Cyber Cookie mascotCyber Cookie
Menu ▾

CVE Repository

All vulnerabilities tracked across every issue.

CVE-2026-85706criticalCVSS 10

GitLab CE/EE (versions 18.7–19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2)

GitLab is a web-based platform that teams use to host, review, and collaborate on software code.

Issue #87
CVE-2026-20079criticalCVSS 10

Cisco Secure Firewall Management Center (versions prior to patched releases)

A centralised management platform used by network administrators to control and monitor Cisco firewall devices across an organisation's infrastructure.

Issue #85
No CVE IDcritical

Adobe Commerce / Magento (versions 2.4.7, 2.4.8, 2.4.9)

Adobe Commerce, built on the open-source Magento platform, is the software that powers the checkout, product catalogue, and payment processing for thousands of online shops worldwide.

Issue #83
CVE-2026-83548criticalCVSS 10

SonicWall SMA 1000 (versions 12.4.3-03453 / 12.5.0-02835 and older)

A remote access gateway used by organisations to let employees connect securely to corporate networks from outside the office.

Issue #81
CVE-2026-66066criticalCVSS 9.5

Ruby on Rails (versions prior to 8.1.3.1 and earlier patched releases)

A popular open-source web application framework used by developers to build websites and web services — including many you use every day without knowing it.

Issue #79
CVE-2026-82078highCVSS 8.8

PaperCut NG and PaperCut MF (all unpatched versions)

PaperCut NG and MF are print management platforms used by universities, corporations, and governments to control and monitor printing across Canon, Epson, Xerox, Brother, and other devices.

Issue #77

Zimbra Collaboration Suite (versions prior to v10.1.20)

A widely used platform that combines email, calendar, contacts, and file sharing — common in government agencies, universities, and mid-to-large businesses.

Issue #75

Spring for GraphQL (versions affected, see advisory)

Part of Broadcom's Spring application framework, a widely used open-source toolkit for building Java-based enterprise software — Spring for GraphQL specifically handles APIs built using the GraphQL query language.

Issue #73
CVE-2026-69836criticalCVSS 10

Microsoft Entra ID (all versions prior to Microsoft's server-side patch)

Microsoft Entra ID is a cloud-based identity and access management service — the system that verifies who you are and controls what you can access across Microsoft 365 and connected apps.

Issue #70
CVE-2025-62593criticalCVSS 9.4

Ray (versions below 2.52.0)

Ray is an open-source Python framework used by developers and data scientists to run large AI and machine learning workloads across many computers at once.

Issue #68
No CVE IDhigh

Evooo1Bot Linux Botnet (Multiple Edge Devices)

Evooo1Bot is a new botnet — a network of hijacked devices secretly controlled by an attacker — built on leaked source code from the notorious Mirai malware. Researchers at Fortinet's FortiGuard Labs identified it after seeing coordinated attacks on edge devices across multiple regions since July 2026, as reported by Infosecurity Magazine.

Issue #65
CVE-2026-59310criticalCVSS 9.8

VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k / 8.0 U2f)

Centralised IT management software that lets organisations control, monitor, and configure all their virtual machines and servers from a single platform.

Issue #64
CVE-2026-48362criticalCVSS 10

Adobe ColdFusion (versions prior to 2025.0.12 and 2023.0.23)

ColdFusion is Adobe's web application server platform, used by developers to build and host database-driven websites and internal business applications.

Issue #63
CVE-2026-58231criticalCVSS 10

SAP Commerce Cloud (Data Hub Adapter, all versions prior to patch)

An enterprise e-commerce platform used by large retailers and manufacturers to manage online storefronts, product catalogues, and customer data.

Issue #62

Progress Kemp LoadMaster (GA v7.2.63.1 and below, LTSF v7.2.54.17 and below)

LoadMaster is an application delivery controller and load balancer used by enterprises and government agencies worldwide to distribute web traffic across multiple servers and keep applications running reliably. Progress Software reports over 100,000 deployments, including across 80% of Fortune 500 companies.

Issue #61
No CVE IDhigh

Connective eID Browser Extension (Belgium, all versions prior to late July 2026 patch)

A browser extension used by over two million people in Belgium to authenticate their identity and sign documents digitally with their national electronic ID card. It is used by eight of Belgium's ten largest banks and more than 60 government agencies.

Issue #60
No CVE IDhigh

Atlassian Rovo (RovoBlast, parameter-to-prompt injection)

An enterprise AI assistant embedded across Jira, Confluence, and Bitbucket that can autonomously conduct multi-step research tasks and interact with third-party tools including Slack, Microsoft 365, and Google Workspace.

Issue #59
CVE-2026-20272criticalCVSS 9.8

Cisco IOS XE Software (Command Injection)

The operating system that runs on a wide range of Cisco routers and switches used in corporate and government networks worldwide.

