Vulnerability catalog

Actively exploited CVEs with matching Yasna coverage.

Browse imported exploited-vulnerability catalog data and jump into the headlines that mention each CVE.

1623 vulnerabilities tracked 250 with matching headlines

Search vulnerabilities

Search by CVE, vendor, product, or vulnerability name.

CISA KEV Added 12 Jun 2026

CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools - Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

CVE record 3 matching headlines Latest mention 2 weeks, 1 day ago Ransomware: Known Due 15 Jun 2026
CISA KEV Added 8 Jun 2026

CVE-2026-50751

Check Point Security Gateway - Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVE record 0 matching headlines Ransomware: Known Due 11 Jun 2026
CISA KEV Added 27 May 2026

CVE-2026-45321

TanStack TanStack - TanStack Unspecified Vulnerability
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

CVE record 0 matching headlines Ransomware: Known Due 10 Jun 2026
CISA KEV Added 27 May 2026

CVE-2026-48027

Nx Nx Console - Nx Console Embedded Malicious Code Vulnerability
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

CVE record 0 matching headlines Ransomware: Known Due 10 Jun 2026
CISA KEV Added 30 Apr 2026

CVE-2026-41940

WebPros cPanel & WHM and WP2 (WordPress Squared) - WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE record 3 matching headlines Latest mention 1 month, 2 weeks ago Ransomware: Known Due 3 May 2026
CISA KEV Added 28 Apr 2026

CVE-2024-1708

ConnectWise ScreenConnect - ConnectWise ScreenConnect Path Traversal Vulnerability
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

CVE record 3 matching headlines Latest mention 2 years, 3 months ago Ransomware: Known Due 12 May 2026
CISA KEV Added 24 Apr 2026

CVE-2024-57726

SimpleHelp SimpleHelp - SimpleHelp Missing Authorization Vulnerability
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

CVE record 0 matching headlines Ransomware: Known Due 8 May 2026
CISA KEV Added 24 Apr 2026

CVE-2024-57728

SimpleHelp SimpleHelp - SimpleHelp Path Traversal Vulnerability
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CVE record 0 matching headlines Ransomware: Known Due 8 May 2026
CISA KEV Added 20 Apr 2026

CVE-2023-27351

PaperCut NG/MF - PaperCut NG/MF Improper Authentication Vulnerability
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

CVE record 0 matching headlines Ransomware: Known Due 4 May 2026
CISA KEV Added 20 Apr 2026

CVE-2024-27199

JetBrains TeamCity - JetBrains TeamCity Relative Path Traversal Vulnerability
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

CVE record 1 matching headline Latest mention 2 years, 3 months ago Ransomware: Known Due 4 May 2026
CISA KEV Added 13 Apr 2026

CVE-2023-21529

Microsoft Exchange Server - Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

CVE record 0 matching headlines Ransomware: Known Due 27 Apr 2026
CISA KEV Added 19 Mar 2026

CVE-2026-20131

Cisco Secure Firewall Management Center (FMC) - Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

CVE record 4 matching headlines Latest mention 3 months ago Ransomware: Known Due 22 Mar 2026
CISA KEV Added 13 Feb 2026

CVE-2026-1731

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) - BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

CVE record 3 matching headlines Latest mention 2 months, 1 week ago Ransomware: Known Due 16 Feb 2026
CISA KEV Added 5 Feb 2026

CVE-2026-24423

SmarterTools SmarterMail - SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.

CVE record 2 matching headlines Latest mention 4 months, 1 week ago Ransomware: Known Due 26 Feb 2026
CISA KEV Added 26 Jan 2026

CVE-2025-52691

SmarterTools SmarterMail - SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

CVE record 0 matching headlines Ransomware: Known Due 16 Feb 2026
CISA KEV Added 26 Jan 2026

CVE-2026-23760

SmarterTools SmarterMail - SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

CVE record 1 matching headline Latest mention 4 months, 1 week ago Ransomware: Known Due 16 Feb 2026
CISA KEV Added 5 Dec 2025

CVE-2025-55182

Meta React Server Components - Meta React Server Components Remote Code Execution Vulnerability
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

CVE record 14 matching headlines Latest mention 2 months, 3 weeks ago Ransomware: Known Due 12 Dec 2025
CISA KEV Added 20 Oct 2025

CVE-2025-61884

Oracle E-Business Suite - Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

CVE record 3 matching headlines Latest mention 8 months, 1 week ago Ransomware: Known Due 10 Nov 2025
CISA KEV Added 6 Oct 2025

CVE-2025-61882

Oracle E-Business Suite - Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

CVE record 4 matching headlines Latest mention 8 months ago Ransomware: Known Due 27 Oct 2025
CISA KEV Added 29 Sep 2025

CVE-2025-10035

Fortra GoAnywhere MFT - Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVE record 4 matching headlines Latest mention 8 months, 2 weeks ago Ransomware: Known Due 20 Oct 2025
CISA KEV Added 22 Jul 2025

CVE-2025-49704

Microsoft SharePoint - Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

CVE record 1 matching headline Latest mention 11 months ago Ransomware: Known Due 23 Jul 2025
CISA KEV Added 22 Jul 2025

CVE-2025-49706

Microsoft SharePoint - Microsoft SharePoint Improper Authentication Vulnerability
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

CVE record 1 matching headline Latest mention 11 months ago Ransomware: Known Due 23 Jul 2025
CISA KEV Added 20 Jul 2025

CVE-2025-53770

Microsoft SharePoint - Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

CVE record 5 matching headlines Latest mention 8 months ago Ransomware: Known Due 21 Jul 2025
CISA KEV Added 10 Jul 2025

CVE-2025-5777

Citrix NetScaler ADC and Gateway - Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

