Cyber Threat Intelligence
CVE Search & Database
Every CVE this site covers, in one filterable table — including CVE IDs bundled inside a roundup or Patch Tuesday advisory that never got a headline of their own. Filtering happens in your browser; nothing you type here is sent anywhere.
Newest 50 of 2041 CVEs
| CVE ID | Title | Products | CVSS | KEV | Updated |
|---|---|---|---|---|---|
| CVE-2026-102489 | Exploited Zammad helpdesk chain runs from session hijack to root | — | — | — | OCT 03, 2026 |
| CVE-2026-102490 | Exploited Zammad helpdesk chain runs from session hijack to root | — | — | — | OCT 03, 2026 |
| CVE-2026-104286 | Exploited FortiMail flaw lets attackers write files with no fix out yet | — | — | KEV | OCT 02, 2026 |
| CVE-2026-86950 | Apple CoreGraphics zero-day exploited in targeted attacks, CISA says | — | — | KEV | SEP 30, 2026 |
| CVE-2026-76504 | Exploited Cisco SD-WAN Manager flaw gives attackers admin API access | — | — | KEV | SEP 30, 2026 |
| CVE-2026-88771 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88772 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88773 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88774 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88775 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88776 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88777 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-88778 | Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn | — | — | — | SEP 29, 2026 |
| CVE-2026-65660 | CISA confirms exploitation of SharePoint and MikroTik RouterOS flaws | — | — | — | SEP 25, 2026 |
| CVE-2026-67279 | CISA confirms exploitation of SharePoint and MikroTik RouterOS flaws | — | — | — | SEP 25, 2026 |
| CVE-2026-5430 | CISA flags six exploited flaws in VPN, SD-WAN and commerce platforms | — | — | — | SEP 25, 2026 |
| CVE-2026-87902 | CISA confirms attacks on WordPress core file inclusion flaw | — | — | KEV | SEP 25, 2026 |
| CVE-2026-93952 | Arista VeloCloud OrchestratorOn-Prem Input Validation Flaw (CVE-2026-93952) | Arista VeloCloud Orchestrator (VCO) On-Prem | 10.0 | KEV | SEP 24, 2026 |
| CVE-2026-85102 | 2 CVEs: Check Point Quantum Security Gateway & Check Point Quantum Security Management (CVE-2026-85102) | Check Point Quantum Security Gateway, Check Point Quantum Security Management | 9.8 | KEV | SEP 24, 2026 |
| CVE-2026-93616 | Management Server directory traversal and file upload | Check Point Quantum Security Gateway, Check Point Quantum Security Management | 9.8 | KEV | SEP 24, 2026 |
| CVE-2026-94127 | F5 BIG-IP APM Vulnerability (CVE-2026-94127) | F5 BIG-IP APM | 9.8 | KEV | SEP 24, 2026 |
| CVE-2026-32566 | ACPT- Custom Post Types Plugin for WordPress Privilege Escalation (CVE-2026-32566) | ACPT (Pro) - Custom Post Types Plugin for WordPress, ACPT (Pro) (through 2.0.63) | 9.8 | KEV | SEP 20, 2026 |
| CVE-2026-87886 | Acronis Backup plugin for cPanel & WHM Privilege Escalation (CVE-2026-87886) | Acronis Backup plugin for cPanel & WHM (before 1.9.3.1021), Acronis Backup extension for Plesk (before 1.8.11.638), Acronis Backup plugin for DirectAdmin (before 1.2.3.238) | 7.8 | KEV | SEP 20, 2026 |
| CVE-2026-57739 | AcyMailing SMTP Newsletter SQL Injection (CVE-2026-57739) | AcyMailing SMTP Newsletter, AcyMailing (through 10.11.0) | 9.3 | KEV | SEP 20, 2026 |
| CVE-2026-71362 | Adobe Commerce Privilege Escalation (CVE-2026-71362) | Adobe Commerce, Magento | 9.1 | KEV | SEP 20, 2026 |
| CVE-2026-32558 | Affiliate Pro - Affiliate Program for WooCommerce & WordPress Privilege Escalation (CVE-2026-32558) | Affiliate Pro - Affiliate Program for WooCommerce & WordPress, Affiliate Pro (through 8.9.1) | 9.8 | KEV | SEP 20, 2026 |
