CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-20349HIGH | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service VulnerabilityA vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to t… CWE-244Aug 11, 2026 | CVSS8.6v3.1 | EPSS0.874% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-68820HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUse after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CWE-416Aug 11, 2026 | CVSS7.0v3.1 | EPSS0.332% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-72898CRITICAL | Metabase SQL injection via password reset endpointMetabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | CVSS10.0v4.0 | EPSS10.4% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-18577HIGH | Incomplete patch leads to administrative account takeoverAn incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 CWE-288Aug 2, 2026 | CVSS8.2v4.0 | EPSS4.1% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18556HIGH | Unauthenticated administrative account takeoverAuthentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. CWE-288Aug 1, 2026 | CVSS8.2v4.0 | EPSS0.492% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20316MEDIUM | Cisco Secure Firewall Management Center Software Static Credential VulnerabilityA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow t… CWE-259Jul 29, 2026 | CVSS5.3v3.1 | EPSS0.788% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-63077CRITICAL | JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | CVSS9.8v3.1 | EPSS10.7% | PoCs4 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-16812CRITICAL | VeloCloud Orchestrator OS Command InjectionVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in a… CWE-78Jul 27, 2026 | CVSS10.0v4.0 | EPSS0.884% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-16232CRITICAL | Authentication Bypass in the SmartConsole Login Process Using an Application TokenAn authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this… | CVSS9.3v4.0 | EPSS73.3% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-63030CRITICAL | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | CVSS9.8v3.1 | EPSS95.6% | PoCs80 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-60137MEDIUM | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CWE-89Jul 17, 2026 | CVSS5.9v3.1 | EPSS73.1% | PoCs53 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9198CRITICAL | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code ValidationIBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments | CVSS9.8v3.1 | EPSS17.4% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-27137HIGH | DD-WRT Stack-Based Buffer Overflow VulnerabilityAn issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request). CWE-121Jul 16, 2026 | CVSS8.1v3.1 | EPSS16.5% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15410HIGH | SonicWall SMA1000 Appliances Code Injection VulnerabilityPost-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CWE-94Jul 14, 2026 | CVSS7.2v3.1 | EPSS76.3% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2026-15409CRITICAL | SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | CVSS10.0v3.1 | EPSS74.2% | PoCs7 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2026-58644CRITICAL | Microsoft SharePoint Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CWE-502Jul 14, 2026 | CVSS9.8v3.1 | EPSS6.37% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50522CRITICAL | Microsoft SharePoint Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CWE-502Jul 14, 2026 | CVSS9.8v3.1 | EPSS77% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56164MEDIUM | Microsoft SharePoint Server Elevation of Privilege VulnerabilityMissing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. CWE-306Jul 14, 2026 | CVSS5.3v3.1 | EPSS22.4% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56155HIGH | Active Directory Federation Services Elevation of Privilege VulnerabilityInsufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. CWE-1220Jul 14, 2026 | CVSS7.8v3.1 | EPSS2.33% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56291CRITICAL | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | CVSS10.0v4.0 | EPSS76.1% | PoCs4 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-48282CRITICAL | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | CVSS10.0v3.1 | EPSS99.2% | PoCs3 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-56290CRITICAL | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | CVSS10.0v4.0 | EPSS83.3% | PoCs5 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-55255HIGH | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowLangflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1. CWE-639Jun 23, 2026 | CVSS8.4v3.1 | EPSS29.1% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-48908CRITICAL | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | CVSS10.0v4.0 | EPSS88.1% | PoCs11 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-48939CRITICAL | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | CVSS10.0v4.0 | EPSS82.5% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |