CVEs NewScan detects
Every CVE NewScan detects, newest first, with the technology it affects and the day the detection landed. Most are version-matched against a fingerprinted component — those link to a page with the affected range, the release that fixes it, and how the scanner reports it. The rest are reported by a check that observes the vulnerability or its precondition directly rather than matching a version, so the row names that check instead of linking to a version range. The list is generated from the detection packs themselves and grows daily — local, in-band scanning is free, so you can check any of these against your own systems without a licence.
245 CVEs · 148 critical · 84 high · 13 medium · 180 with a detail page
| CVE | Tech | Severity | Description | Added |
|---|---|---|---|---|
| CVE-2026-73604 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73603 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73602 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73601 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73488 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73487 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73486 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73485 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73483 | Flowise | critical | Flowise before 3.1.4: sandbox escapes and agent-node code injection - remote code execution on the Flowise host, unauthenticated in two of them | 2026-08-13 |
| CVE-2026-72794 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-13 |
| CVE-2026-72793 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-13 |
| CVE-2026-47717 | FUXA | high | Reported by NewScan's unauthenticated interface: Unauthenticated FUXA SCADA/HMI project | 2026-08-13 |
| CVE-2026-73211 | PeerTube | critical | PeerTube unauthenticated SQL injection from a federated peer, plus cross-origin video takeover | 2026-08-12 |
| CVE-2026-73090 | PeerTube | critical | PeerTube cross-origin video takeover via a federated Update activity | 2026-08-12 |
| CVE-2026-20349 | Cisco ASA/FTD WebVPN | high | Cisco ASA/FTD Remote Access SSL VPN unauthenticated reload - a single crafted HTTP request takes the VPN down (CVSS 8.6, KEV 2026-08-12) | 2026-08-12 |
| CVE-2026-72899 | Metabase | critical | Covered by the Metabase batch fix for CVE-2026-72898 | 2026-08-11 |
| CVE-2026-72898 | Metabase | critical | Metabase unauthenticated SQL injection to administrator (/api/session/reset_password, and public-link field filters) | 2026-08-11 |
| CVE-2023-38646 | Metabase | critical | Metabase pre-authentication remote code execution via a public setup token | 2026-08-11 |
| CVE-2026-69086 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-69083 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-68586 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-68585 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-68584 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-21858 | n8n | critical | n8n Form Webhook Content-Type confusion allows unauthenticated arbitrary file read ("Ni8mare") | 2026-08-10 |
| CVE-2025-68613 | n8n | critical | n8n expression sandbox escape allows authenticated remote code execution | 2026-08-10 |
| CVE-2019-9193 | PostgreSQL | high | Covered by the PostgreSQL batch fix for CVE-2018-1058 | 2026-08-10 |
| CVE-2018-1058 | PostgreSQL | high | PostgreSQL search_path privilege escalation: an unprivileged user can create objects that a superuser then executes | 2026-08-10 |
| CVE-2026-12971 | learnpress | medium | LearnPress SSRF: the instructor-role AI image-import feature fetches an arbitrary attacker-supplied URL server-side | 2026-08-10 |
| CVE-2026-67620 | REST APIs | high | Reported by NewScan's named-CVE check: test_ssrf | 2026-08-09 |
