Known Exploited Vulnerabilities

97 CVEs confirmed actively exploited (CISA KEV)

These vulnerabilities are listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to patch them within mandated timelines. All organizations should prioritize remediation immediately.

CVE-2026-20349

Aug 11, 2026

High 8.6

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthe...

Read Advisory

CVE-2026-68820

Aug 11, 2026

High 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally....

Read Advisory

CVE-2026-72898

Aug 10, 2026

Critical 10.0

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance....

Read Advisory

CVE-2026-18577

Aug 2, 2026

High 8.2

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1...

Read Advisory

CVE-2026-18556

Aug 1, 2026

High 8.2

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1....

Read Advisory

CVE-2026-20316

Jul 29, 2026

Medium 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac...

Read Advisory

CVE-2026-16812

Jul 27, 2026

Critical 10.0

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may ...

Read Advisory

CVE-2026-63077

Jul 27, 2026

Critical 9.8

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol...

Read Advisory

CVE-2026-16232

Jul 22, 2026

Critical 9.1

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full...

Read Advisory

CVE-2026-63030

Jul 17, 2026

Critical 9.8

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), coul...

Read Advisory

CVE-2026-9198

Jul 17, 2026

Critical 9.8

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exe...

Read Advisory

CVE-2026-60137

Jul 17, 2026

Critical 9.1

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme pas...

Read Advisory

CVE-2021-27137

Jul 16, 2026

High 8.1

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would ove...

Read Advisory

CVE-2026-15409

Jul 14, 2026

Critical 10.0

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make re...

Read Advisory

CVE-2026-50522

Jul 14, 2026

Critical 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network....

Read Advisory

CVE-2026-56164

Jul 14, 2026

Critical 9.8

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-58644

Jul 14, 2026

Critical 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network....

Read Advisory

CVE-2026-56155

Jul 14, 2026

High 7.8

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally....

Read Advisory

CVE-2026-15410

Jul 14, 2026

High 7.2

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could pot...

Read Advisory

CVE-2026-56291

Jul 9, 2026

Critical 10.0

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....

Read Advisory

CVE-2026-48282

Jun 30, 2026

Critical 10.0

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execut...

Read Advisory

CVE-2026-56290

Jun 29, 2026

Critical 10.0

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....

Read Advisory

CVE-2026-55255

Jun 23, 2026

High 8.4

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenti...

Read Advisory

CVE-2026-48908

Jun 20, 2026

Critical 10.0

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code....

Read Advisory

CVE-2026-48939

Jun 20, 2026

Critical 10.0

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution....

Read Advisory

CVE-2026-12569

Jun 18, 2026

Critical 9.3

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * ...

Read Advisory

CVE-2026-20262

Jun 15, 2026

Medium 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an af...

Read Advisory

CVE-2026-54420

Jun 14, 2026

High 8.5

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running Clou...

Read Advisory

CVE-2026-48558

Jun 12, 2026

Critical 10.0

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity token...

Read Advisory

CVE-2026-35273

Jun 11, 2026

Critical 9.8

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploita...

Read Advisory

CVE-2026-10520

Jun 9, 2026

Critical 10.0

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution...

Read Advisory

CVE-2026-25089

Jun 9, 2026

Critical 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox ...

Read Advisory

CVE-2026-11645

Jun 9, 2026

High 8.8

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H...

Read Advisory

CVE-2026-50751

Jun 8, 2026

Critical 9.3

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...

Read Advisory

CVE-2026-48907

Jun 5, 2026

Critical 10.0

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution....

Read Advisory

CVE-2026-7473

Jun 5, 2026

Medium 6.9

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is p...

Read Advisory

CVE-2026-8037

Jun 4, 2026

Critical 9.8

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting uns...

Read Advisory

CVE-2026-20245

Jun 4, 2026

High 7.8

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBo...

Read Advisory

CVE-2026-28318

Jun 4, 2026

High 7.5

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure custom...

Read Advisory

CVE-2026-20230

Jun 3, 2026

High 8.6

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacke...

Read Advisory

CVE-2025-48595

Jun 1, 2026

High 8.4

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

Read Advisory

CVE-2026-46817

May 28, 2026

Critical 9.8

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow...

Read Advisory

CVE-2026-48027

May 27, 2026

Critical 9.8

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available ...

Read Advisory

CVE-2026-45247

May 26, 2026

Critical 9.8

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a...

Read Advisory

CVE-2026-45659

May 22, 2026

High 8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network....

Read Advisory

CVE-2026-48172

May 21, 2026

Critical 10.0

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonap...

Read Advisory

CVE-2026-34926

May 21, 2026

Medium 6.7

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents ...

Read Advisory

CVE-2026-41091

May 20, 2026

High 7.8

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally....

Read Advisory

CVE-2026-45498

May 20, 2026

High 7.5

Microsoft Defender Denial of Service Vulnerability...

