This week's burn-down
Nothing new this week.
10 fixes from the first two groups are still open. They're below, newest first.
- CVE-2026-104286Patch second
Fortinet FortiMail Path Traversal Vulnerability
- CVE-2026-76504Patch second
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances Code Injection Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft Windows Link Following Vulnerability
Start here
What to patch first.
180 of these vulnerabilities are actively used in ransomware attacks. Start with these — they're the ones criminals are exploiting right now.
- Patch first180used in ransomware
- Patch second193critical, or high-severity on internet-facing gear
- Patch third417high-severity, or on internet-facing gear
- Patch fourth55everything else on the list
Every entry here is on CISA's Known Exploited Vulnerabilities list, and CISA's current directive, BOD 26-04, gives federal agencies 3 or 14 days to fix a listed vulnerability.
Treat all four groups as due inside that window and work through them in this order; a later place in the order is not permission to wait.
The order comes from CVSS severity and our guess at internet exposure from the kind of product. Neither is how CISA sets its deadlines: the directive looks at:
- Whether your system is actually reachable from the internet
- Whether the attack can be automated
- How much control it gives an attacker
Want just the ones that hit your gear? Check your stack to pick your vendors and see what's being exploited right now.
Insurance readiness
Your insurer will ask if this is patched.
Unpatched entries on CISA's Known Exploited Vulnerabilities list are exactly what cyber-insurance carrier questionnaires probe for, and knowing which controls they check is how you keep a renewal from stalling.
Get the free carrier questionnaire →Microsoft updates
One Windows Update run clears all of these.
Windows updates are cumulative: the newest one includes every fix that came before it. Run Windows Update on your machines and everything below is covered. The KB numbers are the receipts, not a to-do list.
- KB5053618covered 7 actively-exploited CVEs
- KB5053594covered 7 actively-exploited CVEs
- KB5053886covered 7 actively-exploited CVEs
- KB5053887covered 7 actively-exploited CVEs
- KB5053596covered 6 actively-exploited CVEs
- KB5053603covered 6 actively-exploited CVEs
- KB5053638covered 6 actively-exploited CVEs
- KB5053606covered 6 actively-exploited CVEs
- KB5053602covered 6 actively-exploited CVEs
- KB5053598covered 6 actively-exploited CVEs
Known exploited vulnerabilities
What's being actively exploited.
CISA's Known Exploited Vulnerabilities (KEV) catalog is the U.S. government's list of vulnerabilities that have been exploited in the wild. This page tracks the entries that affect software small businesses run, refreshed daily, with what each one affects and what to do about it in plain English. It is not every CVE, only the ones used in real attacks.
Breadth
Exploited in the wild, not yet on CISA's list.
VulnCheck tracks 553 additional SMB-relevant CVEs being actively exploited beyond CISA's KEV catalog. 51 are flagged as used in ransomware campaigns. The list below covers the same vendors as everything else on this page: Microsoft, Apple, Adobe, Cisco, Fortinet, SonicWall, Ivanti, Palo Alto, Google, and Ubiquiti.
- CVE-2025-25252VulnCheck· Fortinet FortiOS
Fortinet FortiOS Insufficient Session Expiration
- CVE-2023-34132VulnCheck· SonicWall Analytics
SonicWall Analytics Use of Password Hash Instead of Password for Authentication
- CVE-2026-63520VulnCheck· Microsoft SharePoint
Microsoft SharePoint Improper Input Validation
- CVE-2026-69836VulnCheck· Microsoft Entra Id
Microsoft Entra Id Deserialization of Untrusted Data
- CVE-2020-9771VulnCheck· Apple Mac OS X
macOS APFS Snapshot Mount Authorization Bypass
- CVE-2026-48294VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2026-48313VulnCheck· Adobe ColdFusion
Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2020-1013VulnCheck· Microsoft Windows
Microsoft Windows Group Policy Elevation of Privilege Vulnerability
- CVE-2025-62631VulnCheck· Fortinet FortiOS
Fortinet FortiOS Insufficient Session Expiration
- CVE-2026-45586VulnCheck· Microsoft Windows
Microsoft Windows Improper Link Resolution Before File Access ('Link Following')
Show all 553 SMB-relevant (543 more)
- CVE-2021-27076VulnCheck· Microsoft Business Productivity Servers
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2026-39813VulnCheck· Fortinet FortiSandbox
Fortinet FortiSandbox Path Traversal: '../filedir'
- CVE-2026-41089VulnCheck· Microsoft Windows
Microsoft Windows Stack-based Buffer Overflow
- CVE-2024-12802VulnCheckKnown ransomware use· SonicWall SonicOS
SonicWall SonicOS Authentication Bypass by Primary Weakness
- CVE-2020-17103VulnCheck· Microsoft Windows
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2025-40600VulnCheck· SonicWall SonicOS
SonicWall SonicOS Use of Externally-Controlled Format String
- CVE-2025-32818VulnCheck· SonicWall SonicOS
SonicWall SonicOS NULL Pointer Dereference
- CVE-2026-25187VulnCheck· Microsoft Windows
Microsoft Windows Improper Link Resolution Before File Access ('Link Following')
- CVE-2026-21262VulnCheck· Microsoft SQL Server 2016
Microsoft SQL Server 2016 Improper Access Control
- CVE-2026-26127VulnCheck· Microsoft .NET
Microsoft .NET Out-of-bounds Read
- CVE-2025-43532VulnCheck· Apple macOS
Apple macOS Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CVE-2025-43517VulnCheck· Apple macOS
Apple macOS Sequoia/Sonoma/Tahoe Log Entry Data Redaction Vulnerability
- CVE-2025-43542VulnCheck· Apple macOS
Apple iOS/iPadOS/visionOS and macOS Sequoia/Tahoe FaceTime Password Disclosure
- CVE-2025-46289VulnCheck· Apple macOS
Apple macOS Improper Authorization
- CVE-2025-24113VulnCheck· Apple Safari
Apple Safari/iOS/iPadOS/visionOS/watchOS and macOS Sequoia Interface Spoofing Vulnerability
- CVE-2025-43482VulnCheck· Apple macOS
Apple macOS Improper Input Validation
- CVE-2025-43512VulnCheck· Apple macOS
Apple iOS/iPadOS and macOS Sequoia/Sonoma/Tahoe Privilege Escalation
- CVE-2023-36899VulnCheck· Microsoft .NET Framework
Microsoft .NET Framework Improper Input Validation
- CVE-2014-6321VulnCheck· Microsoft Windows
Microsoft Windows Improper Control of Generation of Code ('Code Injection')
- CVE-2026-20931VulnCheck· Microsoft Windows
Microsoft Windows External Control of File Name or Path
- CVE-2026-20029VulnCheck· Cisco Identity Services Engine
Cisco Identity Services Engine Improper Restriction of XML External Entity Reference
- CVE-2023-39276VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2026-25815VulnCheck· Fortinet FortiOS
Fortinet FortiOS LDAP Credentials Disclosure
- CVE-2024-53705VulnCheck· SonicWall SonicOS
SonicWall SonicOS Server-Side Request Forgery (SSRF)
- CVE-2023-39280VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2023-39279VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2023-39278VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2025-40601VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2024-40762VulnCheck· SonicWall SonicOS
SonicWall SonicOS Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
- CVE-2023-39277VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2024-20404VulnCheck· Cisco Finesse
Cisco Finesse Server-Side Request Forgery (SSRF)
- CVE-2020-16040VulnCheck· Google Chrome
Google Chrome Improper Input Validation
- CVE-2025-20282VulnCheck· Cisco Identity Services Engine
Cisco Identity Services Engine Improper Privilege Management
- CVE-2025-52665VulnCheck· Ubiquiti UniFi Access
Ubiquiti UniFi Access Missing Authentication for Critical Function
- CVE-2025-64155VulnCheck· Fortinet FortiSIEM
Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2023-44353VulnCheck· Adobe ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data
- CVE-2023-44352VulnCheck· Adobe ColdFusion
Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2025-59719VulnCheck· Fortinet FortiWeb
Fortinet FortiWeb Improper Verification of Cryptographic Signature
- CVE-2020-1066VulnCheckKnown ransomware use· Microsoft .NET Framework
.NET Framework Elevation of Privilege Vulnerability
- CVE-2025-9491VulnCheck· Microsoft Windows
Microsoft Windows User Interface (UI) Misrepresentation of Critical Information
