Recent severe CVEs
The 5 most recent actively-exploited and CRITICAL-severity vulnerabilities from CISA's Known Exploited Vulnerabilities catalog and NIST's National Vulnerability Database. Updated hourly. About these sources ↗
Fortinet FortiMail Path Traversal Vulnerability
Fortinet · FortiMail
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple · Multiple Products
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix · NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Citrix NetScaler Improper Input Validation Vulnerability
Citrix · NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.