EPSS 53.14% Jun 9, 2026
CVE-2026-10520 KEV CRITICAL

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-le…

CVSS 10.0 EPSS 99.91% Jun 9, 2026
CVE-2026-8037 KEV CRITICAL

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

CVSS 9.8 EPSS 77.36% Jun 4, 2026
CVE-2026-20230 KEV HIGH

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

CVSS 8.6 EPSS 88.20% Jun 3, 2026
CVE-2026-20182 KEV CRITICAL

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

CVSS 10.0 EPSS 91.52% May 14, 2026
CVE-2026-0257 KEV HIGH

PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

CVSS 7.8 EPSS 96.38% May 13, 2026
CVE-2026-42271 KEV HIGH

LiteLLM: Authenticated command execution via MCP stdio test endpoints

CVSS 8.7 EPSS 92.57% May 8, 2026
CVE-2026-41940 KEV CRITICAL

WebPros cPanel and WHM Authentication Bypass via Login Flow

CVSS 9.3 EPSS 98.53% Apr 29, 2026
CVE-2026-0740 CRITICAL

Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload

CVSS 9.8 EPSS 62.90% Apr 7, 2026
CVE-2026-20079 KEV CRITICAL

Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability

CVSS 10.0 EPSS 88.18% Mar 4, 2026
CVE-2026-20127 KEV CRITICAL

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

CVSS 10.0 EPSS 88.48% Feb 25, 2026
CVE-2026-2041 HIGH

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability

CVSS 8.8 EPSS 73.75% Feb 20, 2026
CVE-2026-2043 HIGH

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability

CVSS 8.8 EPSS 73.75% Feb 20, 2026
CVE-2026-2441 KEV HIGH

chromium-browser: Use after free in CSS

CVSS 8.8 EPSS 55.10% Feb 13, 2026
CVE-2026-1603 KEV HIGH

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS 8.6 EPSS 87.94% Feb 10, 2026

Showing 1 to 25 CVEs · page 1 (more available)