| CVE-2026-10595 | Web apps | high | Reported by NewScan's named-CVE check: test_url_path_traversal | 2026-08-09 |
| CVE-2026-8037 | Progress Kemp LoadMaster | critical | Pre-auth OS command injection in the LoadMaster API (/accessv2) -> arbitrary command execution on the appliance (CVSS 9.6) | 2026-08-08 |
| CVE-2026-61808 | lightrag | critical | Reported by NewScan's unauthenticated interface: Unauthenticated LightRAG API server (authentication disabled) | 2026-08-08 |
| CVE-2026-64638 | WordPress | high | XSS2Shell: WordPress core pre-auth reflected XSS on wp-login.php via a strip_tags()/KSES parser differential | 2026-08-08 |
| CVE-2026-14812 | Premium-SEO | critical | Premium-SEO is a malicious WordPress plugin, not a compromised one: every build ships an unauthenticated backdoor that creates a hidden administrator account (login prefix resource… | 2026-08-07 |
| CVE-2026-11976 | google-analytics-premium | critical | MonsterInsights Pro 10.2.0 shipped from a compromised update bucket: backdoored class-system-check.php hijacks the MonsterInsights/ExactMetrics update channel to an attacker server… | 2026-08-07 |
| CVE-2026-9205 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-9196 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-9130 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-9081 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8478 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8470 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8446 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-8182 | 2026-08-06 |
| CVE-2026-8183 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8182 | Langflow | critical | Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixed in the same range | 2026-08-06 |
| CVE-2026-7869 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-7658 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-7657 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-7646 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-68746 | livebook | critical | Reported by NewScan's unauthenticated interface: Unauthenticated Livebook notebook server | 2026-08-06 |
| CVE-2026-56164 | Microsoft SharePoint Server | critical | SharePoint Server on-premises remote code execution - actively exploited July 2026, chained for IIS machine-key theft | 2026-08-06 |
| CVE-2026-45659 | Microsoft SharePoint Server | critical | SharePoint Server on-premises remote code execution - actively exploited July 2026 | 2026-08-06 |
| CVE-2026-41940 | cPanel / WHM | critical | cPanel / WHM authentication bypass - unauthenticated administrative control of the hosting server, all supported versions | 2026-08-06 |
| CVE-2026-35616 | FortiClient EMS | critical | FortiClient EMS improper access control - unauthenticated code/command execution via crafted requests | 2026-08-06 |
| CVE-2026-32201 | Microsoft SharePoint Server | critical | SharePoint Server spoofing via improper input validation - a manipulated Referer plus a malformed query string bypasses the front-end authorization check | 2026-08-06 |
| CVE-2026-21643 | FortiClient EMS | critical | FortiClient EMS 7.4.4 pre-authentication SQL injection in the management server | 2026-08-06 |
| CVE-2026-18577 | N-able N-central | critical | N-able N-central authentication bypass - unauthenticated administrative control of the RMM server, and therefore of every endpoint it manages | 2026-08-06 |
| CVE-2026-17633 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17632 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17630 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17625 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17624 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17623 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-16232 | Check Point Security Gateway | critical | Check Point SmartConsole/management authentication bypass - exploited in the wild | 2026-08-06 |