Issue #58
CVE-2026-63077criticalCVSS 9.8

JetBrains TeamCity (all on-premise versions before the patched release)

A continuous integration and delivery (CI/CD) server — software development teams use it to automatically build, test, and deploy their code.

Issue #57
CVE-2026-58048criticalCVSS 9.4

cPanel & WHM (all supported versions), WP Squared

cPanel is the control panel software that web hosting companies use to let customers manage websites, email accounts, and databases through a browser interface. WHM (Web Host Manager) sits above it, used by hosting administrators to manage the server itself.

Issue #56

N-able N-central (versions prior to 2026.3.1.7)

N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) — companies that handle IT infrastructure for other businesses — to monitor, patch, and remotely access their clients' servers and devices.

Issue #55
CVE-2026-15409criticalCVSS 10

SonicWall SMA1000 (all versions prior to the patch issued July 14, 2026)

A hardware appliance organisations use to give remote workers secure access to internal corporate networks, sitting at the edge of the network as a gateway.

Issue #54
No CVE IDunrated

Coldcard Hardware Wallet (Mk3 firmware 4.0.1–4.1.9; Mk4/Mk5 before 5.6.0; Q before 1.5.0Q)

Coldcard is a Bitcoin-only hardware wallet — a physical device that stores your private keys offline, made by Canadian company Coinkite.

Issue #53
CVE-2026-48449criticalCVSS 10

Adobe Campaign Classic (versions prior to 7.4.3 build 9398)

Adobe Campaign Classic is enterprise marketing software used by large organisations to manage and automate mass email, SMS, and direct mail campaigns.

Issue #52
CVE-2026-3545criticalCVSS 9.8

Google Chrome (versions prior to Chrome 145)

Google Chrome is the world's most widely used web browser, installed on billions of devices for everyday browsing, work, and personal use.

Issue #51
CVE-2026-66066criticalCVSS 9.5

Ruby on Rails Active Storage (versions 7.0.0–8.1.3 and Rails 6.x with Vips enabled)

Ruby on Rails is a popular open-source web development framework used to build web applications. Active Storage is its built-in system for handling file uploads.

Issue #50
CVE-2026-53921criticalCVSS 9.8

OpenWrt (versions prior to 24.10.8 and 25.12.5)

OpenWrt is an open-source operating system that replaces the factory firmware on home and small-business routers, giving users more control over their network hardware.

Issue #49
CVE-2026-63077criticalCVSS 9.8

JetBrains TeamCity On-Premises (all versions before 2025.11.7 and 2026.1.3)

TeamCity is a continuous integration and delivery server made by JetBrains — software used by development teams to automatically build, test, and deploy code.

Issue #48
CVE-2026-16723criticalCVSS 9

Alibaba Fastjson (versions 1.2.68 through 1.2.83)

Fastjson is an open-source Java library maintained by Alibaba that parses and generates JSON (a common data exchange format), used extensively in enterprise web services and APIs.

Issue #47
CVE-2026-54121highCVSS 8.8

Microsoft Active Directory Certificate Services (Windows Server 2012 through 2025)

Microsoft's built-in system for issuing digital certificates inside a corporate Windows network — used to prove that computers and users are who they claim to be.

Issue #46
CVE-2026-12569criticalCVSS 9.3

PTC Windchill and FlexPLM (all versions before June 2026 patches)

CVE-2026-12569 is a critical unsafe deserialization vulnerability (a flaw where an application processes attacker-supplied data as trusted executable instructions without verifying it first). Successful exploitation allows an unauthenticated attacker to execute arbitrary code on the vulnerable server, as reported by Bleeping Computer.

Issue #45
CVE-2026-29059highCVSS 7.5

Windmill (versions prior to 1.603.3)

Windmill is an open-source developer platform that lets teams build and run automated scripts, workflows, and internal tools through a web interface.

Issue #44
CVE-2026-50522criticalCVSS 9.8

Microsoft SharePoint Server (all supported on-premises versions)

SharePoint is Microsoft's on-premises collaboration platform used by organisations to host internal websites, share documents, and manage team workflows.

Issue #43
CVE-2026-6875criticalCVSS 9.5

ServiceNow AI Platform (unpatched instances before June 2026 patch releases)

ServiceNow is a cloud-based platform used by businesses to manage IT operations, employee workflows, and customer service processes.

Issue #42
CVE-2026-42533criticalCVSS 9.2

NGINX Web Server (versions 0.9.6 through 1.31.2)

NGINX is a web server used by a large portion of the internet to deliver websites and handle web traffic — it sits between your browser and the application behind it.

Issue #41

7-Zip (versions below 26.02)

7-Zip is a free, widely used file compression and extraction tool for Windows that handles formats including ZIP, RAR, and XZ archives.