- CVE-2025-54251VulnCheck· Adobe Experience Manager
Adobe Experience Manager XML Injection (aka Blind XPath Injection)
- CVE-2022-2915VulnCheck· SonicWall SMA 200 Firmware
SonicWall SMA 200 Firmware Heap-based Buffer Overflow
- CVE-2023-5970VulnCheck· SonicWall SMA 200 Firmware
SonicWall SMA 200 Firmware Improper Authentication
- CVE-2025-24477VulnCheck· Fortinet FortiOS
Fortinet FortiOS Heap-based Buffer Overflow
- CVE-2022-1703VulnCheck· SonicWall SMA 210 Firmware
SonicWall SMA 210 Firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2024-20419VulnCheck· Cisco Smart Software Manager On-Prem
Cisco Smart Software Manager On-Prem Unverified Password Change
- CVE-2023-34124VulnCheck· SonicWall Analytics
SonicWall Analytics Authentication Bypass by Primary Weakness
- CVE-2025-54249VulnCheck· Adobe Experience Manager
Adobe Experience Manager Server-Side Request Forgery (SSRF)
- CVE-2025-53772VulnCheck· Microsoft Web Deploy 4.0
Microsoft Web Deploy 4.0 Deserialization of Untrusted Data
- CVE-2025-20363VulnCheck· Cisco IOS XR
Cisco IOS XR Heap-based Buffer Overflow
- CVE-2025-52970VulnCheck· Fortinet FortiWeb
Fortinet FortiWeb Improper Handling of Parameters
- CVE-2022-20705VulnCheck· Cisco RV Series Routers
Cisco RV Series Routers Stack-based Buffer Overflow
- CVE-2025-47170VulnCheck· Microsoft Office
Microsoft Office Use After Free
- CVE-2025-47165VulnCheck· Microsoft Office
Microsoft Office Use After Free
- CVE-2022-35803VulnCheck· Microsoft Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-24481VulnCheck· Microsoft Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2020-1048VulnCheck· Microsoft Windows
Microsoft Windows Incorrect Resource Transfer Between Spheres
- CVE-2025-25256VulnCheck· Fortinet FortiSIEM
Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2025-54254VulnCheck· Adobe Experience Manager Forms
Adobe Experience Manager Forms Improper Restriction of XML External Entity Reference
- CVE-2024-38196VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2024-30090VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Untrusted Pointer Dereference
- CVE-2020-2034VulnCheck· Palo Alto Networks PAN-OS
Palo Alto Networks PAN-OS Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2011-3315VulnCheck· Cisco Unified IP Interactive Voice Response
Cisco Unified IP Interactive Voice Response Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2025-49533VulnCheck· Adobe Experience Manager
Adobe Experience Manager Deserialization of Untrusted Data
- CVE-2018-4237VulnCheck· Apple iPhone OS
Apple iOS/macOS/tvOS/watchOS 'libxpc' Vulnerability
- CVE-2025-53771VulnCheckKnown ransomware use· Microsoft SharePoint
Microsoft SharePoint Improper Authentication
- CVE-2023-20085VulnCheck· Cisco Identity Services Engine
Cisco Identity Services Engine Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2022-41335VulnCheck· Fortinet FortiSwitchManager
Fortinet FortiSwitchManager Relative Path Traversal
- CVE-2025-0107VulnCheck· Palo Alto Networks Expedition
Palo Alto Networks Expedition Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2009-1558VulnCheck· Cisco WVC54GCA
Cisco WVC54GCA Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2025-47176VulnCheck· Microsoft Office
Microsoft Office Path Traversal: '.../...//'
- CVE-2024-21407VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Use After Free
- CVE-2025-20188VulnCheck· Cisco IOS XE
Cisco IOS XE Use of Hard-coded Credentials
- CVE-2020-16139VulnCheck· Cisco Unified IP Conference Station 7937G Firmware
Cisco Unified IP Conference Station 7937G Crafted Packets Remote Denial of Service
- CVE-2024-20440VulnCheck· Cisco Smart Licensing Utility
Cisco Smart Licensing Utility Insertion of Sensitive Information into Log File
- CVE-2020-3187VulnCheck· Cisco Secure Firewall Threat Defense
Cisco Secure Firewall Threat Defense Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2000-0984VulnCheck· Cisco iOS
Cisco iOS HTTP Server '?/' String Vulnerability
- CVE-2018-0150VulnCheck· Cisco IOS XE
Cisco IOS XE Use of Hard-coded Credentials
- CVE-2018-0160VulnCheck· Cisco IOS XE
Cisco IOS XE Double Free
- CVE-2025-4664VulnCheck· Google Chrome
Google Chrome Loader Policy Enforcement Vulnerability
- CVE-2025-32819VulnCheck· SonicWall SMA 100 Appliances
SonicWall SMA 100 Appliances Files or Directories Accessible to External Parties
- CVE-2020-3529VulnCheck· Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Uncontrolled Resource Consumption
- CVE-2024-38023VulnCheck· Microsoft SharePoint
Microsoft SharePoint Deserialization of Untrusted Data
- CVE-2024-38024VulnCheck· Microsoft SharePoint
Microsoft SharePoint Deserialization of Untrusted Data
- CVE-2024-20666VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2025-24061VulnCheck· Microsoft Windows
Microsoft Windows Protection Mechanism Failure
- CVE-2025-24071VulnCheck· Microsoft Windows
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2022-20933VulnCheck· Cisco Meraki MX64 Firmware
Cisco Meraki MX64 Firmware Failure to Handle Missing Parameter
- CVE-2017-0176VulnCheck· Microsoft Windows
Microsoft Windows Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CVE-2023-28218VulnCheck· Microsoft Windows
Microsoft Windows Heap-based Buffer Overflow
- CVE-2024-28916VulnCheck· Microsoft Xbox Gaming Services
Microsoft Xbox Gaming Services Improper Link Resolution Before File Access ('Link Following')
- CVE-2024-21447VulnCheck· Microsoft Windows
Microsoft Windows Improper Link Resolution Before File Access ('Link Following')
- CVE-2024-38100VulnCheck· Microsoft Windows
Microsoft Windows Improper Access Control
- CVE-2024-23109VulnCheckKnown ransomware use· Fortinet FortiSIEM
Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2024-23108VulnCheckKnown ransomware use· Fortinet FortiSIEM
Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2025-0283VulnCheckKnown ransomware use· Ivanti Connect Secure, Policy Secure, and Neurons
Ivanti Connect Secure, Policy Secure, and Neurons stack-based buffer overflow
- CVE-2024-38653VulnCheck· Ivanti Avalanche
Ivanti Avalanche Improper Restriction of XML External Entity Reference
- CVE-2024-21390VulnCheck· Microsoft Authenticator
Microsoft Authenticator Improper Authentication
- CVE-2000-0325VulnCheck· Microsoft Jet
Microsoft Jet Database Engine VBA Shell Vulnerability
- CVE-2024-38021VulnCheck· Microsoft Office
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2021-31969VulnCheck· Microsoft Windows
Microsoft Windows Improper Privilege Management
- CVE-2024-26229VulnCheck· Microsoft Windows CSC Service
Windows CSC Service Elevation of Privilege Vulnerability
- CVE-2024-50570VulnCheck· Fortinet FortiClient
Fortinet FortiClient Cleartext Storage of Sensitive Information
- CVE-2024-44258VulnCheck· Apple iPadOS
Apple iPadOS Improper Link Resolution Before File Access ('Link Following')
- CVE-2024-21894VulnCheck· Ivanti Connect Secure and Policy Secure
Ivanti Connect Secure and Policy Secure Out-of-bounds Write
- CVE-2020-9910VulnCheck· Apple iCloud
Apple iCloud Improper Authentication
- CVE-2020-9870VulnCheck· Apple iPadOS
Apple iPadOS Improper Input Validation
- CVE-2023-20263VulnCheckKnown ransomware use· Cisco Hyperflex HX Data Platform
Cisco Hyperflex HX Data Platform URL Redirection to Untrusted Site ('Open Redirect')
- CVE-2024-9381VulnCheck· Ivanti CSA (Cloud Services Application)
Ivanti CSA Path Traversal Security Bypass Vulnerability
- CVE-2012-2626VulnCheck· SonicWall Scrutinizer
SonicWall Scrutinizer Improper Authentication
- CVE-2009-1872VulnCheck· Adobe ColdFusion
Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2014-9792VulnCheck· Google Android
Android Nexus 5 Qualcomm Components Elevation of Privilege Vulnerability
- CVE-2020-3451VulnCheck· Cisco RV340W Firmware
Cisco RV340W Firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2022-20707VulnCheck· Cisco RV Series Routers
Cisco RV Series Routers Stack-based Buffer Overflow
- CVE-2023-0656VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2022-22274VulnCheck· SonicWall SonicOS
SonicWall SonicOS Stack-based Buffer Overflow
- CVE-2024-41869VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Use After Free Remote Code Execution Vulnerability
- CVE-2024-43491VulnCheck· Microsoft Windows
Microsoft Windows Update Remote Code Execution Vulnerability