| CVE-2026-10547 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-10128 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2025-64446 | FortiWeb | critical | FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself | 2026-08-06 |
| CVE-2025-61882 | Oracle E-Business Suite | critical | Oracle E-Business Suite pre-auth RCE in the internet-facing web tier - the Cl0p mass-extortion campaign (CVSS 9.8) | 2026-08-06 |
| CVE-2025-59287 | Microsoft WSUS | critical | Windows Server Update Services unauthenticated deserialization -> RCE as SYSTEM (CVSS 9.8) | 2026-08-06 |
| CVE-2025-5777 | Citrix NetScaler ADC/Gateway | critical | CitrixBleed 2: out-of-bounds memory disclosure on the login endpoint leaks session tokens, replayed to hijack sessions and bypass MFA (CVSS 9.3) | 2026-08-06 |
| CVE-2025-49844 | Redis | critical | RediShell: Lua use-after-free reachable from a crafted EVAL script -> remote code execution (CVSS 10.0) | 2026-08-06 |
| CVE-2025-20333 | Cisco ASA/FTD WebVPN | critical | Cisco ASA/FTD VPN web server buffer overflow - unauthenticated root RCE (ArcaneDoor-class; CISA ED 25-03) | 2026-08-06 |
| CVE-2025-10035 | GoAnywhere MFT | critical | GoAnywhere MFT License Servlet deserialization -> command injection, unauthenticated with a forged license-response signature (CVSS 10.0) | 2026-08-06 |
| CVE-2026-49331 | HTTP | high | Reported by NewScan's named-CVE check: test_header_trust | 2026-08-06 |
| CVE-2026-42586 | Redis | high | Reported by NewScan's named-CVE check: test_redis_injection | 2026-08-06 |
| CVE-2026-25589 | RedisBloom | high | Invalid memory access in RESTORE when used with the RedisBloom module -> potential remote code execution | 2026-08-06 |
| CVE-2026-25588 | RedisTimeSeries | high | Invalid memory access in RESTORE when used with the RedisTimeSeries module -> potential remote code execution | 2026-08-06 |
| CVE-2026-25243 | Redis | high | Invalid memory access in the RESTORE command from a crafted serialized payload -> remote code execution | 2026-08-06 |
| CVE-2026-23479 | Redis | high | Use-after-free in the unblock-client flow -> remote code execution | 2026-08-06 |
| CVE-2026-0257 | PaloAlto GlobalProtect | high | PAN-OS GlobalProtect authentication bypass - an attacker establishes VPN connections without valid credentials | 2026-08-06 |
| CVE-2025-32023 | Redis | high | Hyperloglog out-of-bounds write from a crafted hyperloglog value -> remote code execution | 2026-08-06 |
| CVE-2025-20362 | Cisco ASA/FTD WebVPN | high | Cisco ASA/FTD WebVPN unauthorized access to restricted URL endpoints - chained with CVE-2025-20333 for pre-auth RCE | 2026-08-06 |
| CVE-2024-55656 | RedisBloom | high | RedisBloom integer overflow via CMS.INITBYDIM with large WIDTH/DEPTH -> heap overflow, potential remote code execution | 2026-08-06 |
| CVE-2024-51737 | RediSearch | high | RediSearch integer overflow via crafted FT.SEARCH/FT.AGGREGATE LIMIT or KNN arguments -> heap overflow, potential remote code execution | 2026-08-06 |
| CVE-2024-51480 | RedisTimeSeries | high | RedisTimeSeries integer overflow via crafted TS.QUERYINDEX/TS.MGET/TS.MRANGE/TS.MREVRANGE arguments -> heap overflow, potential remote code execution | 2026-08-06 |
| CVE-2024-46981 | Redis | high | Lua use-after-free (garbage-collector manipulation) -> remote code execution | 2026-08-06 |
| CVE-2024-31449 | Redis | high | Lua library stack overflow via a crafted EVAL script -> remote code execution as the Redis process | 2026-08-06 |
| CVE-2026-23631 | Redis | medium | Lua use-after-free via master-replica synchronization -> remote code execution | 2026-08-06 |
