Exploited CVEs

Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.

CVE-2026-73570

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

CVE
CVE-2026-84782

DTLS Retransmits Handshake Messages From a Stale Buffer Offset

CVE
CVE-2026-42608

Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.

CVE
CVE-2026-71362

Adobe Commerce | Incorrect Authorization (CWE-863)

CVE
CVE-2025-68461

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

CVE
CVE-2020-35730

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

CVE
CVE-2020-12641

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVE
CVE-2021-44026

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

CVE
CVE-2026-48842

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CVE
CVE-2023-5631

Stored XSS vulnerability in Roundcube

CVE
CVE-2026-80521

af_unix: Unlink scc_entry in unix_del_edge().

CVE
CVE-2026-90898

Bifrost unauthenticated remote code execution via MCP stdio client registration

CVE
CVE-2026-86242

Unauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked Builds

CVE
CVE-2026-55245

Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

CVE
CVE-2026-89775

KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation

CVE
CVE-2026-32882

libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride

CVE
CVE-2025-39682

tls: fix handling of zero-length records on the rx_list

CVE
CVE-2026-53266

netfilter: bridge: make ebt_snat ARP rewrite writable

CVE
CVE-2025-39964

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

CVE
CVE-2026-45321

Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

CVE
CVE-2026-58138

Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators

CVE
CVE-2026-68121

pppoe: reload header pointer after dev_hard_header()

CVE
CVE-2026-74469

sctp: prevent peer transport count overflow

CVE
CVE-2026-80844

xfrm: ah6: validate routing header segments_left

CVE
CVE-2026-81000

net: tun: bound receive headroom

CVE
CVE-2025-24799

GLPI allows unauthenticated SQL injection through the inventory endpoint

CVE
CVE-2026-77179

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback

CVE
CVE-2026-79994

Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race

CVE
CVE-2026-0628

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVE
CVE-2021-38003

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE
Next →