CVE record 11 matching headlines Latest mention 7 months, 2 weeks ago Ransomware: Known Due 11 Jul 2025
CISA KEV Added 25 Jun 2025

CVE-2019-6693

Fortinet FortiOS - Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

CVE record 0 matching headlines Ransomware: Known Due 16 Jul 2025
CISA KEV Added 29 Apr 2025

CVE-2025-31324

SAP NetWeaver - SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

CVE record 7 matching headlines Latest mention 10 months, 4 weeks ago Ransomware: Known Due 20 May 2025
CISA KEV Added 8 Apr 2025

CVE-2025-29824

Microsoft Windows - Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CVE record 2 matching headlines Latest mention 10 months, 1 week ago Ransomware: Known Due 29 Apr 2025
CISA KEV Added 7 Apr 2025

CVE-2025-31161

CrushFTP CrushFTP - CrushFTP Authentication Bypass Vulnerability
CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

CVE record 1 matching headline Latest mention 1 year, 2 months ago Ransomware: Known Due 28 Apr 2025
CISA KEV Added 4 Apr 2025

CVE-2025-22457

Ivanti Connect Secure, Policy Secure, and ZTA Gateways - Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

CVE record 0 matching headlines Ransomware: Known Due 11 Apr 2025
CISA KEV Added 18 Mar 2025

CVE-2025-24472

Fortinet FortiOS and FortiProxy - Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

CVE record 1 matching headline Latest mention 1 year, 3 months ago Ransomware: Known Due 8 Apr 2025
CISA KEV Added 11 Mar 2025

CVE-2025-26633

Microsoft Windows - Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.

CVE record 3 matching headlines Latest mention 1 year, 2 months ago Ransomware: Known Due 1 Apr 2025
CISA KEV Added 4 Mar 2025

CVE-2025-22225

VMware ESXi - VMware ESXi Arbitrary Write Vulnerability
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

CVE record 0 matching headlines Ransomware: Known Due 25 Mar 2025
CISA KEV Added 3 Mar 2025

CVE-2018-8639

Microsoft Windows - Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

CVE record 0 matching headlines Ransomware: Known Due 24 Mar 2025
CISA KEV Added 18 Feb 2025

CVE-2024-53704

SonicWall SonicOS - SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

CVE record 2 matching headlines Latest mention 1 year, 4 months ago Ransomware: Known Due 11 Mar 2025
CISA KEV Added 13 Feb 2025

CVE-2024-57727

SimpleHelp SimpleHelp - SimpleHelp Path Traversal Vulnerability
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

CVE record 0 matching headlines Ransomware: Known Due 6 Mar 2025
CISA KEV Added 24 Jan 2025

CVE-2025-23006

SonicWall SMA1000 Appliances - SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

CVE record 1 matching headline Latest mention 1 year, 5 months ago Ransomware: Known Due 14 Feb 2025
CISA KEV Added 14 Jan 2025

CVE-2024-55591

Fortinet FortiOS and FortiProxy - Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVE record 0 matching headlines Ransomware: Known Due 21 Jan 2025
CISA KEV Added 13 Jan 2025

CVE-2023-48365

Qlik Sense - Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

CVE record 0 matching headlines Ransomware: Known Due 3 Feb 2025
CISA KEV Added 8 Jan 2025

CVE-2025-0282

Ivanti Connect Secure, Policy Secure, and ZTA Gateways - Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

CVE record 5 matching headlines Latest mention 4 months ago Ransomware: Known Due 15 Jan 2025
CISA KEV Added 7 Jan 2025

CVE-2024-41713

Mitel MiCollab - Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

CVE record 0 matching headlines Ransomware: Known Due 28 Jan 2025
CISA KEV Added 7 Jan 2025

CVE-2024-55550

Mitel MiCollab - Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

CVE record 0 matching headlines Ransomware: Known Due 28 Jan 2025
CISA KEV Added 17 Dec 2024

CVE-2024-55956

Cleo Multiple Products - Cleo Multiple Products Unauthenticated File Upload Vulnerability
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

CVE record 0 matching headlines Ransomware: Known Due 7 Jan 2025
CISA KEV Added 13 Dec 2024

CVE-2024-50623

Cleo Multiple Products - Cleo Multiple Products Unrestricted File Upload Vulnerability
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

CVE record 0 matching headlines Ransomware: Known Due 3 Jan 2025
CISA KEV Added 4 Dec 2024

CVE-2024-51378

CyberPersons CyberPanel - CyberPanel Incorrect Default Permissions Vulnerability
CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.

CVE record 0 matching headlines Ransomware: Known Due 25 Dec 2024
CISA KEV Added 3 Dec 2024

CVE-2024-11667

Zyxel Multiple Firewalls - Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

CVE record 0 matching headlines Ransomware: Known Due 24 Dec 2024
CISA KEV Added 25 Nov 2024

CVE-2023-28461

Array Networks AG/vxAG ArrayOS - Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.

CVE record 0 matching headlines Ransomware: Known Due 16 Dec 2024
CISA KEV Added 18 Nov 2024

CVE-2024-0012

Palo Alto Networks PAN-OS - Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

CVE record 0 matching headlines Ransomware: Known Due 9 Dec 2024
CISA KEV Added 18 Nov 2024

CVE-2024-9474

Palo Alto Networks PAN-OS - Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

CVE record 0 matching headlines Ransomware: Known Due 9 Dec 2024
CISA KEV Added 12 Nov 2024

CVE-2024-49039

Microsoft Windows - Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

CVE record 0 matching headlines Ransomware: Known Due 3 Dec 2024
CISA KEV Added 7 Nov 2024

CVE-2024-51567

CyberPersons CyberPanel - CyberPanel Incorrect Default Permissions Vulnerability
CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

CVE record 0 matching headlines Ransomware: Known Due 28 Nov 2024