| CVE-2026-70494 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70493 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70492 | Open WebUI | high | Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in the web loader and vega renderer, cross-tenant re… | 2026-08-05 |
| CVE-2026-70491 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70490 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70489 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70488 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70487 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70486 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70485 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70484 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70483 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70482 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70481 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70480 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70479 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-54020 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-67200 | Rocket.Chat | critical | Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read | 2026-08-04 |
| CVE-2026-56845 | Rocket.Chat | critical | Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read | 2026-08-04 |
| CVE-2021-43798 | Rocket.Chat | critical | Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read | 2026-08-04 |
| CVE-2026-69243 | aiohttp | medium | aiohttp HTTP parser request smuggling (WebSocket upgrade handling) | 2026-08-04 |
| CVE-2026-8763 | Bouncy Castle | critical | Bouncy Castle for Java certificate/signature verification bypasses (X.509 name-constraint bypass, CMS zero-signer accept, RSA PKCS#1 hash truncation) plus unbounded-KDF DoS | 2026-08-03 |
| CVE-2026-59652 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59648 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59647 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59643 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59640 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59639 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-58063 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-15055 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-13586 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-12860 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2024-45519 | Zimbra Collaboration | critical | Zimbra postjournal service command injection - unauthenticated RCE via crafted SMTP message | 2026-08-02 |
| CVE-2024-40766 | SonicWall SMA/SSL-VPN | critical | SonicOS management access-control flaw - unauthorized resource access / firewall crash | 2026-08-02 |
| CVE-2024-4040 | CrushFTP | critical | CrushFTP VFS sandbox escape via server-side template injection - unauthenticated file read / RCE | 2026-08-02 |
| CVE-2024-38475 | Apache httpd | critical | Apache mod_rewrite improper substitution escaping - source disclosure and code execution via crafted URLs | 2026-08-02 |
| CVE-2024-36401 | GeoServer | critical | GeoServer unauthenticated RCE - OGC request property names evaluated as XPath expressions | 2026-08-02 |
| CVE-2024-23897 | Jenkins | critical | Jenkins CLI arbitrary file read via expandAtFiles - reads secrets, then full takeover | 2026-08-02 |
| CVE-2024-1709 | ConnectWise ScreenConnect | critical | ScreenConnect SetupWizard authentication bypass - create an administrator, then RCE | 2026-08-02 |
| CVE-2023-50164 | Apache Struts | critical | Struts file-upload path traversal -> upload a webshell (RCE) | 2026-08-02 |
| CVE-2023-35078 | Ivanti EPMM / MobileIron Core | critical | Ivanti EPMM unauthenticated API access - read/modify enrolled-device and user data | 2026-08-02 |
