vulnti.work

Vulnerability list

Filter public vulnerability entries by severity / channel / vendor / time.

Clear
Microsoft Exchange Server Cross-Site Scripting Vulnerability
High KEV

CVE-2026-42897 · 2026-07-14 · pending_review

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browse…

Citrix NetScaler Out-of-Bounds Read Vulnerability
High KEV

CVE-2026-3055 · 2026-07-14 · pending_review

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overre…

Fortinet FortiClient EMS SQL Injection Vulnerability
High KEV

CVE-2026-21643 · 2026-07-14 · pending_review

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Microsoft Windows Type Confusion Vulnerability
High KEV

CVE-2026-21519 · 2026-07-14 · pending_review

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.

Microsoft Windows Information Disclosure Vulnerability
High KEV

CVE-2026-20805 · 2026-07-14 · pending_review

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
High KEV

CVE-2026-1603 · 2026-07-14 · pending_review

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
High KEV

CVE-2026-0300 · 2026-07-14 · pending_review

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root pri…

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
High KEV

CVE-2025-6543 · 2026-07-15 · pending_review

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) …

Fortinet FortiWeb Path Traversal Vulnerability
High KEV

CVE-2025-64446 · 2026-07-14 · pending_review

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Microsoft Windows Use After Free Vulnerability
High KEV

CVE-2025-62221 · 2026-07-14 · pending_review

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.

Microsoft Windows Race Condition Vulnerability
High KEV

CVE-2025-62215 · 2026-07-14 · pending_review

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to g…

Oracle E-Business Suite Unspecified Vulnerability
High KEV

CVE-2025-61882 · 2026-07-15 · pending_review

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Proc…

Microsoft Windows Improper Access Control Vulnerability
High KEV

CVE-2025-59230 · 2026-07-15 · pending_review

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

Fortinet FortiWeb OS Command Injection Vulnerability
High KEV

CVE-2025-58034 · 2026-07-14 · pending_review

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
High KEV

CVE-2025-5777 · 2026-07-15 · pending_review

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual…

Android Framework Integer Overflow Vulnerability
High KEV

CVE-2025-48595 · 2026-07-14 · pending_review

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

Android Runtime Use-After-Free Vulnerability
High KEV

CVE-2025-48543 · 2026-07-15 · pending_review

Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.

SonicWall SMA1000 Missing Authorization Vulnerability
High KEV

CVE-2025-40602 · 2026-07-14 · pending_review

SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.

Microsoft Windows SMB Client Improper Access Control Vulnerability
High KEV

CVE-2025-33073 · 2026-07-14 · pending_review

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to con…

Microsoft Windows External Control of File Name or Path Vulnerability
High KEV

CVE-2025-33053 · 2026-07-15 · pending_review

Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcu…

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
High KEV

CVE-2025-32756 · 2026-07-15 · pending_review

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

Apple Multiple Products Buffer Overflow Vulnerability
High 8.8 KEV

CVE-2025-31277 · 2026-07-15 · pending_review

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.

Next page →