| CVE-2021-23758 | Ajax.NET Professional Insecure Deserialization (CVE-2021-23758) | Ajax.NET Professional (ajaxpro.2, all versions) | 8.1 | KEV | SEP 20, 2026 |
| CVE-2026-9055 | Amelia Privilege Escalation (CVE-2026-9055) | Amelia, Melograno Booking for Appointments and Events Calendar – Amelia | 9.8 | KEV | SEP 20, 2026 |
| CVE-2026-50752 | Check Point Quantum Security Gateway Vulnerability (CVE-2026-50752) | Check Point Quantum Security Gateway | 7.4 | KEV | SEP 20, 2026 |
| CVE-2026-42031 | CKAN SQL Injection (CVE-2026-42031) | CKAN, okfn CKAN (before 2.10.10 and 2.11.5) | 9.8 | KEV | SEP 20, 2026 |
| CVE-2025-60698 | D-Link DIR-882 Vulnerability (CVE-2025-60698) | D-Link DIR-882 (firmware DIR882A1_FW102B02) | 7.3 | KEV | SEP 20, 2026 |
| CVE-2026-41948 | Dify Path Traversal (CVE-2026-41948) | Dify, Dify (1.14.1 and prior) | 9.4 | KEV | SEP 20, 2026 |
| CVE-2026-11613 | Divi Ajax Filter Vulnerability (CVE-2026-11613) | Divi Ajax Filter, Divi Engine Divi Ajax Filter (through 5.1.2) | 9.8 | KEV | SEP 20, 2026 |
| CVE-2026-89013 | Dolibarr ERP/CRM Vulnerability (CVE-2026-89013) | Dolibarr ERP/CRM (23.0.4 before 24.0.1) | 7.5 | KEV | SEP 20, 2026 |
| CVE-2026-18781 | Drag and Drop Multiple File Upload for Contact Form 7 Code Injection (CVE-2026-18781) | Drag and Drop Multiple File Upload for Contact Form 7 (before 1.3.9.9) | 8.1 | KEV | SEP 20, 2026 |
| CVE-2026-23536 | Red Hat OpenShift AI— Feast Feature Server Path Traversal (CVE-2026-23536) | Red Hat OpenShift AI (RHOAI) — Feast Feature Server | 7.5 | KEV | SEP 20, 2026 |
| CVE-2026-69255 | Flowise Code Injection (CVE-2026-69255) | Flowise, FlowiseAI Flowise (before 3.1.3) | 8.8 | KEV | SEP 20, 2026 |
| CVE-2025-6068 | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Vulnerability (CVE-2025-6068) | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel (up to 2.4.31) | 6.4 | KEV | SEP 20, 2026 |
| CVE-2026-84813 | GeoDirectory SQL Injection (CVE-2026-84813) | GeoDirectory, GeoDirectory (through 2.8.174) | 9.3 | KEV | SEP 20, 2026 |
| CVE-2026-63219 | GeoNetwork opensource Vulnerability (CVE-2026-63219) | GeoNetwork opensource (before 4.4.12 and 4.2.17) | 8.6 | KEV | SEP 20, 2026 |
| CVE-2026-58400 | GeoNetwork Code Injection (CVE-2026-58400) | GeoNetwork, Core-Geonetwork (before 4.4.12/4.2.17) | 9.1 | KEV | SEP 20, 2026 |
| CVE-2026-76904 | GeoTools SQL Injection (CVE-2026-76904) | GeoTools, GeoTools (30.5 through before 33.6/34.5/35.1) | 9.8 | KEV | SEP 20, 2026 |
| CVE-2026-60004 | Gitea Code Injection (CVE-2026-60004) | Gitea, Gitea (before 1.27.1) | 9.8 | KEV | SEP 20, 2026 |
| CVE-2026-58704 | Google Pixel Privilege Escalation (CVE-2026-58704) | Google Pixel, Android (Cellular Modem component) | 8.8 | KEV | SEP 20, 2026 |
| CVE-2026-84434 | Gravity Forms Vulnerability (CVE-2026-84434) | Gravity Forms (up to 3.1.0.4) | — | KEV | SEP 20, 2026 |
| CVE-2026-18562 | HUSKY – Products Filter Professional for WooCommerce Vulnerability (CVE-2026-18562) | HUSKY – Products Filter Professional for WooCommerce (up to 1.4.3) | 6.1 | KEV | SEP 20, 2026 |
| CVE-2026-54196 | JetFormBuilder Privilege Escalation (CVE-2026-54196) | JetFormBuilder (up to 3.6.1) | 6.8 | KEV | SEP 20, 2026 |
| CVE-2026-66384 | JFrog Artifactory Path Traversal (CVE-2026-66384) | JFrog Artifactory | 5.3 | KEV | SEP 20, 2026 |
| CVE-2026-87827 | KGUARD DVR devices Vulnerability (CVE-2026-87827) | KGUARD DVR devices (firmware dating from 2016; D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, D99xx variants) | — | KEV | SEP 20, 2026 |
| CVE-2026-16747 | Kirki Vulnerability (CVE-2026-16747) | Kirki (before 6.2.1) | 6.5 | KEV | SEP 20, 2026 |
No CVEs matched that filter.