| CVE-2023-29300 | Adobe ColdFusion | critical | ColdFusion WDDX deserialization - unauthenticated remote code execution | 2026-08-02 |
| CVE-2023-26360 | Adobe ColdFusion | critical | ColdFusion improper access control / deserialization - unauthenticated arbitrary file read and RCE | 2026-08-02 |
| CVE-2023-25690 | Apache httpd | critical | Apache mod_proxy HTTP request smuggling via a RewriteRule/ProxyPassMatch substitution | 2026-08-02 |
| CVE-2023-22518 | Atlassian Confluence | critical | Confluence improper authorization - unauthenticated restore/takeover of the instance | 2026-08-02 |
| CVE-2023-22515 | Atlassian Confluence | critical | Confluence broken access control - unauthenticated administrator account creation | 2026-08-02 |
| CVE-2023-20198 | Cisco IOS XE Web UI | critical | IOS XE web UI privilege escalation - unauthenticated admin account creation (mass implant campaign) | 2026-08-02 |
| CVE-2022-37042 | Zimbra Collaboration | critical | Covered by the Zimbra Collaboration batch fix for CVE-2022-27925 | 2026-08-02 |
| CVE-2022-28346 | Django | critical | Django SQL injection via crafted dictionary expansion in QuerySet.annotate()/aggregate() | 2026-08-02 |
| CVE-2022-27925 | Zimbra Collaboration | critical | Zimbra mboximport archive extraction path traversal -> RCE (chained with CVE-2022-37042 auth bypass) | 2026-08-02 |
| CVE-2022-26134 | Atlassian Confluence | critical | Confluence OGNL injection - unauthenticated remote code execution | 2026-08-02 |
| CVE-2022-1040 | Sophos Firewall | critical | Sophos Firewall User Portal/Webadmin authentication bypass -> RCE | 2026-08-02 |
| CVE-2021-45046 | Log4j | critical | Log4j Thread Context lookup bypass of the 2.15.0 fix - RCE in some configurations | 2026-08-02 |
| CVE-2021-41773 | Apache httpd | critical | Apache path traversal outside the document root (cgi-bin -> RCE) | 2026-08-02 |
| CVE-2021-40539 | ManageEngine ADSelfService Plus | critical | ADSelfService Plus REST API authentication bypass -> remote code execution | 2026-08-02 |
| CVE-2021-22005 | VMware vCenter Server | critical | vCenter Analytics service arbitrary file upload -> RCE | 2026-08-02 |
| CVE-2021-21972 | VMware vCenter Server | critical | vCenter vRealize Operations plugin unauthenticated file upload -> RCE | 2026-08-02 |
| CVE-2021-20016 | SonicWall SMA/SSL-VPN | critical | SonicWall SMA100 SQL injection - unauthenticated credential/session access | 2026-08-02 |
| CVE-2020-14882 | Oracle WebLogic Server | critical | WebLogic administration console path-traversal authentication bypass -> RCE | 2026-08-02 |
| CVE-2020-12271 | Sophos Firewall | critical | Sophos XG SQL injection -> remote code execution (Asnarok) | 2026-08-02 |
| CVE-2019-7609 | Kibana | critical | Kibana Timelion prototype pollution -> arbitrary code execution as the Kibana process | 2026-08-02 |
| CVE-2019-6340 | Drupal | critical | Drupal RESTful Web Services unsafe deserialization -> remote code execution | 2026-08-02 |
| CVE-2018-7600 | Drupal | critical | Drupalgeddon2 - unauthenticated remote code execution via Form API render arrays | 2026-08-02 |
| CVE-2018-12613 | phpMyAdmin | critical | phpMyAdmin file inclusion via the index.php target parameter -> code execution | 2026-08-02 |
| CVE-2017-5638 | Apache Struts | critical | Struts Jakarta multipart parser OGNL injection - unauthenticated RCE via the Content-Type header (Equifax) | 2026-08-02 |
| CVE-2017-10271 | Oracle WebLogic Server | critical | WebLogic WLS-WSAT XML deserialization - unauthenticated RCE | 2026-08-02 |
| CVE-2014-0160 | OpenSSL | critical | Heartbleed - TLS heartbeat over-read leaks up to 64KB of process memory (keys, sessions, credentials) | 2026-08-02 |
| CVE-2024-38816 | Spring Framework | high | Spring path traversal - functional web resource handlers serve files outside the configured location | 2026-08-02 |