- CVE-2008-3648VulnCheck· Microsoft Windows XP
Microsoft Windows XP Improper Control of Generation of Code ('Code Injection')
- CVE-2021-28481VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-22005VulnCheck· Microsoft SharePoint
Microsoft SharePoint Deserialization of Untrusted Data
- CVE-2024-21754VulnCheck· Fortinet FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy Backup File Weak Key Vulnerability
- CVE-2018-4404VulnCheck· Apple iPhone OS
Apple iPhone OS Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2018-4233VulnCheck· Apple Safari
Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2023-36745VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2010-2506VulnCheck· Cisco Linksys Firmware
Cisco Linksys Firmware Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2023-41724VulnCheck· Ivanti Sentry
Ivanti Sentry Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2023-46808VulnCheck· Ivanti Neurons For ITSM
Ivanti Neurons For ITSM Unrestricted Upload of File with Dangerous Type
- CVE-2024-20345VulnCheck· Cisco AppDynamics Controller
Cisco AppDynamics Controller Directory Traversal Vulnerability
- CVE-2020-1375VulnCheck· Microsoft Windows
Windows COM Server Elevation of Privilege Vulnerability
- CVE-2021-26897VulnCheck· Microsoft Windows
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2022-21907VulnCheck· Microsoft Windows
HTTP Protocol Stack Remote Code Execution Vulnerability
- CVE-2017-0068VulnCheck· Microsoft Edge
Microsoft Edge Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2021-30538VulnCheck· Google Chrome
Google Chrome Incorrect Authorization
- CVE-2022-24463VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2013-2912VulnCheck· Google Chrome
Google Chrome Pepper Plug-in API (PPAPI) PepperInProcessRouter::SendToHost Vulnerability
- CVE-2023-26397VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Out-of-bounds Read
- CVE-2018-4312VulnCheck· Apple Safari
Apple Safari Use After Free
- CVE-2018-4386VulnCheck· Apple Safari
Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-13798VulnCheck· Apple Safari
Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-16391VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Validation of Array Index
- CVE-2019-0537VulnCheck· Microsoft Visual Studio
Microsoft Visual Studio Information Disclosure Vulnerability
- CVE-2023-26347VulnCheck· Adobe ColdFusion
Adobe ColdFusion Improper Access Control
- CVE-2018-5019VulnCheck· Adobe Acrobat DC
Adobe Acrobat DC Out-of-bounds Read
- CVE-2018-4443VulnCheck· Apple Safari
Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-3212VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2020-15994VulnCheck· Google Chrome
Google Chrome Use After Free
- CVE-2017-16383VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2019-0948VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of XML External Entity Reference
- CVE-2020-9802VulnCheck· Apple iCloud
Apple iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows, iCloud for Windows Web Content Vulnerability
- CVE-2023-34993VulnCheck· Fortinet FortiWLM
Fortinet FortiWLM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2024-26234VulnCheck· Microsoft Windows
Proxy Driver Spoofing Vulnerability
- CVE-2017-11884VulnCheck· Microsoft Excel
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2024-20720VulnCheck· Adobe Commerce
Adobe Commerce Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2021-20039VulnCheck· SonicWall SMA 200 Firmware
SonicWall SMA 200 Firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2023-21716VulnCheck· Microsoft Office
Microsoft Word Remote Code Execution
- CVE-2024-21888VulnCheck· Ivanti Connect Secure and Policy Secure
Ivanti Connect Secure Privilege Escalation
- CVE-2024-22024VulnCheck· Ivanti Connect Secure and Policy Secure
Ivanti Connect Secure and Policy Secure Improper Restriction of XML External Entity Reference
- CVE-2019-5782VulnCheck· Google Chrome
Google Chrome Out-of-bounds Read
- CVE-2021-30497VulnCheck· Ivanti Avalanche
Ivanti Avalanche Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2023-29324VulnCheck· Microsoft Windows
Windows MSHTML Platform Security Feature Bypass
- CVE-2023-40088VulnCheck· Google Android
Google Android Use After Free
- CVE-2021-22122VulnCheck· Fortinet FortiWeb
Fortinet FortiWeb Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-1733VulnCheck· Microsoft Psexec
Microsoft Psexec Improper Privilege Management
- CVE-2020-1206VulnCheck· Microsoft Windows
Microsoft Windows Use of Uninitialized Resource
- CVE-2023-21742VulnCheck· Microsoft SharePoint
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2010-1807VulnCheck· Apple Safari
Apple Safari Improper Input Validation
- CVE-2023-32563VulnCheck· Ivanti Avalanche
Ivanti Avalanche Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2023-34133VulnCheck· SonicWall Analytics
SonicWall Analytics Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CVE-2018-0127VulnCheck· Cisco RV Series Routers
Cisco RV Series Routers Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2001-0537VulnCheck· Cisco iOS
Cisco iOS Improper Authentication
- CVE-2019-1821VulnCheck· Cisco Evolved Programmable Network Manager
Cisco Evolved Programmable Network Manager Improper Input Validation
- CVE-2023-20073VulnCheck· Cisco RV Series Routers
Cisco RV Series Routers Unrestricted Upload of File with Dangerous Type
- CVE-2021-21087VulnCheck· Adobe ColdFusion
Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-1801VulnCheck· Apple iPadOS
Apple macOS iframe Sandboxing Vulnerability
- CVE-2019-5840VulnCheck· Google Chrome
Google Chrome Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2023-21746VulnCheck· Microsoft Windows
Windows NTLM Elevation of Privilege Vulnerability
- CVE-2022-2295VulnCheckKnown ransomware use· Google Chrome
Google Chrome Access of Resource Using Incompatible Type ('Type Confusion')
- CVE-2023-38204VulnCheck· Adobe ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data
- CVE-2011-0105VulnCheck· Microsoft Excel
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2022-39952VulnCheck· Fortinet FortiNAC
Fortinet FortiNAC External Control of File Name or Path
- CVE-2022-46690VulnCheck· Apple iPadOS
Apple iPadOS Out-of-bounds Write
- CVE-2019-0623VulnCheck· Microsoft Windows
Win32k Elevation of Privilege
- CVE-2023-32423VulnCheck· Apple Safari
Apple Safari Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CVE-2023-32402VulnCheck· Apple Safari
Apple Safari Out-of-bounds Read
- CVE-2022-22279VulnCheckKnown ransomware use· SonicWall SRA 1200 Firmware
SonicWall SRA 1200 Firmware Relative Path Traversal
- CVE-2023-24932VulnCheck· Microsoft Windows
Secure Boot Security Feature Bypass Vulnerability
- CVE-2022-30136VulnCheck· Microsoft Windows
Windows Network File System Remote Code Execution
- CVE-2023-21768VulnCheck· Microsoft Windows
Windows Ancillary Function Driver for WinSock Privilege Escalation
- CVE-2022-21894VulnCheck· Microsoft Windows
Secure Boot Security Feature Bypass
- CVE-2009-2521VulnCheckKnown ransomware use· Microsoft Internet Information Services (IIS)
Microsoft Internet Information Services (IIS) Uncontrolled Resource Consumption
- CVE-2020-1210VulnCheckKnown ransomware use· Microsoft SharePoint
Microsoft SharePoint Download of Code Without Integrity Check
- CVE-2023-23514VulnCheck· Apple iPadOS
Apple iPadOS Use After Free
- CVE-2023-23524VulnCheck· Apple iPadOS
Apple iPadOS Uncontrolled Resource Consumption
- CVE-2023-23522VulnCheck· Apple macOS
macOS Ventura Temporary File Handling Vulnerability
- CVE-2022-24500VulnCheckKnown ransomware use· Microsoft Windows
Windows SMB Remote Code Execution
- CVE-2022-0456VulnCheck· Google Chrome
Google Chrome Use After Free
- CVE-2022-46703VulnCheck· Apple iPadOS
iPadOS, macOS Ventura, iOS and iPadOS Read Sensitive Location Vulnerability
- CVE-2022-42837VulnCheck· Apple iPadOS
iOS and iPadOS, macOS Ventura, iOS and iPadOS, and watchOS 9.2 URL Parsing Vulnerability
- CVE-2022-46700VulnCheck· Apple Safari
Apple Safari Out-of-bounds Write
- CVE-2022-46694VulnCheck· Apple iPadOS
Apple iPadOS Out-of-bounds Write
- CVE-2022-46695VulnCheck· Apple iPadOS
Apple iPadOS Improper Restriction of Rendered UI Layers or Frames
- CVE-2022-42840VulnCheck· Apple iPadOS
macOS Monterey, macOS Ventura, macOS Big Sur, iOS and iPadOS Kernel Privilege App Code Execution Vulnerability