Issue #40
CVE-2026-63030criticalCVSS 7.5

WordPress Core (versions 6.9.0 through 7.0.1)

WordPress is the software that powers roughly half of all websites on the internet, from personal blogs to major news outlets.

Issue #39
CVE-2026-25089criticalCVSS 9.1

Fortinet FortiSandbox (versions 5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2 versions, and FortiSandbox Cloud/PaaS 5.0.4–5.0.5)

A Fortinet security product that analyses suspicious files and network traffic in an isolated environment to detect malware before it reaches the rest of a network.

Issue #38
CVE-2026-53412criticalCVSS 9.8

Zoom Desktop Client for Windows (versions before 6.3.10)

Zoom is the video conferencing and online meetings platform used by hundreds of millions of people worldwide for work calls, webinars, and remote collaboration.

Issue #37
CVE-2026-15409criticalCVSS 10

SonicWall SMA 1000 Series (versions below 12.4.3-03453 / 12.5.0-02835)

A hardware and virtual appliance that organisations use to give remote workers secure access to internal corporate networks and applications.

Issue #36

Balbooa Forms for Joomla (versions prior to 2.4.1)

A drag-and-drop form builder for Joomla websites that lets site owners create contact forms with file upload functionality.

Issue #35
No CVE IDhigh

CMS Platforms (globally targeted, unpatched installs)

A content management system (CMS) is software that powers websites, letting users publish and manage content without writing code directly. WordPress, Drupal, and Joomla are common examples.

Issue #34

Gitea Docker Image (versions 1.26.2 and below)

Gitea is an open-source, self-hosted platform for storing and managing source code — think a version of GitHub or GitLab that a company runs on its own servers.

Issue #33
CVE-2026-50656highCVSS 7.8

Windows Defender (Microsoft Malware Protection Engine versions prior to 1.1.26060.3008)

Microsoft's built-in antivirus and security tool included with every modern Windows installation.

Issue #32
CVE-2026-50746criticalCVSS 10

UniFi Connect Application (versions 3.4.16 and below)

UniFi Connect is a Ubiquiti platform for managing displays, intercom systems, and building access hardware — popular in small offices, schools, and home setups.

Issue #31
CVE-2026-43499highCVSS 7.8

Linux Kernel (versions with futex code dating to 2011)

The kernel is the core of the Linux operating system — the layer that manages memory, processes, and hardware on behalf of every program running on the machine.

Issue #30
CVE-2026-48282criticalCVSS 10

Adobe ColdFusion (versions 2025.9, 2023.20 and earlier)

A commercial platform used by developers to build and deploy enterprise websites and web applications.

Issue #29

ClamAV (versions affected across multiple release branches)

ClamAV is a free, open-source antivirus scanning engine maintained by Cisco's Talos group, widely used inside email gateways, file upload systems, and security tooling at organisations of all sizes.

Issue #28

SimpleHelp RMM (versions prior to the patched release)

SimpleHelp is a remote support and monitoring tool used by IT teams and managed service providers to access and manage computers remotely.

Issue #27
CVE-2026-6682highCVSS 7.6

FatFs (no upstream fix available for this CVE)

FatFs is a tiny open-source library that lets embedded devices — security cameras, drones, hardware crypto wallets, industrial controllers — read and write USB drives and SD cards using the FAT and exFAT formats found on most removable storage.

Issue #26
CVE-2026-50548criticalCVSS 9.8

Cursor AI Code Editor (versions before 3.0)

Cursor is an AI-powered code editor used by software developers to write, edit, and review code, with a built-in AI agent that can execute terminal commands automatically on the developer's behalf.

Issue #25
CVE-2026-48276criticalCVSS 10

Adobe ColdFusion (versions prior to ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10)

ColdFusion is Adobe's web application server platform, used by organisations to build and run database-driven websites and internal business applications.

Issue #24
CVE-2026-10816highCVSS 7.7

Citrix NetScaler ADC and NetScaler Gateway (versions prior to 14.1-72.61 and 13.1-63.18)

Citrix NetScaler products are network appliances used by organisations to manage, secure, and accelerate traffic flowing into their applications and services.

Issue #23
CVE-2026-8037criticalCVSS 9.8

Progress Kemp LoadMaster (GA v7.2.63.1 and older, LTSF v7.2.54.17 and older)

An application delivery controller and load balancer that enterprises use to manage and distribute incoming traffic across servers — it sits at the network edge, making it a high-value target.

Issue #22
CVE-2026-55200criticalCVSS 9.2

libssh2 (versions 1.11.1 and below)

A C library that gives software the ability to connect to SSH servers — it is embedded inside widely-used tools including curl, Git, and PHP, meaning it quietly runs inside many applications you use every day without advertising its presence.

