ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

Real-Time Threat Intelligence & CVE Tracker

Continuous monitoring and intelligence feed for newly disclosed Common Vulnerabilities and Exposures (CVEs).

100 CISA KEV Exploits Active 20 Vulnerabilities Monitored Live Feed Sync: Real-time
High-Impact Zero-Day Spotlight CRITICAL CVSS 9.8 1 month ago
CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Vendor: Cisco Fix: Vendor Patch / Mitigation Available

Latest Security Vulnerabilities

Explore Feed
CVE-2026-20349 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 1 month ago

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Vendor: Cisco Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) View Details
CVE-2026-20316 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Cisco Secure Firewall Management Center (FMC) Vulnerability

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

Vendor: Cisco Product: Secure Firewall Management Center (FMC) View Details
CVE-2025-68686 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Fortinet FortiOS Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Vendor: Fortinet Product: FortiOS View Details
CVE-2026-15610 MEDIUM 4.3 2 months ago

by All

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger arbitrary re-embedding of stored RAG documents, modifying the rag_documents table and consuming the site owner's paid third-party AI API credits (OpenAI, Gemini, OpenRouter, or xAI).

Vendor: All View Details
CVE-2026-39808 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Fortinet FortiSandbox Vulnerability

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Vendor: Fortinet Product: FortiSandbox View Details
CVE-2026-25089 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Fortinet FortiSandbox Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Vendor: Fortinet Product: FortiSandbox View Details
CVE-2026-15410 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

SonicWall SMA1000 Appliances Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Vendor: SonicWall Product: SMA1000 Appliances View Details
CVE-2026-15409 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

SonicWall SMA1000 Appliances Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Vendor: SonicWall Product: SMA1000 Appliances View Details
CVE-2008-4128 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 2 months ago

Cisco IOS Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

Vendor: Cisco Product: IOS View Details
CVE-2026-20230 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 3 months ago

Cisco Unified Communications Manager Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Vendor: Cisco Product: Unified Communications Manager View Details
CVE-2026-20262 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 3 months ago

Cisco Catalyst SD-WAN Manager Vulnerability

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

Vendor: Cisco Product: Catalyst SD-WAN Manager View Details
CVE-2026-20245 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 4 months ago

Cisco Catalyst SD-WAN Manager Vulnerability

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

Vendor: Cisco Product: Catalyst SD-WAN Manager View Details
CVE-2026-7473 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 4 months ago

Arista Extensible Operating System Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

Vendor: Arista Product: Extensible Operating System View Details
CVE-2026-50751 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 4 months ago

Check Point Security Gateway Vulnerability

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Vendor: Check Point Product: Security Gateway View Details
CVE-2026-0257 CRITICAL 9.8 Fix: Vendor Patch / Mitigation Available 4 months ago

Palo Alto Networks PAN-OS Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Vendor: Palo Alto Networks Product: PAN-OS View Details