- CVE-2022-46718VulnCheck· Apple iPadOS
iOS and iPadOS, macOS Ventura, macOS Big Sur, and macOS Monterey App Sensitive Location Read Vulnerability
- CVE-2022-42855VulnCheck· Apple iPadOS
tvOS, macOS Monterey, macOS Ventura, iOS and iPadOS App Arbitrary Entitlements Vulnerability
- CVE-2022-42846VulnCheck· Apple iPadOS
iOS and iPadOS Malicious Video File System Termination Vulnerability
- CVE-2022-42861VulnCheck· Apple iPadOS
iOS and iPadOS, macOS Monterey, and macOS Ventura App Sandbox Bypass Vulnerability
- CVE-2022-42848VulnCheck· Apple iPadOS
iOS and iPadOS, and tvOS Kernel Privilege App Code Execution Vulnerability
- CVE-2022-46692VulnCheck· Apple iCloud
Safari, tvOS, iCloud for Windows, iOS, iPadOS, macOS Ventura, and watchOS Same Origin Policy Bypass Vulnerability
- CVE-2023-23496VulnCheck· Apple Safari
macOS Ventura, watchOS, Safari, tvOS, iOS and iPadOS Maliciously Crafted Web Content Code Execution Vulnerability
- CVE-2022-46689VulnCheck· Apple Safari
Apple Safari Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2022-42864VulnCheck· Apple iPadOS
Apple iPadOS Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CVE-2022-46705VulnCheck· Apple Safari
iOS, iPadOS, macOS Ventura, and Safari URL Spoofing Vulnerability
- CVE-2022-42852VulnCheck· Apple Safari
Safari, tvOS, macOS Ventura, watchOS 9.2, iOS and iPadOS Malicious Web Content Process Memory Disclosure Vulnerability
- CVE-2022-46691VulnCheck· Apple Safari
Apple Safari Out-of-bounds Write
- CVE-2021-34481VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Improper Privilege Management
- CVE-2021-42298VulnCheck· Microsoft Malware Protection Engine
Microsoft Malware Protection Engine Improper Control of Generation of Code ('Code Injection')
- CVE-2022-34721VulnCheck· Microsoft Windows
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution
- CVE-2020-1599VulnCheckKnown ransomware use· Microsoft Windows
Windows Spoofing Vulnerability
- CVE-2022-30170VulnCheck· Microsoft Windows
Windows Credential Roaming Service Elevation of Privilege Vulnerability
- CVE-2013-1300VulnCheck· Microsoft Windows
Win32k Memory Allocation Vulnerability
- CVE-2013-3881VulnCheck· Microsoft Windows
Win32k NULL Page Vulnerability
- CVE-2016-0095VulnCheck· Microsoft Windows
Win32k Elevation of Privilege Vulnerability
- CVE-2020-16875VulnCheckKnown ransomware use· Microsoft Exchange Server
Microsoft Exchange Server Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CVE-2021-33768VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Privilege Escalation
- CVE-2021-34470VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Privilege Escalation
- CVE-2018-6055VulnCheck· Google Chrome
Google Chrome Improper Input Validation
- CVE-2021-34730VulnCheckKnown ransomware use· Cisco Application Extension Platform
Cisco Application Extension Platform Stack-based Buffer Overflow
- CVE-2021-43207VulnCheckKnown ransomware use· Microsoft Windows
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2021-41349VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Spoofing Vulnerability
- CVE-2015-2551VulnCheckKnown ransomware use· Microsoft Windows
- CVE-2019-8646VulnCheckKnown ransomware use· Apple iPhone OS
Apple iPhone OS Out-of-bounds Read
- CVE-2022-26809VulnCheckKnown ransomware use· Microsoft Windows
Remote Procedure Call Runtime Remote Code Execution
- CVE-2015-2370VulnCheck· Microsoft Windows
Windows RPC Elevation of Privilege Vulnerability
- CVE-2021-1636VulnCheck· Microsoft SQL Server
Microsoft SQL Server Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CVE-2021-31206VulnCheckKnown ransomware use· Microsoft Exchange Server
Microsoft Exchange Server Remote Code Execution
- CVE-2015-0096VulnCheck· Microsoft Windows
Microsoft Windows Untrusted Search Path
- CVE-2010-2743VulnCheck· Microsoft Windows
Microsoft Windows Win32k Keyboard Layout Privilege Escalation
- CVE-2021-26885VulnCheck· Microsoft Windows
Windows WalletService Privilege Escalation
- CVE-2010-3338VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2021-30896VulnCheck· Apple iPadOS
iOS and iPadOS, tvOS, watchOS, and macOS Monterey Gameplay Data Disclosure Vulnerability
- CVE-2021-30895VulnCheck· Apple iPadOS
iOS, iPadOS, tvOS, watchOS, and macOS Monterey App User Contact Information Disclosure Vulnerability
- CVE-2021-1472VulnCheck· Cisco RV Series Routers
Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2021-1473VulnCheck· Cisco RV Series Routers
Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2019-1225VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2019-1224VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2019-1108VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2020-16896VulnCheckKnown ransomware use· Microsoft Windows
Windows Remote Desktop Protocol (RDP) Information Disclosure
- CVE-2018-8114VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2021-28442VulnCheck· Microsoft Windows
Windows TCP/IP Information Disclosure Vulnerability
- CVE-2018-8275VulnCheck· Microsoft Edge
Microsoft Edge Out-of-bounds Write
- CVE-2016-7242VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-3377VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-0067VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-3207VulnCheck· Microsoft Jscript
Microsoft Jscript Improper Input Validation
- CVE-2017-0141VulnCheck· Microsoft Edge
Microsoft Edge Scripting Engine Memory Corruption Vulnerability
- CVE-2011-0097VulnCheck· Microsoft Excel
Microsoft Excel Integer Overrun Vulnerability
- CVE-2021-28324VulnCheck· Microsoft Windows
Windows SMB Information Disclosure Vulnerability
- CVE-2018-0955VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2016-3205VulnCheck· Microsoft Jscript
Microsoft Jscript Improper Input Validation
- CVE-2016-7203VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-0191VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-3210VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-8598VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-5165VulnCheck· Google Chrome
Google Chrome Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2010-3336VulnCheck· Microsoft Office
Microsoft Office Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2018-8267VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2018-8122VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2016-3222VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2018-8133VulnCheck· Microsoft Edge
Microsoft Edge Access of Resource Using Incompatible Type ('Type Confusion')
- CVE-2016-3206VulnCheck· Microsoft Jscript
Microsoft Jscript Improper Input Validation
- CVE-2017-0015VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-0193VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-8605VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-8601VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-3199VulnCheck· Microsoft Edge
Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2018-0953VulnCheck· Microsoft Edge
Microsoft Edge Out-of-bounds Write
- CVE-2021-28482VulnCheckKnown ransomware use· Microsoft Exchange Server
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-1765VulnCheck· Apple Mac OS X
Apple macOS iframe Sandbox Enforcement Vulnerability
- CVE-2021-30737VulnCheck· Apple iPadOS
Apple iPadOS Out-of-bounds Write
- CVE-2019-0606VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2013-3128VulnCheck· Microsoft Windows
Microsoft Windows OpenType Font Parsing Vulnerability
- CVE-2016-4119VulnCheck· Apple Mac OS X
Apple Mac OS X Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2018-8580VulnCheck· Microsoft SharePoint
Microsoft SharePoint Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2018-8622VulnCheck· Microsoft Windows
Microsoft Windows Kernel Information Disclosure Vulnerability
- CVE-2018-8627VulnCheck· Microsoft Excel
Microsoft Excel Use of Uninitialized Resource
- CVE-2018-8477VulnCheck· Microsoft Windows
Microsoft Windows Kernel Information Disclosure Vulnerability
- CVE-2018-8595VulnCheck· Microsoft Windows
Microsoft Windows GDI Information Disclosure Vulnerability
- CVE-2018-8596VulnCheck· Microsoft Windows
Windows GDI Information Disclosure Vulnerability
- CVE-2018-8637VulnCheck· Microsoft Windows
Microsoft Win32k Information Disclosure Vulnerability