| CVE-2024-29041 | Express | high | Express open redirect - res.location()/res.redirect() accept a malformed URL that browsers follow off-site | 2026-08-02 |
| CVE-2024-24919 | Check Point Security Gateway | high | Check Point Remote Access VPN arbitrary file read (password hashes, certificates) | 2026-08-02 |
| CVE-2024-1708 | ConnectWise ScreenConnect | high | ScreenConnect path traversal - write outside the extension sandbox | 2026-08-02 |
| CVE-2024-1135 | Gunicorn | high | Gunicorn HTTP request smuggling - improper Transfer-Encoding validation desyncs it from the front-end proxy | 2026-08-02 |
| CVE-2023-38408 | OpenSSH | high | OpenSSH ssh-agent PKCS#11 provider remote code execution (agent forwarding to a hostile host) | 2026-08-02 |
| CVE-2023-35081 | Ivanti EPMM / MobileIron Core | high | Ivanti EPMM administrator path traversal - arbitrary file write (chained with CVE-2023-35078) | 2026-08-02 |
| CVE-2023-30861 | Flask | high | Flask session cookie can be cached by a proxy and served to another client (session disclosure) | 2026-08-02 |
| CVE-2023-23752 | Joomla | high | Joomla improper access check on the web-service endpoints - unauthenticated config/credential disclosure | 2026-08-02 |
| CVE-2023-20273 | Cisco IOS XE Web UI | high | IOS XE web UI command injection - root after the CVE-2023-20198 account creation | 2026-08-02 |
| CVE-2022-3602 | OpenSSL | high | OpenSSL X.509 email-address punycode buffer overflow (4-byte stack overwrite) | 2026-08-02 |
| CVE-2022-24999 | Express | high | qs prototype pollution via bracketed query keys -> denial of service | 2026-08-02 |
| CVE-2021-35042 | Django | high | Django SQL injection through QuerySet.order_by() with an unvalidated column name | 2026-08-02 |
| CVE-2024-37032 | ollama | medium | Reported by NewScan's unauthenticated interface: Unauthenticated Ollama model API | 2026-08-02 |
| CVE-2021-44832 | Log4j | medium | Log4j JDBC Appender remote code execution when an attacker controls the logging configuration | 2026-08-02 |
| CVE-2016-2107 | OpenSSL | medium | OpenSSL AES-NI CBC MAC-check padding oracle (Lucky-13 variant) - plaintext recovery | 2026-08-02 |
| CVE-2026-68771 | comfyui | critical | Reported by NewScan's unauthenticated interface: Unauthenticated ComfyUI interface | 2026-08-01 |
| CVE-2026-3141 | formgent | critical | FormGent unauthenticated arbitrary file deletion via REST API (wp-config.php -> site takeover) | 2026-08-01 |
| CVE-2026-14919 | shopmonitor | critical | ShopMonitor.io authentication bypass via email redirection -> unauthenticated administrator account takeover | 2026-08-01 |
| CVE-2026-6540 | HTTP routing | high | Reported by NewScan's named-CVE check: test_path_acl_bypass | 2026-08-01 |
| CVE-2026-53501 | Thumbor | high | Reported by NewScan's named-CVE check: test_media_proxy_ssrf | 2026-08-01 |
| CVE-2026-53500 | Thumbor | high | Reported by NewScan's named-CVE check: test_media_proxy_ssrf | 2026-08-01 |
| CVE-2026-17566 | pgadmin | high | Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable | 2026-08-01 |
| CVE-2026-17349 | pgadmin | high | Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable | 2026-08-01 |
| CVE-2026-17347 | pgadmin | high | Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable | 2026-08-01 |
| CVE-2026-16144 | kali-forms | high | Kali Forms remote code execution via improper code-generation control | 2026-08-01 |
| CVE-2026-15988 | ai-engine | high | AI Engine cross-site request forgery -> actions as an authenticated user | 2026-08-01 |
| CVE-2026-15450 | nex-forms | high | NEX-Forms authenticated path traversal -> arbitrary file deletion | 2026-08-01 |
| CVE-2026-15414 | subscriptions-for-woocommerce | high | Subscriptions for WooCommerce authenticated privilege escalation | 2026-08-01 |
