vulnti.work

Vulnerability list

Filter public vulnerability entries by severity / channel / vendor / time.

Clear
Broadcom VMware Aria Operations Command Injection Vulnerability
Critical KEV

CVE-2026-22719 · 2026-09-02 · pending_review

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remot…

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Critical KEV

CVE-2026-20182 · 2026-09-02 · pending_review

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected syste…

Cisco Unified Communications Products Code Injection Vulnerability
Critical KEV

CVE-2026-20045 · 2026-09-02 · pending_review

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Uni…

Ivanti Sentry OS Command Injection Vulnerability
Critical KEV

CVE-2026-10520 · 2026-09-02 · pending_review

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be su…

Citrix NetScaler Memory Overflow Vulnerability
Critical KEV

CVE-2025-7775 · 2026-09-02 · pending_review

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

Oracle E-Business Suite Unspecified Vulnerability
Critical 9.8 KEV

CVE-2025-61882 · 2026-09-02 · pending_review

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Proc…

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Critical KEV

CVE-2025-4428 · 2026-09-02 · pending_review

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability res…

SonicWall SMA1000 Appliances Deserialization Vulnerability
Critical 9.8 KEV

CVE-2025-23006 · 2026-09-02 · pending_review

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrar…

Cisco Identity Services Engine Injection Vulnerability
Critical KEV

CVE-2025-20337 · 2026-09-02 · pending_review

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability…

Cisco Identity Services Engine Injection Vulnerability
Critical KEV

CVE-2025-20281 · 2026-09-02 · pending_review

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability…

Mozilla Firefox Use-After-Free Vulnerability
Critical 9.8 KEV

CVE-2024-9680 · 2026-09-02 · pending_review

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Critical 9.8 KEV

CVE-2024-55591 · 2026-09-02 · pending_review

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Critical KEV

CVE-2024-37079 · 2026-09-02 · pending_review

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafte…

Android Kernel Remote Code Execution Vulnerability
Critical KEV

CVE-2024-36971 · 2026-09-02 · pending_review

Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Critical KEV

CVE-2024-3393 · 2026-09-02 · pending_review

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeat…

Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Critical 9.1 KEV

CVE-2024-21887 · 2026-09-02 · pending_review

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrat…

Fortinet FortiOS Out-of-Bound Write Vulnerability
Critical 9.8 KEV

CVE-2024-21762 · 2026-09-02 · pending_review

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

Cisco ASA and FTD Denial-of-Service Vulnerability
Critical KEV

CVE-2024-20481 · 2026-09-02 · pending_review

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a deni…

Cisco Smart Licensing Utility Static Credential Vulnerability
Critical KEV

CVE-2024-20439 · 2026-09-02 · pending_review

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Critical 9.4 KEV

CVE-2023-4966 · 2026-09-02 · pending_review

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA vir…

Qlik Sense HTTP Tunneling Vulnerability
Critical 9.6 KEV

CVE-2023-41265 · 2026-09-02 · pending_review

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

Microsoft Windows Search Remote Code Execution Vulnerability
Critical KEV

CVE-2023-36884 · 2026-09-02 · pending_review

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Critical 9.8 KEV

CVE-2023-35078 · 2026-09-02 · pending_review

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API pat…

VMware vCenter Server Out-of-Bounds Write Vulnerability
Critical KEV

CVE-2023-34048 · 2026-09-02 · pending_review

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Critical KEV

CVE-2023-33010 · 2026-09-02 · pending_review

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-servi…

Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Critical KEV

CVE-2023-33009 · 2026-09-02 · pending_review

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-servic…

Zyxel Multiple Firewalls OS Command Injection Vulnerability
Critical KEV

CVE-2023-28771 · 2026-09-02 · pending_review

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

Zyxel Multiple NAS Devices Command Injection Vulnerability
Critical KEV

CVE-2023-27992 · 2026-09-02 · pending_review

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.

Vmware Aria Operations for Networks Command Injection Vulnerability
Critical KEV

CVE-2023-20887 · 2026-09-02 · pending_review

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution…

Next page →