ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

Real-Time Threat Intelligence & CVE Tracker

Continuous monitoring and intelligence feed for newly disclosed Common Vulnerabilities and Exposures (CVEs).

100 CISA KEV Exploits Active 200 Vulnerabilities Monitored Live Feed Sync: Real-time
High-Impact Zero-Day Spotlight CRITICAL CVSS 9.8 1 month ago
CVE-2026-72898: Metabase Metabase Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Vendor: Metabase Fix: Vendor Patch / Mitigation Available

Latest Security Vulnerabilities

Explore Feed
CVE-2026-72898 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 1 month ago

Metabase Metabase Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

Vendor: Metabase View Details
CVE-2026-68820 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 1 month ago

Microsoft Windows Ancillary Function Driver for WinSock Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Vendor: Microsoft Product: Windows Ancillary Function Driver for WinSock View Details
CVE-2026-20349 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 1 month ago

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Vendor: Cisco Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) View Details
CVE-2026-8037 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Progress LoadMaster Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Vendor: Progress Product: LoadMaster View Details
CVE-2026-63077 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

JetBrains TeamCity Vulnerability

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

Vendor: JetBrains Product: TeamCity View Details
CVE-2026-9198 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

IBM Langflow Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

Vendor: IBM Product: Langflow View Details
CVE-2026-34486 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Apache Tomcat Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Vendor: Apache Product: Tomcat View Details
CVE-2026-18556 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

N-able N-central Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

Vendor: N-able Product: N-central View Details
CVE-2026-18577 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

N-able N-central Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

Vendor: N-able Product: N-central View Details
CVE-2026-20316 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Cisco Secure Firewall Management Center (FMC) Vulnerability

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Vendor: Cisco Product: Secure Firewall Management Center (FMC) View Details
CVE-2026-16812 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Arista VeloCloud Orchestrator Vulnerability

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

Vendor: Arista Product: VeloCloud Orchestrator View Details
CVE-2025-68686 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Fortinet FortiOS Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Vendor: Fortinet Product: FortiOS View Details
CVE-2026-50522 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Microsoft SharePoint Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Vendor: Microsoft Product: SharePoint View Details
CVE-2026-16232 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Check Point SmartConsole Vulnerability

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

Vendor: Check Point Product: SmartConsole View Details
CVE-2021-27137 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

DD-WRT DD-WRT Vulnerability

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

Vendor: DD-WRT View Details