Issue #21
No CVE IDhigh

Cisco Unified Communications Manager (active exploitation, patch version unconfirmed)

Cisco Unified Communications Manager (Unified CM) is enterprise software that manages phone calls, video conferencing, and messaging for large organisations — essentially the switchboard that ties all internal communications together.

Issue #20
CVE-2026-12957highCVSS 8.5

Amazon Q Developer (versions before the May 12 patch)

Amazon Q Developer is an AI-powered coding assistant, built as a Visual Studio Code extension, that offers code suggestions, automated refactoring, and the ability to connect to external tools and services.

Issue #19

PTC Windchill and FlexPLM (all versions prior to patched releases)

Windchill is enterprise software used by manufacturers — in industries like automotive, aerospace, and defence — to manage the full lifecycle of a product, from design files and engineering specs through to compliance records. Think of it as the document nervous system of a factory floor.

Issue #18
CVE-2025-67038criticalCVSS 9.8

Lantronix EDS5000 Series (firmware 2.1.0.0R3 and below)

A serial-to-IP converter — a piece of hardware that connects older serial devices (like industrial sensors or legacy equipment) to a modern network, often found in factories, hospitals, and infrastructure environments.

Issue #17

Cisco Unified Communications Manager (Unified CM)

Cisco Unified CM is an enterprise on-premises platform that manages voice calls, video conferencing, and internal communications for large organisations — the phone system backbone for thousands of businesses.

Issue #16
CVE-2026-8461highCVSS 8.8

FFmpeg / libavcodec MagicYUV decoder (all versions before 8.1.2)

FFmpeg is an open-source library used by hundreds of applications — including Kodi, OBS Studio, Jellyfin, Nextcloud, PhotoPrism, and messaging platforms like Slack and Telegram — to process, decode, and encode video files.

Issue #15

Squid Proxy (versions before 7.6 / before patch merged in Squid 8)

Squid is a widely used open-source web proxy that organisations run to cache web traffic, reduce bandwidth, and speed up browsing for everyone sharing that network connection.

Issue #14
CVE-2026-4020mediumCVSS 5.3

Gravity SMTP WordPress Plugin (versions below 2.1.5)

A WordPress plugin installed on roughly 100,000 websites that manages transactional email sending by connecting to third-party services like Amazon SES, Google, and Mailjet.

Issue #12
CVE-2026-42530criticalCVSS 9.2

NGINX Open Source (versions using the HTTP/3 QUIC module)

NGINX is open-source web server software that sits in front of websites and applications to handle incoming traffic, widely used as a reverse proxy and load balancer across the internet.

Issue #11
CVE-2026-20181criticalCVSS 9.1

Cisco ISE (versions prior to 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 4)

Identity Services Engine (ISE) is software many large organizations use to control which devices and users are allowed onto their network.

Issue #10
CVE-2026-39813criticalCVSS 9.1

Fortinet FortiSandbox (Multiple Versions)

FortiSandbox is a cybersecurity product made by Fortinet that organisations use to detect malware and advanced threats by running suspicious files and code in an isolated environment before they reach the network.

Issue #9
CVE-2026-0257highCVSS 7.8

Palo Alto PAN-OS GlobalProtect (actively exploited)

PAN-OS is the operating system running Palo Alto Networks firewalls and network security appliances — the software layer that decides what traffic enters and leaves an organisation's network.

Issue #8
CVE-2026-20253criticalCVSS 9.8

Splunk Enterprise (versions 10.0.6 and below, 10.2.3 and below)

Splunk is a platform used by IT and security teams to collect, search, and analyse machine-generated data — logs, alerts, and system events — across an organisation's infrastructure.

Issue #7
No CVE IDunrated

phpBB (versions 3.3.16 and below / 4.0.0-a2 and below)

phpBB is a free, open-source web forum platform still running thousands of active community discussion boards worldwide.

Issue #6

Ivanti Sentry (versions before 10.5.2, 10.6.2, and 10.7.1)

A security gateway appliance (formerly MobileIron Sentry) that organisations use to manage and secure mobile device access to enterprise email and internal applications.

Issue #5
CVE-2026-25089criticalCVSS 9.1

FortiSandbox (versions 5.0.0–5.0.5 and 4.4.0–4.4.8)

FortiSandbox is a security tool made by Fortinet that analyses suspicious files and web content in an isolated environment to detect malware before it reaches a network.

Issue #4

Google Chrome (versions below 149.0.7827.102)

The world's most widely used web browser, built by Google and installed on most Windows, Mac, and Linux computers.

Issue #3

Check Point Remote Access VPN and Mobile Access

A security product made by Israeli cybersecurity company Check Point that lets employees connect securely to their company's network from outside the office.

Issue #2
CVE-2026-20245highCVSS 7.8

Cisco Catalyst SD-WAN Manager (unpatched)

A network management platform that lets organisations centrally control and monitor their wide-area network (the system connecting offices, branches, and cloud services together).

Issue #1