Read Advisory

CVE-2026-9082

May 20, 2026

Medium 6.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1...

Read Advisory

CVE-2026-8398

May 15, 2026

Critical 9.8

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc be...

Read Advisory

CVE-2026-20182

May 14, 2026

Critical 10.0

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vu...

Read Advisory

CVE-2026-42897

May 14, 2026

High 8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-0257

May 13, 2026

Critical 9.1

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized V...

Read Advisory

CVE-2026-45321

May 12, 2026

Critical 9.6

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate G...

Read Advisory

CVE-2026-42208

May 8, 2026

Critical 9.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-...

Read Advisory

CVE-2026-42271

May 8, 2026

High 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST ...

Read Advisory

CVE-2026-6973

May 7, 2026

High 7.2

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution....

Read Advisory

CVE-2026-0300

May 6, 2026

Critical 9.3

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code wi...

Read Advisory

CVE-2026-41940

Apr 29, 2026

Critical 9.8

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel....

Read Advisory

CVE-2026-31431

Apr 22, 2026

High 7.8

Copy Fail (CVE-2026-31431) is an in-place AEAD memory bug in the Linux kernel's algif_aead crypto interface, allowing local low-privileged attackers to corrupt memory and execute arbitrary code at kernel level. The fix reverts commit 72548b093ee3 (except for associated-data copying) to restore out-of-place operation. Disclosed by Theori/Xint as Copy Fail; actively exploited in the wild and listed in CISA KEV.

Read Advisory

CVE-2026-39808

Apr 14, 2026

Critical 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code ...

Read Advisory

CVE-2026-33825

Apr 14, 2026

High 7.8

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally....

Read Advisory

CVE-2026-32201

Apr 14, 2026

Medium 6.5

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-32202

Apr 14, 2026

Medium 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-39987

Apr 9, 2026

Critical 9.8

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticate...

Read Advisory

CVE-2026-34486

Apr 9, 2026

High 7.5

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53...

Read Advisory

CVE-2026-34197

Apr 7, 2026

High 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bri...

Read Advisory

CVE-2026-35616

Apr 4, 2026

Critical 9.8

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests....

Read Advisory

CVE-2026-3909

Mar 13, 2026

High 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)...

Read Advisory

CVE-2026-3910

Mar 13, 2026

High 8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi...

Read Advisory

CVE-2025-67038

Mar 11, 2026

Critical 9.8

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the comm...

Read Advisory

CVE-2026-20131

Mar 4, 2026

Critical 10.0

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root o...

Read Advisory

CVE-2026-20127

Feb 25, 2026

Critical 10.0

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, r...

Read Advisory

CVE-2026-20128

Feb 25, 2026

High 7.5

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This v...

Read Advisory

CVE-2026-20133

Feb 25, 2026

Medium 6.5

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file ...

Read Advisory

CVE-2026-20122

Feb 25, 2026

Medium 5.4

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the atta...

Read Advisory

CVE-2026-22769

Feb 17, 2026

Critical 10.0

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of...

Read Advisory

CVE-2025-68686

Feb 10, 2026

Medium 5.9

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, Fort...

Read Advisory

CVE-2026-0770

Jan 23, 2026

Critical 9.8

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins...

Read Advisory

CVE-2025-34291

Dec 5, 2025

Critical 9.4

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with all...

Read Advisory

CVE-2025-32975

Jun 24, 2025

Critical 10.0

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an ...

Read Advisory

CVE-2025-48700

Jun 23, 2025

Medium 6.1

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaSc...

Read Advisory

CVE-2025-2749

Mar 24, 2025

High 7.2

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbit...

Read Advisory

CVE-2024-21182

Jul 16, 2024

High 7.5

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerabilit...

Read Advisory

CVE-2024-27199

Mar 4, 2024

High 7.3

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible...

Read Advisory

CVE-2024-1708

Feb 21, 2024

High 8.4

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critic...

Read Advisory

CVE-2023-4346

Aug 29, 2023

High 7.5

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the devi...

Read Advisory

CVE-2023-27351

Apr 20, 2023

High 7.5

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The spe...

Read Advisory

CVE-2022-0492

Mar 3, 2022

High 7.8

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_a...

Read Advisory

CVE-2010-0806

Mar 10, 2010

Critical 9.3

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving acce...

Read Advisory

CVE-2010-0249

Jan 15, 2010

Critical 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 20...

Read Advisory

CVE-2009-3459

Oct 13, 2009

Critical 9.3

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers mem...

Read Advisory

CVE-2009-1537

May 29, 2009

Critical 9.3

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP...

Read Advisory

CVE-2009-0238

Feb 25, 2009

High 8.8

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in ...

Read Advisory

CVE-2008-4250

Oct 23, 2008

Critical 10.0

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a craft...

Read Advisory

CVE-2008-4128

Sep 18, 2008

Critical 9.3

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary comm...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.