ToolsCVE trackerATT&CKCIDRDNSEmail securityHeadersTrackersTLSMy connectionCSP builderEmail headersJWTCert decoderPassphrasePassword checkHash & encodesecurity.txtDNSSEC & CAA

d4 · tools · cve

CVE tracker.

Which vulnerabilities are actually being exploited? This tracks CISA's Known Exploited Vulnerabilities catalogue, enriches any CVE with severity (CVSS) and exploit probability (EPSS) on demand, and offers per-vendor RSS feeds plus optional email alerts - no account needed, no tracking of what you look up.

Latest known-exploited vulnerabilities

CVEVendor / productWhat it isAddedFix due
CVE-2026-20316Cisco
Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauth…2026-07-292026-08-01
CVE-2026-16812Arista
VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impa…2026-07-272026-07-30
CVE-2025-68686Fortinet
FortiOS
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patc…2026-07-272026-08-10
CVE-2026-50522Microsoft
SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.2026-07-222026-07-25
CVE-2026-16232Check Point
SmartConsole
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and u…2026-07-222026-07-25
CVE-2026-63030WordPress
Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerabili…2026-07-212026-07-24
CVE-2026-60137WordPress
Core
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-6303…2026-07-212026-08-04
CVE-2026-0770Langflow
Langflow
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installatio…2026-07-212026-07-24
CVE-2021-27137DD-WRT
DD-WRT
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code ex…2026-07-212026-07-24
CVE-2026-58644Microsoft
SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.2026-07-162026-07-19
CVE-2026-39808Fortinet
FortiSandbox
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTT…2026-07-162026-07-19
CVE-2026-25089Fortinet
FortiSandbox
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthor…2026-07-162026-07-19
CVE-2026-46817Oracle
E-Business Suite
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle …2026-07-152026-07-18
CVE-2023-4346KNX Association
KNX Protocol Connection Authorization Option 1
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purg…2026-07-152026-07-29
CVE-2026-56164Microsoft
SharePoint Server
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.2026-07-142026-07-17
CVE-2026-56155Microsoft
Active Directory Federation Services
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileg…2026-07-142026-07-28
CVE-2026-15410SonicWall
SMA1000 Appliances
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator…2026-07-142026-07-17
CVE-2026-15409SonicWall
SMA1000 Appliances
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to …2026-07-142026-07-17
CVE-2008-4128Cisco
IOS
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command …2026-07-132026-07-16
CVE-2026-56291Balbooa
Forms
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading o…2026-07-102026-07-13
CVE-2026-48939iCagenda
iCagenda
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately re…2026-07-102026-07-13
CVE-2026-56290Joomlack
Page Builder
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.2026-07-072026-07-10
CVE-2026-55255Langflow
Langflow
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user b…2026-07-072026-07-10
CVE-2026-48908JoomShaper
SP Page Builder
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimate…2026-07-072026-07-10
CVE-2026-48282Adobe
ColdFusion
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.2026-07-072026-07-10
CVE-2026-45659Microsoft
SharePoint Server
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.2026-07-012026-07-04
CVE-2026-48558SimpleHelp
SimpleHelp
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login…2026-06-292026-07-02
CVE-2026-20230Cisco
Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forge…2026-06-252026-06-28
CVE-2026-12569
ransomware
PTC
Windchill and FlexPLM
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a maliciou…2026-06-252026-06-28
CVE-2026-34910Ubiquiti
UniFi OS
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.2026-06-232026-06-26

Showing the 30 most recent of 1,656 catalogued vulnerabilities (synced 2026-08-01 01:50 UTC). "Fix due" is the deadline CISA sets for US federal agencies - a decent urgency yardstick for everyone else too.

Watch a vendor by RSS

New exploited CVEs for one vendor, straight into your feed reader - no account needed. Full feed covers everything.

Microsoft (382) Cisco (95) Apple (93) Adobe (80) Google (72) Oracle (45) Apache (39) Ivanti (35) Fortinet (29) D-Link (26) Linux (26) VMware (26) Citrix (22) Synacor (18) Android (17) SonicWall (17) Palo Alto Networks (15) Samsung (15) SAP (14) Atlassian (13) Mozilla (13) Qualcomm (12) Trend Micro (12) Zyxel (12)

Email alerts for new exploited CVEs

A short email when CISA catalogues something new, linking to the detail here. Double opt-in, unsubscribe in every alert, and nothing about your tracker use is ever logged. More about the alerts.

Sources: CISA Known Exploited Vulnerabilities catalogue (synced daily), the NVD (per-CVE detail, fetched on demand and cached) and FIRST EPSS (exploit probability, refreshed daily). This site stores no personal data about what you look up.