- CVE-2018-8621VulnCheck· Microsoft Windows
Microsoft Windows Kernel Information Disclosure Vulnerability
- CVE-2018-8638VulnCheck· Microsoft Windows
Microsoft Windows DirectX Information Disclosure Vulnerability
- CVE-2018-8598VulnCheck· Microsoft Excel
Microsoft Excel Information Disclosure Vulnerability
- CVE-2018-8514VulnCheck· Microsoft Windows
Microsoft Windows Improper Initialization
- CVE-2018-8616VulnCheck· Microsoft Word
Microsoft Word Information Disclosure Vulnerability
- CVE-2001-0507VulnCheck· Microsoft Internet Information Server (IIS)
Microsoft IIS 5.0 System file listing Privilege Escalation
- CVE-2003-0050VulnCheck· Apple Darwin Streaming Server
Apple Darwin Streaming Server Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2019-1040VulnCheck· Microsoft Windows
Windows NTLM Tampering
- CVE-2018-12808VulnCheckKnown ransomware use· Adobe Acrobat DC
Adobe Acrobat DC Out-of-bounds Write
- CVE-2018-8389VulnCheckKnown ransomware use· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2018-8140VulnCheckKnown ransomware use· Microsoft Windows
Cortana Elevation of Privilege
- CVE-2018-0978VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2018-8641VulnCheck· Microsoft Windows
Microsoft Windows Improper Resource Shutdown or Release
- CVE-2019-11507VulnCheckKnown ransomware use· Ivanti Connect Secure and Policy Secure
Ivanti Connect Secure and Policy Secure Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2018-4893VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Out-of-bounds Read
- CVE-2020-6453VulnCheck· Google Chrome
Google Chrome Out-of-bounds Write
- CVE-2018-0986VulnCheckKnown ransomware use· Microsoft Exchange Server
Microsoft Exchange Server Out-of-bounds Write
- CVE-2020-0651VulnCheckKnown ransomware use· Microsoft Excel
Microsoft Excel Remote Code Execution
- CVE-2020-0650VulnCheckKnown ransomware use· Microsoft Excel
Microsoft Excel Remote Code Execution
- CVE-2020-0640VulnCheckKnown ransomware use· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2020-0642VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows Use After Free
- CVE-2020-0652VulnCheckKnown ransomware use· Microsoft Excel
Microsoft Excel Out-of-bounds Write
- CVE-2020-0624VulnCheckKnown ransomware use· Microsoft Windows
Win32k Elevation of Privilege
- CVE-2020-0653VulnCheckKnown ransomware use· Microsoft Office
Microsoft Excel Remote Code Execution
- CVE-2020-0611VulnCheckKnown ransomware use· Microsoft Windows
Remote Desktop Client Remote Code Execution
- CVE-2020-0609VulnCheckKnown ransomware use· Microsoft Windows
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution
- CVE-2020-0610VulnCheckKnown ransomware use· Microsoft Windows
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution
- CVE-2013-3568VulnCheck· Cisco Linksys WRT110 Firmware
Cisco Linksys WRT110 Firmware Cross-Site Request Forgery (CSRF)
- CVE-2014-0498VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2019-8771VulnCheck· Apple Safari
Apple Safari Improper Restriction of Rendered UI Layers or Frames
- CVE-2017-13315VulnCheck· Google Android
Google Android Incorrect Calculation of Buffer Size
- CVE-2017-13156VulnCheck· Google Android
Google Android Unrestricted Upload of File with Dangerous Type
- CVE-2019-0667VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2019-0784VulnCheck· Microsoft Windows
Microsoft Windows Out-of-bounds Write
- CVE-2019-0666VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2019-0633VulnCheck· Microsoft Windows
Windows SMB Remote Code Execution
- CVE-2019-0630VulnCheck· Microsoft Windows
Windows SMB Remote Code Execution
- CVE-2017-8750VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2016-0051VulnCheck· Microsoft Windows
WebDAV Elevation of Privilege Vulnerability
- CVE-2019-7816VulnCheck· Adobe ColdFusion
Adobe ColdFusion Unrestricted Upload of File with Dangerous Type
- CVE-2019-1663VulnCheck· Cisco RV110W Firmware
Cisco RV110W Firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2017-11869VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2018-15454VulnCheck· Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Input Validation
- CVE-2018-9866VulnCheck· SonicWall Global Management System
SonicWall Global Management System Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2013-2678VulnCheck· Cisco Linksys E4200 Firmware
Cisco Linksys E4200 Firmware Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CVE-2014-6322VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2016-3225VulnCheck· Microsoft Windows
Windows SMB Server Elevation of Privilege Vulnerability
- CVE-2018-1038VulnCheck· Microsoft Windows
Windows Kernel Elevation of Privilege
- CVE-2007-5633VulnCheck· Microsoft Windows
Alfredo Milani Comparetti SpeedFan 4.33 Speedfan.sys Privilege Escalation
- CVE-2018-0101VulnCheck· Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Double Free
- CVE-2005-2678VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft IIS SERVER_NAME Variable Bypass Vulnerability
- CVE-2017-8487VulnCheck· Microsoft Windows
Windows olecnv32.dll Remote Code Execution Vulnerability
- CVE-2003-0109VulnCheck· Microsoft Windows
Microsoft Windows Out-of-bounds Write
- CVE-2009-2526VulnCheck· Microsoft Windows
Microsoft Windows Mitigating Factors for SMBv2 Infinite Loop
- CVE-2009-3103VulnCheckKnown ransomware use· Microsoft Windows
Microsoft Windows SMBv2 srv2.sys Remote Code Execution
- CVE-2004-0116VulnCheck· Microsoft Windows
Microsoft Windows Uncontrolled Resource Consumption
- CVE-2006-3439VulnCheck· Microsoft Windows
Microsoft Windows Out-of-bounds Write
- CVE-2009-0099VulnCheck· Microsoft Exchange Server
Microsoft Exchange Server Improper Input Validation
- CVE-2009-2532VulnCheck· Microsoft Windows
Microsoft Windows Improper Control of Generation of Code ('Code Injection')
- CVE-2017-2404VulnCheck· Apple iPhone OS
Apple iOS before 10.3 "Quick Look" Call Trigger
- CVE-2014-0569VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Integer Overflow or Wraparound
- CVE-2011-0101VulnCheck· Microsoft Excel
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2014-0564VulnCheck· Adobe Flash Player
Adobe Flash Player Arbitrary Code Execution
- CVE-2009-3674VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Uninitialized Memory Corruption
- CVE-2013-5326VulnCheck· Adobe ColdFusion
Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2006-3227VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer ASCII encoded Web filter bypass
- CVE-2016-6909VulnCheck· Fortinet FortiOS
Fortinet FortiOS Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2014-3393VulnCheck· Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Authentication
- CVE-2014-4076VulnCheck· Microsoft Windows
TCP/IP Elevation of Privilege Vulnerability
- CVE-2016-0728VulnCheck· Google Android
Google Android Integer Overflow or Wraparound
- CVE-2016-0147VulnCheck· Microsoft XMP Core Services
Microsoft XMP Core Services Improper Input Validation
- CVE-2016-1409VulnCheck· Cisco iOS
Cisco iOS Improper Input Validation
- CVE-2010-1240VulnCheck· Adobe Acrobat and Reader
Adobe Reader and Acrobat Launch File Warning Vulnerability
- CVE-2015-1637VulnCheck· Microsoft Windows
Schannel Security Feature Bypass Vulnerability
- CVE-2001-0876VulnCheck· Microsoft Windows 98
Microsoft Windows 98 Out-of-bounds Write
- CVE-2003-0818VulnCheck· Microsoft Windows
Microsoft Windows Integer Overflow or Wraparound
- CVE-2001-0877VulnCheck· Microsoft Windows 98
Universal Plug and Play Unchecked Buffer Denial of Service
- CVE-2015-1805VulnCheck· Google Android
Linux kernel before 3.16 Pipe Read and Pipe Write I/O Vector Array Overrun
- CVE-2016-0021VulnCheck· Microsoft Infopath
Microsoft Infopath Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2011-1255VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Use of Uninitialized Resource
- CVE-2015-8446VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2015-0359VulnCheck· Adobe Flash Player
Adobe Flash Player Double Free
- CVE-2015-5560VulnCheck· Adobe Flash Player
Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution
- CVE-2015-0003VulnCheck· Microsoft Windows
Microsoft Windows NULL Pointer Dereference
- CVE-2015-3090VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2015-3104VulnCheck· Adobe Air
Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution
- CVE-2015-0349VulnCheck· Adobe Flash Player
Adobe Flash Player Use After Free
- CVE-2015-3133VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2015-3105VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2015-0336VulnCheck· Adobe Flash Player
Adobe Flash Player Access of Resource Using Incompatible Type ('Type Confusion')
- CVE-2015-0072VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2014-0311VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2013-3894VulnCheck· Microsoft Windows
Microsoft Windows Improper Control of Generation of Code ('Code Injection')
- CVE-2012-0159VulnCheck· Microsoft Office
Microsoft Windows TrueType Font Parsing Vulnerability Remote Code Execution
- CVE-2014-0556VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2014-0324VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2014-1809VulnCheck· Microsoft Office
MSCOMCTL ASLR Vulnerability
- CVE-2014-1815VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2014-1807VulnCheck· Microsoft Windows
Windows Shell File Association Vulnerability
- CVE-2014-0515VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2014-0266VulnCheck· Microsoft Windows
Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2014-0295VulnCheck· Microsoft .NET Framework
VSAVB7RT ASLR Vulnerability
- CVE-2014-0253VulnCheck· Microsoft .NET Framework
Microsoft .NET Framework Improper Input Validation
- CVE-2013-5330VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2012-0773VulnCheck· Adobe Flash Player
Adobe Flash Player Out-of-bounds Write
- CVE-2012-2520VulnCheck· Microsoft Groove Server
Microsoft Groove Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2013-5331VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Control of Generation of Code ('Code Injection')
- CVE-2013-5054VulnCheck· Microsoft Office
Microsoft Office Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2013-5057VulnCheck· Microsoft Office
Microsoft Office 2007 SP3 and 2010 SP1 and SP2 HXDS ASLR Vulnerability
- CVE-2013-3336VulnCheck· Adobe ColdFusion
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 Remote File Read
- CVE-2013-1389VulnCheck· Adobe ColdFusion
Adobe ColdFusion Remote Code Execution
- CVE-2013-1289VulnCheck· Microsoft Groove Server
Microsoft Groove Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2009-3957VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader NULL Pointer Dereference
- CVE-2012-4167VulnCheck· Adobe Flash Player
Adobe Flash Player Integer Overflow Remote Code Execution
- CVE-2013-0633VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2013-0634VulnCheckKnown ransomware use· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2011-0559VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2010-1241VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2009-0084VulnCheck· Microsoft Windows
Microsoft Windows Improper Control of Generation of Code ('Code Injection')
- CVE-2010-0480VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2009-3126VulnCheck· Microsoft Windows
Microsoft GDI+ PNG Integer Overflow
- CVE-2010-2862VulnCheck· Adobe Acrobat and Reader
Adobe Reader CoolType.dll Remote Code Execution
- CVE-2008-2249VulnCheck· Microsoft Windows
Microsoft Windows Mitigating Factors for GDI Integer Overflow
- CVE-2009-1134VulnCheck· Microsoft Office
Microsoft Office Improper Control of Generation of Code ('Code Injection')
- CVE-2009-0561VulnCheck· Microsoft Office
Microsoft Office Excel Record Integer Overflow
- CVE-2011-0618VulnCheck· Adobe Flash Player
Adobe Flash Player Arbitrary Code Execution
- CVE-2010-0028VulnCheck· Microsoft Windows
MS Paint Integer Overflow Vulnerability
- CVE-2009-2501VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2011-0227VulnCheck· Apple iPhone OS
Apple iOS before 4.2.9 and 4.3.x before 4.3.4 IOMobileFrameBuffer Privilege Escalation
- CVE-2012-1875VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Control of Generation of Code ('Code Injection')
- CVE-2012-0779VulnCheck· Adobe Flash Player
Adobe Flash Player object confusion Remote Code Execution
- CVE-2012-0152VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2011-2140VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2012-0003VulnCheck· Microsoft Windows
Windows Media Player (WMP) MIDI Remote Code Execution Vulnerability
- CVE-2011-3414VulnCheck· Microsoft Windows
Microsoft .NET Framework CaseInsensitiveHashProvider.getHashCode Function Vulnerability
- CVE-2011-1269VulnCheck· Microsoft Office
Microsoft Office Improper Input Validation
- CVE-2011-4369VulnCheck· Adobe Acrobat and Reader
Adobe Reader and Acrobat PRC component Remote Code Execution
- CVE-2010-3332VulnCheck· Microsoft .NET Framework
Microsoft .NET Framework Generation of Error Message Containing Sensitive Information
- CVE-2011-2444VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2011-1968VulnCheck· Microsoft Windows
Remote Desktop Protocol Vulnerability
- CVE-2010-1885VulnCheck· Microsoft Windows
Microsoft Windows Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2011-1249VulnCheck· Microsoft Windows
Ancillary Function Driver Elevation of Privilege Vulnerability
- CVE-2011-2110VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2011-2107VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2011-0094VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer 6 and 7 Layouts Handling Memory Corruption Vulnerability
- CVE-2011-1345VulnCheck· Microsoft Internet Explorer
Object Management Memory Corruption Vulnerability
- CVE-2011-0627VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Input Validation
- CVE-2008-1898VulnCheck· Microsoft Office
Microsoft Office Improper Input Validation
- CVE-2011-0096VulnCheck· Microsoft Windows
Microsoft Windows Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2010-3971VulnCheck· Microsoft Internet Explorer
Microsoft CSS Memory Corruption Vulnerability
- CVE-2010-3654VulnCheck· Adobe Flash Player
Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2010-3653VulnCheck· Adobe Shockwave Player
Adobe Shockwave Player Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2010-3889VulnCheck· Microsoft Windows
Microsoft Windows 32-bit Platforms Unspecified Privilege Escalation
- CVE-2010-3888VulnCheck· Microsoft Windows
Microsoft Windows 32-bit Privilege Escalation
- CVE-2010-2729VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2010-2884VulnCheck· Adobe Flash Player
Adobe Flash Player Denial of Service
- CVE-2010-1797VulnCheck· Apple iPhone OS
Apple iPhone OS Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2010-0817VulnCheck· Microsoft SharePoint
Microsoft SharePoint Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2004-0431VulnCheck· Apple QuickTime
Apple QuickTime Integer Overflow or Wraparound
- CVE-2006-6027VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat Reader AcroPDF ActiveX Vulnerability
- CVE-2007-6166VulnCheck· Apple QuickTime
Apple QuickTime Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2008-3008VulnCheck· Microsoft Windows Media Encoder
Microsoft Windows Media Encoder Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2006-0005VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2006-5559VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2009-1930VulnCheck· Microsoft Windows
Microsoft Telnet Credential Reflection Vulnerability
- CVE-2006-0003VulnCheck· Microsoft Data Access Components
Microsoft Data Access Components (MDAC) RDS.Dataspace ActiveX Control Vulnerability
- CVE-2004-1049VulnCheck· Microsoft Windows
Microsoft Windows Integer Overflow or Wraparound
- CVE-2003-0111VulnCheck· Microsoft Virtual Machine
Microsoft Virtual Machine ByteCode Verifier Component Code Execution Vulnerability
- CVE-2009-0075VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer 7 Uninitialized Memory Corruption Vulnerability
- CVE-2006-3643VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2009-1493VulnCheck· Adobe Acrobat and Reader
Adobe Reader customDictionaryOpen Spell Method Vulnerability
- CVE-2008-2042VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Input Validation
- CVE-2009-1492VulnCheck· Adobe Acrobat and Reader
Adobe Reader and Acrobat getAnnots Doc Method Vulnerability
- CVE-2009-2990VulnCheck· Adobe Acrobat and Reader
Adobe Reader and Acrobat Arbitrary Code Execution
- CVE-2009-0555VulnCheck· Microsoft Windows
