🚨 Patch first — highest riskAll critical →
10.0CVE-2025-60206Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows…Unknown10.0CVE-2025-57870A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux…Arcgis Server10.0CVE-2025-49060Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows…Unknown10.0CVE-2025-48106Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows…Unknown10.0CVE-2025-9846Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information…Unknown10.0CVE-2025-2857Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a…Firefox10.0CVE-2020-0796A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1…Windows 10 1903KEV9.9CVE-2025-61913Flowise is a drag & drop user interface to build a customized large language model flow.Flowise9.9CVE-2025-58048Paymenter is a free and open-source webshop solution for hostings.Unknown9.8CVE-2026-1842Microsoft Message Queuing Remote Code ExecutionMicrosoft MSMQKEVCERT-In🔥 Actively exploited (CISA KEV)All KEV →
10.0CVE-2020-0796A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1…Windows 10 1903KEV9.8CVE-2018-19949If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.QtsKEV9.8CVE-2020-12812An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may…FortiosKEV9.8CVE-2019-2725Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web…Agile Product Lifecycle ManagementKEV9.8CVE-2018-19323The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57,…Aorus Graphics EngineKEV9.8CVE-2018-7602A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x.DrupalKEV9.8CVE-2016-1019Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service…Flash Player Desktop RuntimeKEV9.8CVE-2012-1710Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware…Fusion MiddlewareKEVSeverity mix
CRITICAL102 · 18%
HIGH475 · 82%
MEDIUM0 · 0%
LOW0 · 0%
Latest published
CVE-2026-102489 · 2d agoCVE-2026-102490 · 2d agoCVE-2026-104286 · 3d agoCVE-2026-76504 · 4d agoCVE-2026-86950 · 5d agoCVE-2026-88771 · 7d agoCVE-2026-88772 · 7d agoCVE-2026-87902 · 9d agoWhatsApp + email alerts
Subscribe to vendors and products; get pinged the moment a critical or KEV entry lands.
Manage alerts →