| CVE-2026-15258 | webappick-product-feed-for-woocommerce | high | Product Feed Manager for WooCommerce authenticated SQL injection | 2026-08-01 |
| CVE-2026-13609 | acf-frontend-form-element | high | Frontend Admin unauthenticated stored cross-site scripting | 2026-08-01 |
| CVE-2026-12721 | kirki | high | Kirki Customizer Framework SQL injection | 2026-08-01 |
| CVE-2026-12695 | miniorange-2-factor-authentication | high | miniOrange 2FA authentication bypass (unauthenticated MFA circumvention) | 2026-08-01 |
| CVE-2026-12251 | ultimate-member | high | Ultimate Member improper privilege management -> unauthorized access / permission elevation | 2026-08-01 |
| CVE-2021-3129 | Laravel Ignition | critical | Reported by NewScan's exposure path probe: Exposed Laravel Ignition debug handler | 2026-07-31 |
| CVE-2026-44578 | Next.js | high | Next.js May 2026 coordinated security release (13 advisories): SSRF via the middleware/proxy request path, plus middleware and proxy bypass CVE-2026-44573, cache poisoning on middl… | 2026-07-30 |
| CVE-2026-44577 | Next.js | high | Covered by the Next.js batch fix for CVE-2026-44578 | 2026-07-30 |
| CVE-2026-44573 | Next.js | high | Covered by the Next.js batch fix for CVE-2026-44578 | 2026-07-30 |
| CVE-2026-44572 | Next.js | high | Covered by the Next.js batch fix for CVE-2026-44578 | 2026-07-30 |
| CVE-2022-31129 | moment | high | moment regular-expression denial of service parsing a long attacker-supplied date string | 2026-07-30 |
| CVE-2021-23337 | lodash | high | lodash command injection via _.template's variable option | 2026-07-30 |
| CVE-2020-8203 | lodash | high | lodash prototype pollution in zipObjectDeep/set/setWith | 2026-07-30 |
| CVE-2024-21490 | Angular | medium | AngularJS regular-expression denial of service via ng-srcset with untrusted input | 2026-07-30 |
| CVE-2023-45857 | axios | medium | axios leaks the XSRF-TOKEN cookie value to a third-party host in the Authorization-style header | 2026-07-30 |
| CVE-2019-11358 | jQuery | medium | jQuery prototype pollution via $.extend(true, {}, attackerJSON) | 2026-07-30 |
| CVE-2018-14042 | Bootstrap | medium | Bootstrap XSS in data-container of the tooltip/popover plugin | 2026-07-30 |
| CVE-2026-18072 | advanced-responsive-video-embedder | critical | ARVE hardcoded-backdoor authentication bypass -> admin takeover (malicious release) | 2026-07-29 |
| CVE-2026-14512 | IBM WebSphere Application Server | critical | WebSphere pre-authentication unsafe deserialization -> auth bypass / RCE | 2026-07-29 |
| CVE-2026-14446 | IBM WebSphere Application Server | critical | WebSphere admin-console broken access control -> privilege escalation | 2026-07-29 |
| CVE-2026-13423 | streamit | critical | Streamit theme unauthenticated AJAX arbitrary-function call -> privilege escalation / RCE | 2026-07-29 |
| CVE-2026-16498 | Model Context Protocol | high | Reported by NewScan's named-CVE check: test_mcp_session_isolation | 2026-07-29 |
| CVE-2026-16723 | Fastjson | high | Reported by NewScan's named-CVE check: test_fastjson_rce | 2026-07-27 |
| CVE-2025-3248 | Langflow | critical | Langflow before 1.3.0: unauthenticated remote code execution via POST /api/v1/validate/code | 2026-07-23 |
| CVE-2026-0770 | Langflow | high | Reported by NewScan's named-CVE check: test_langflow_rce | 2026-07-23 |
| CVE-2026-42533 | nginx | critical | nginx script-engine capture/map heap overflow (DoS; RCE where ASLR bypassable) | 2026-07-21 |
| CVE-2025-55752 | Apache Tomcat | critical | Tomcat rewrite dir-traversal -> RCE | 2026-07-21 |
| CVE-2025-29927 | Next.js | critical | Next.js middleware authorization bypass - the internal x-middleware-subrequest header skips middleware entirely | 2026-07-21 |