Microsoft Windows Improper Control of Generation of Code ('Code Injection')
- CVE-2009-2493VulnCheck· Microsoft Visual C\+\+
Microsoft Active Template Library (ATL) COM Initialization Vulnerability
- CVE-2009-3023VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft Internet Information Services (IIS) Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CVE-2009-1923VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2009-1536VulnCheck· Microsoft .NET Framework
Microsoft .NET Framework Improper Input Validation
- CVE-2009-1136VulnCheck· Microsoft Isa Server
Microsoft Isa Server Improper Control of Generation of Code ('Code Injection')
- CVE-2009-0087VulnCheck· Microsoft Office
WordPad and Office Text Converter Memory Corruption Vulnerability
- CVE-2008-1436VulnCheck· Microsoft Windows
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 Privilege Escalation
- CVE-2009-0080VulnCheck· Microsoft Windows
Microsoft Windows Improper Privilege Management
- CVE-2009-0078VulnCheck· Microsoft Windows
Windows WMI Service Isolation Vulnerability
- CVE-2009-0079VulnCheck· Microsoft Windows
Windows RPCSS Service Isolation Vulnerability
- CVE-2007-0015VulnCheck· Apple QuickTime
Apple QuickTime Out-of-bounds Write
- CVE-2009-0658VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2008-4844VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer CRecordInstance::TransferToDestination Remote Code Execution
- CVE-2008-4841VulnCheck· Microsoft WordPad
WordPad Word 97 Text Converter Stack Overflow Vulnerability
- CVE-2008-1446VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft Internet Information Services (IIS) Integer Overflow or Wraparound
- CVE-2008-2463VulnCheck· Microsoft Office
Microsoft Office Improper Control of Generation of Code ('Code Injection')
- CVE-2008-0081VulnCheck· Microsoft Excel
Microsoft Excel Use of Uninitialized Resource
- CVE-2006-5758VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2008-3873VulnCheck· Adobe Flash Player
Adobe Flash Player 9.0.124.0 and earlier System.setClipboard method in ActionScript Vulnerability
- CVE-2008-3704VulnCheck· Microsoft Visual Basic
Microsoft Visual Basic Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2008-2244VulnCheck· Microsoft Office
Microsoft Office Word 2002 SP3 Malformed Data Remote Code Execution
- CVE-2008-2641VulnCheck· Adobe Acrobat 3D
Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2 Input Validation in a JavaScript Method Vulnerability
- CVE-2007-0071VulnCheck· Adobe Flash Player
Adobe Flash Player SWF Negative Scene Count Vulnerability
- CVE-2007-6026VulnCheck· Microsoft Jet
Microsoft Jet Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2008-1092VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2007-5347VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer 5.01 through 7 DHTML Object Memory Corruption Vulnerability
- CVE-2007-5587VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2007-3896VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2007-5020VulnCheck· Adobe Acrobat and Reader
Adobe Acrobat and Reader Improper Control of Generation of Code ('Code Injection')
- CVE-2007-3899VulnCheck· Microsoft Office
Microsoft Office Improper Control of Generation of Code ('Code Injection')
- CVE-2003-0352VulnCheck· Microsoft Windows
Microsoft Windows Out-of-bounds Write
- CVE-2007-1070VulnCheck· Microsoft Windows
Microsoft Windows Out-of-bounds Write
- CVE-2007-1748VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2007-0870VulnCheck· Microsoft Word
Word Document Stream Vulnerability
- CVE-2007-0038VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2007-1765VulnCheck· Microsoft Windows
Microsoft Windows Cursor, Animated Cursor, and Icon Processing Vulnerability
- CVE-2007-0515VulnCheck· Microsoft Office
Word Malformed Function Vulnerability
- CVE-2006-6456VulnCheck· Microsoft Office
Word Malformed Data Structures Vulnerability
- CVE-2006-6561VulnCheck· Microsoft Office
Microsoft Word Count Vulnerability
- CVE-2006-5994VulnCheck· Microsoft Office
Word Malformed String Vulnerability
- CVE-2007-0024VulnCheck· Microsoft Windows
Microsoft Windows Integer Overflow or Wraparound
- CVE-2006-4704VulnCheck· Microsoft Visual Studio
Microsoft Visual Studio 2005 WMI Object Broker Vulnerability
- CVE-2006-4446VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Out-of-bounds Write
- CVE-2006-4777VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2006-5745VulnCheck· Microsoft XMP Core Services
Microsoft XML Core Services Vulnerability
- CVE-2006-4534VulnCheck· Microsoft Office
Microsoft Word Malformed Stack Vulnerability
- CVE-2006-4694VulnCheck· Microsoft Office
Microsoft Office Improper Control of Generation of Code ('Code Injection')
- CVE-2006-3730VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Control of Generation of Code ('Code Injection')
- CVE-2006-4868VulnCheck· Microsoft Windows
Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2006-3649VulnCheck· Microsoft Visual Basic
Microsoft Visual Basic Out-of-bounds Write
- CVE-2006-3590VulnCheck· Microsoft PowerPoint
Microsoft PowerPoint Mso.dll Vulnerability
- CVE-2006-1301VulnCheck· Microsoft Excel
Microsoft Excel Improper Control of Generation of Code ('Code Injection')
- CVE-2006-1540VulnCheck· Microsoft Office
Microsoft Office Improper Control of Generation of Code ('Code Injection')
- CVE-2006-3059VulnCheck· Microsoft Excel
Microsoft Excel Malformed file Vulnerability
- CVE-2006-1359VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Control of Generation of Code ('Code Injection')
- CVE-2006-0009VulnCheck· Microsoft Office
Microsoft Office Out-of-bounds Write
- CVE-2005-4560VulnCheck· Microsoft Windows
Microsoft Windows Improper Input Validation
- CVE-2005-1790VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Javascript BODY onload Vulnerability
- CVE-2000-0884VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft IIS 4.0 and 5.0 Folder Traversal Vulnerability
- CVE-2001-0154VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer HTML E-mail Feature Vulnerability
- CVE-2005-1983VulnCheck· Microsoft Windows
Microsoft Windows Out-of-bounds Write
- CVE-2005-1219VulnCheck· Microsoft Image Color Management
Microsoft Image Color Management Out-of-bounds Write
- CVE-2005-2087VulnCheck· Microsoft Internet Explorer
Microsoft IE 5.01 SP4 up to 6 javaprxy.dll COM Instantiation Heap Corruption Vulnerability
- CVE-2004-0847VulnCheck· Microsoft Asp.net
Microsoft Asp.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2005-0053VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Drag-and-Drop Vulnerability
- CVE-2004-1043VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer HTML Help ActiveX control Cross Domain Vulnerability
- CVE-2004-0727VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Similar Method Name Redirection Cross Domain Vulnerability
- CVE-2004-0566VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Integer Overflow or Wraparound
- CVE-2004-0549VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer showModalDialog Method Vulnerability
- CVE-2003-1041VulnCheck· Microsoft Internet Explorer
Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2003-0533VulnCheck· Microsoft Netmeeting
Microsoft Netmeeting Out-of-bounds Write
- CVE-2004-0380VulnCheck· Microsoft Outlook Express
Microsoft Outlook Express MHTML URL Processing Vulnerability
- CVE-2002-0649VulnCheck· Microsoft Data Engine
Microsoft Data Engine Improper Restriction of Operations within the Bounds of a Memory Buffer
- CVE-2003-0605VulnCheck· Microsoft Windows
Windows 2000 SP3 and SP4 PerformScmStage function Vulnerability
- CVE-2002-1717VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2001-0500VulnCheck· Microsoft Index Server
Microsoft Index Server Out-of-bounds Write
- CVE-2001-0333VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft Internet Information Services (IIS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2000-0071VulnCheck· Microsoft Internet Information Services (IIS)
Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized Actor
VulnCheck also tracks 3,136 exploited CVEs outside the SMB-relevant vendor allowlist — gear we don't typically see in dental, law, or accounting shops. Full exploited-not-on-CISA breadth: 3,689.
Breadth data via VulnCheck KEV.
Last 90 days
Added recently.
New SMB-relevant additions to KEV in the last 90 days — the urgent items most likely to need action this quarter.
CVE-2026-104286 · Fortinet FortiMailPath Traversal VulnerabilityPatch secondAdded to KEV Oct 1, 2026
Fortinet FortiMail Path Traversal Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CVE-2026-76504 · Cisco Catalyst SD-WAN ManagerHex Encoding VulnerabilityPatch secondAdded to KEV Sep 30, 2026
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
CVE-2026-86950 · Apple Multiple ProductsOut-of-Bounds Write VulnerabilityPatch thirdAdded to KEV Sep 29, 2026
Apple Multiple Products Out-of-Bounds Write Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CVE-2026-65660 · Microsoft SharePointCode Injection VulnerabilityPatch thirdAdded to KEV Sep 25, 2026
Microsoft SharePoint Code Injection Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
CVE-2026-71362 · Adobe Commerce and MagentoIncorrect Authorization VulnerabilityPatch secondAdded to KEV Sep 24, 2026
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Affects anyone running Adobe Commerce and Magento. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
CVE-2026-76460 · Cisco Identity Services EngineIncorrect Use of Privileged APIs VulnerabilityPatch secondAdded to KEV Sep 16, 2026
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CVE-2026-58704 · Google PixelImproper Authorization VulnerabilityPatch thirdAdded to KEV Sep 16, 2026
Google Pixel Improper Authorization Vulnerability
Affects anyone running Google Pixel. Google products typically sit at the identity or browsing layer — exploitation usually affects access to cloud services and stored sessions.
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
CVE-2026-76461 · Cisco Secure Email GatewaySQL Injection VulnerabilityPatch secondAdded to KEV Sep 14, 2026
Cisco Secure Email Gateway SQL Injection Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
CVE-2025-25249 · Fortinet Multiple ProductsHeap-based Buffer Overflow VulnerabilityPatch secondAdded to KEV Sep 9, 2026
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
CVE-2026-20079 · Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementFirewall Management Center Authentication Bypass Using an Alternate Path or Channel VulnerabilityPatch secondAdded to KEV Sep 9, 2026
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
CVE-2026-87491 · Google Chromium V8Out of Bounds Write VulnerabilityPatch thirdAdded to KEV Sep 9, 2026
Google Chromium V8 Out of Bounds Write Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-75650 · Adobe Commerce and MagentoImproper Neutralization of Special Elements Used in a Template Engine VulnerabilityPatch secondAdded to KEV Sep 8, 2026
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Affects anyone running Adobe Commerce and Magento. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Microsoft Windows: 2 CVEsPatch thirdadded Sep 8, 2026
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
- KB5122876
- KB5122882
- KB5122878
- KB5123099
- +2 more
Microsoft Windows Link Following Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
- KB5122871
- KB5124008
- KB5122880
- KB5124012
CVE-2026-85046 · Google Chromium V8Type Confusion VulnerabilityPatch thirdAdded to KEV Sep 4, 2026
Google Chromium V8 Type Confusion Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
SonicWall SMA1000 Appliances: 2 CVEsPatch secondadded Sep 2, 2026
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVE-2019-1068 · Microsoft SQL ServerRemote Code Execution VulnerabilityPatch thirdAdded to KEV Aug 26, 2026
Microsoft SQL Server Remote Code Execution Vulnerability
Affects anyone running Microsoft SQL Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CVE-2026-33824 · Microsoft Internet Key Exchange (IKE) Service ExtensionsDouble Free VulnerabilityPatch secondAdded to KEV Aug 18, 2026
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CVE-2026-55040 · Microsoft SharePointWeak Authentication VulnerabilityPatch secondAdded to KEV Aug 18, 2026
Microsoft SharePoint Weak Authentication Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-65400 · Apple macOSImproper Authentication VulnerabilityPatch secondAdded to KEV Aug 18, 2026
Apple macOS Improper Authentication Vulnerability
Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)Heap Inspection VulnerabilityPatch secondAdded to KEV Aug 11, 2026
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSockUse-After-Free VulnerabilityPatch thirdAdded to KEV Aug 11, 2026
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5120238
- KB5120242
- KB5120229
- KB5120249
- +9 more
CVE-2026-20316 · Cisco Secure Firewall Management Center (FMC)Secure Firewall Management Center Use of Hard-coded Password VulnerabilityKnown ransomware usePatch firstAdded to KEV Jul 29, 2026
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
CVE-2025-68686 · Fortinet FortiOSExposure of Sensitive Information to an Unauthorized Actor VulnerabilityPatch thirdAdded to KEV Jul 27, 2026
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CVE-2026-50522 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch secondAdded to KEV Jul 22, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CVE-2026-58644 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch secondAdded to KEV Jul 16, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Fortinet FortiSandbox: 2 CVEsPatch secondadded Jul 16, 2026
Fortinet FortiSandbox OS Command Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Fortinet FortiSandbox OS Command Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
SonicWall SMA1000 Appliances: 2 CVEsPatch firstadded Jul 14, 2026
- CVE-2026-15409Known ransomware use
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
- CVE-2026-15410Known ransomware use
SonicWall SMA1000 Appliances Code Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVE-2026-56155 · Microsoft Active Directory Federation ServicesInsufficient Granularity of Access Control VulnerabilityPatch thirdAdded to KEV Jul 14, 2026
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Affects anyone running Microsoft Active Directory Federation Services. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5099538
- KB5099540
- KB5099536
- KB5099535
- +2 more
CVE-2026-56164 · Microsoft SharePoint ServerMissing Authentication for Critical Function VulnerabilityPatch fourthAdded to KEV Jul 14, 2026
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
CVE-2008-4128 · Cisco iOSCross-Site Request Forgery VulnerabilityPatch secondAdded to KEV Jul 13, 2026
Cisco iOS Cross-Site Request Forgery Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Earlier
Older entries still worth a check.
The most recent SMB-relevant entries that predate the 90-day window above. Use the search bar to reach anything older.
CVE-2026-48282 · Adobe ColdFusionPath Traversal VulnerabilityPatch secondAdded to KEV Jul 7, 2026
Adobe ColdFusion Path Traversal Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
CVE-2026-45659 · Microsoft SharePoint ServerDeserialization of Untrusted Data VulnerabilityKnown ransomware usePatch firstAdded to KEV Jul 1, 2026
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-20230 · Cisco Unified Communications ManagerServer-Side Request Forgery (SSRF) VulnerabilityPatch secondAdded to KEV Jun 25, 2026
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
Ubiquiti UniFi OS: 3 CVEsPatch secondadded Jun 23, 2026
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Ubiquiti UniFi OS Path Traversal Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Ubiquiti UniFi OS Improper Access Control Vulnerability
Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
CVE-2026-20262 · Cisco Catalyst SD-WAN ManagerDirectory or Path Traversal VulnerabilityPatch thirdAdded to KEV Jun 15, 2026
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
CVE-2026-10520 · Ivanti SentryOS Command Injection VulnerabilityPatch secondAdded to KEV Jun 11, 2026
Ivanti Sentry OS Command Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
CVE-2026-11645 · Google Chromium V8Out-of-Bounds Read and Write VulnerabilityPatch thirdAdded to KEV Jun 9, 2026
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-20245 · Cisco Catalyst SD-WAN ManagerImproper Encoding or Escaping of Output VulnerabilityPatch secondAdded to KEV Jun 9, 2026
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
CVE-2026-0257 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityKnown ransomware usePatch firstAdded to KEV May 29, 2026
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2010-0806 · Microsoft Internet ExplorerUse-After-Free VulnerabilityPatch thirdAdded to KEV May 20, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability
Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2009-3459 · Adobe Acrobat and ReaderHeap-Based Buffer Overflow VulnerabilityPatch thirdAdded to KEV May 20, 2026
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Microsoft Defender: 2 CVEsPatch thirdadded May 20, 2026
Microsoft Defender Link Following Vulnerability
Affects anyone running Microsoft Defender. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Microsoft Defender Denial of Service Vulnerability
Affects anyone running Microsoft Defender. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CVE-2008-4250 · Microsoft WindowsBuffer Overflow VulnerabilityPatch secondAdded to KEV May 20, 2026
Microsoft Windows Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Not sure where to start
You don't have to triage 845 vulnerabilities yourself.
We watch this list daily and tell you which ones touch the software you actually run. Free 30-minute briefing — share what you have, get a prioritized short list back, and we tell you when you don't need us.