| CVE-2024-34351 | Next.js | high | Next.js Server Actions SSRF - a crafted Host header makes the server fetch an attacker-chosen origin | 2026-07-21 |
| CVE-2026-63030 | WordPress | critical | WP2Shell: REST API batch-route confusion -> SQLi (CVE-2026-60137) -> unauthenticated RCE | 2026-07-19 |
| CVE-2026-60137 | WordPress | critical | Covered by the WordPress batch fix for CVE-2026-63030 | 2026-07-19 |
| CVE-2021-44228 | Log4j | critical | Log4Shell - JNDI lookup in a logged string gives unauthenticated remote code execution | 2026-07-17 |
| CVE-2022-42889 | Apache Commons Text | high | Reported by NewScan's named-CVE check: test_text4shell | 2026-07-17 |
| CVE-2024-3400 | PaloAlto GlobalProtect | critical | PAN-OS GlobalProtect command injection -> pre-auth RCE | 2026-07-13 |
| CVE-2024-21887 | Ivanti Connect Secure | critical | Ivanti Connect Secure command injection (chained -> pre-auth RCE) | 2026-07-13 |
| CVE-2024-21762 | FortiOS SSL-VPN | critical | FortiOS SSL-VPN out-of-bounds write -> pre-auth RCE | 2026-07-13 |
| CVE-2023-4966 | Citrix NetScaler ADC/Gateway | critical | Citrix Bleed: sensitive session-token disclosure | 2026-07-13 |
| CVE-2023-46747 | F5 BIG-IP | critical | F5 BIG-IP Traffic Management UI auth bypass -> RCE | 2026-07-13 |
| CVE-2023-35708 | MOVEit Transfer | critical | MOVEit Transfer SQL injection -> privilege escalation | 2026-07-13 |
| CVE-2023-35036 | MOVEit Transfer | critical | MOVEit Transfer SQL injection (follow-up) | 2026-07-13 |
| CVE-2023-34362 | MOVEit Transfer | critical | MOVEit Transfer SQL injection -> RCE (Cl0p mass-exploitation) | 2026-07-13 |
| CVE-2023-0669 | GoAnywhere MFT | critical | GoAnywhere MFT deserialization -> RCE (Cl0p) | 2026-07-13 |
| CVE-2022-1388 | F5 BIG-IP | critical | F5 BIG-IP iControl REST authentication bypass -> RCE | 2026-07-13 |
| CVE-2021-34473 | Microsoft Exchange OWA | critical | ProxyShell: pre-auth RCE | 2026-07-13 |
| CVE-2021-26855 | Microsoft Exchange OWA | critical | ProxyLogon: pre-auth SSRF | 2026-07-13 |
| CVE-2023-46805 | Ivanti Connect Secure | high | Ivanti Connect Secure authentication bypass | 2026-07-13 |
| CVE-2025-14847 | MongoDB | high | MongoBleed: unauthenticated zlib-decompression heap memory disclosure | 2026-07-11 |
| CVE-2020-25213 | wp-file-manager | critical | WP File Manager unauthenticated arbitrary file upload -> RCE | 2026-07-07 |
| CVE-2017-1001000 | WordPress | critical | WordPress REST API unauthenticated content injection / privilege escalation | 2026-07-07 |
| CVE-2017-9066 | WordPress | high | WordPress SSRF via HTTP request handling (unpatched pre-4.7.5 branch) | 2026-07-07 |
| CVE-2025-24813 | Apache Tomcat | critical | Tomcat partial-PUT deserialization RCE | 2026-06-29 |
| CVE-2024-6387 | OpenSSH | critical | regreSSHion: unauthenticated RCE in sshd | 2026-06-29 |
| CVE-2024-4577 | PHP | critical | PHP-CGI argument injection → RCE (Windows) | 2026-06-29 |
| CVE-2022-22965 | Spring Framework | critical | Spring4Shell RCE via data binding | 2026-06-29 |
| CVE-2021-42013 | Apache httpd | critical | Apache path traversal → RCE | 2026-06-29 |
| CVE-2021-23017 | nginx | critical | nginx resolver off-by-one heap overwrite (RCE) | 2026-06-29 |
| CVE-2024-49767 | Werkzeug | high | Werkzeug multipart resource exhaustion | 2026-06-29 |
| CVE-2023-25577 | Werkzeug | high | Werkzeug multipart DoS (resource exhaustion) | 2026-06-29 |
| CVE-2021-40438 | Apache httpd | high | mod_proxy SSRF | 2026-06-29 |
| CVE-2020-11022 | jQuery | medium | jQuery htmlPrefilter XSS | 2026-06-29 |
| CVE-2019-8331 | Bootstrap | medium | Bootstrap XSS in tooltip/popover data-template | 2026-06-29 |
| CVE-2018-2783 | Angular | medium | AngularJS (1.x) is end-of-life; multiple sandbox-escape XSS | 2026-06-29 |
No CVE matches that filter.
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →