|
High
|
16 Feb 2026 |
16 Feb 2026 |
CPAI-2025-12173
|
|
CVE-2025-55346
|
Flowise Remote Code Execution (CVE-2025-55346)
|
|
High
|
16 Feb 2026 |
16 Feb 2026 |
CPAI-2025-12172
|
|
CVE-2025-8723
|
WordPress Cloudflare Image Resizing Plugin Remote Code Execution (CVE-2025-8723)
|
|
High
|
16 Feb 2026 |
16 Feb 2026 |
CPAI-2024-5410
|
|
CVE-2024-47066
|
LobeHub Lobe Chat Server-Side Request Forgery (CVE-2024-47066)
|
|
High
|
16 Feb 2026 |
16 Feb 2026 |
CPAI-2025-12204
|
|
CVE-2025-48148
|
StoreKeeper for WooCommerce Unrestricted File Upload (CVE-2025-48148)
|
|
Critical
|
12 Feb 2026 |
16 Feb 2026 |
CPAI-2026-0850
|
|
CVE-2026-1731
|
BeyondTrust Multiple Products Command Injection (CVE-2026-1731)
|
|
Critical
|
1 Feb 2026 |
16 Feb 2026 |
CPAI-2026-0845
|
|
CVE-2026-1281 CVE-2026-1340
|
Ivanti Endpoint Manager Mobile Command Injection (CVE-2026-1281; CVE-2026-1340)
|
|
Critical
|
29 Jan 2026 |
15 Feb 2026 |
CPAI-2025-12238
|
|
CVE-2025-40536 CVE-2025-40554
|
SolarWinds Web Help Desk Authentication Bypass (CVE-2025-40536; CVE-2025-40554)
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2026-0839
|
|
CVE-2026-1603
|
Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2024-5460
|
|
CVE-2024-39924
|
Dani-Garcia Vaultwarden Privilege Escalation (CVE-2024-39924)
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2026-0834
|
|
|
Lazarus Campaign Command and Control
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2026-0832
|
|
|
Formbook Campaign Command and Control
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2026-0836
|
|
|
Belkin Wemo Cross-Site Scripting
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2024-5456
|
|
CVE-2024-43441
|
Apache HugeGraph Authentication Bypass (CVE-2024-43441)
|
|
Medium
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2025-12152
|
|
CVE-2025-34176
|
pfSense CE Directory Traversal (CVE-2025-34176)
|
|
High
|
15 Feb 2026 |
15 Feb 2026 |
CPAI-2025-12037
|
|
CVE-2025-15029
|
Centreon Awie SQL Injection (CVE-2025-15029)
|
|
Critical
|
12 Feb 2026 |
12 Feb 2026 |
CPAI-2026-0801
|
|
CVE-2026-1731
|
BeyondTrust Multiple Products Command Injection (CVE-2026-1731)
|
|
High
|
12 Feb 2026 |
12 Feb 2026 |
CPAI-2025-12211
|
|
CVE-2025-67736
|
Sangoma FreePBX SQL Injection (CVE-2025-67736)
|
|
High
|
12 Feb 2026 |
12 Feb 2026 |
CPAI-2020-4613
|
|
CVE-2020-36911
|
Covenant Remote Code Execution (CVE-2020-36911)
|
|
High
|
12 Feb 2026 |
12 Feb 2026 |
CPAI-2025-11956
|
|
CVE-2025-62507
|
Redis Stack Overflow (CVE-2025-62507)
|
|
High
|
8 Jan 2026 |
12 Feb 2026 |
CPAI-2025-12201
|
|
CVE-2025-14174
|
Google Chrome Out Of Bounds Read (CVE-2025-14174)
|
|
Critical
|
1 Feb 2026 |
11 Feb 2026 |
CPAI-2026-0737
|
|
CVE-2026-1281 CVE-2026-1340
|
Ivanti Endpoint Manager Mobile Command Injection (CVE-2026-1281; CVE-2026-1340)
|
|
High
|
11 Feb 2026 |
11 Feb 2026 |
CPAI-2022-3124
|
|
CVE-2022-21820
|
NVIDIA Data Center GPU Manager Memory Corruption (CVE-2022-21820)
|
|
High
|
11 Feb 2026 |
11 Feb 2026 |
CPAI-2024-5419
|
|
CVE-2024-0088
|
NVIDIA Triton Inference Server Out-of-Bounds Write (CVE-2024-0088)
|
|
High
|
11 Feb 2026 |
11 Feb 2026 |
CPAI-2024-5418
|
|
CVE-2024-0087
|
NVIDIA Triton Inference Server Arbitrary File Write (CVE-2024-0087)
|
|
High
|
11 Feb 2026 |
11 Feb 2026 |
CPAI-2026-0754
|
|
CVE-2026-25137
|
NixOS Odoo Information Disclosure (CVE-2026-25137)
|
|
High
|
10 Feb 2026 |
11 Feb 2026 |
CPAI-2026-0752
|
Microsoft CVE-2026-21533
|
CVE-2026-21533
|
Microsoft Windows Remote Desktop Services Elevation of Privilege (CVE-2026-21533)
|
|
High
|
10 Feb 2026 |
11 Feb 2026 |
CPAI-2026-0750
|
Microsoft CVE-2026-21519
|
CVE-2026-21519
|
Microsoft Desktop Windows Manager Elevation of Privilege (CVE-2026-21519)
|
|
Medium
|
10 Feb 2026 |
11 Feb 2026 |
CPAI-2026-0751
|
Microsoft CVE-2026-21525
|
CVE-2026-21525
|
Microsoft Windows Remote Access Connection Manager Denial of Service (CVE-2026-21525)
|
|
Critical
|
14 Jan 2026 |
11 Feb 2026 |
CPAI-2025-12145
|
|
CVE-2020-12125 CVE-2024-10194 CVE-2025-5408
|
Wavlink Multiple Products Buffer Overflow (CVE-2020-12125; CVE-2024-10194; CVE-2025-5408)
|
|
Critical
|
5 Jan 2026 |
11 Feb 2026 |
CPAI-2025-12109
|
|
CVE-2024-0536 CVE-2024-0537 CVE-2024-0538 CVE-2024-0539 CVE-2024-0540 CVE-2024-0542 CVE-2024-2980 CVE-2024-2981 CVE-2024-30587 CVE-2024-4240 CVE-2024-4241 CVE-2024-4242 CVE-2024-4243 CVE-2025-7529
|
Embedded Devices Web Servers Buffer Overflow (CVE-2024-0536; CVE-2024-0537; CVE-2024-0538; CVE-2024-0539; CVE-2024-0540; CVE-2024-0542; CVE-2024-2980; CVE-2024-2981; CVE-2024-30587; CVE-2024-4240; CVE-2024-4241; CVE-2024-4242; CVE-2024-4243; CVE-2025-7529)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2026-0725
|
Microsoft CVE-2026-21533
|
CVE-2026-21533
|
Microsoft Windows Remote Desktop Services Elevation of Privilege (CVE-2026-21533)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2026-0706
|
Microsoft CVE-2026-21519
|
CVE-2026-21519
|
Microsoft Desktop Windows Manager Elevation of Privilege (CVE-2026-21519)
|
|
Medium
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2026-0697
|
Microsoft CVE-2026-21525
|
CVE-2026-21525
|
Microsoft Windows Remote Access Connection Manager Denial of Service (CVE-2026-21525)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2026-0583
|
Microsoft CVE-2026-21238
|
CVE-2026-21238
|
Microsoft Windows Ancillary Function Driver for WinSock Elevation of Privilege (CVE-2026-21238)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2026-0582
|
Microsoft CVE-2026-21241
|
CVE-2026-21241
|
Microsoft Windows Ancillary Function Driver for WinSock Elevation of Privilege (CVE-2026-21241)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2026-0713
|
Microsoft CVE-2026-21231
|
CVE-2026-21231
|
Microsoft Windows Kernel Elevation of Privilege (CVE-2026-21231)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2025-12058
|
|
CVE-2025-57833
|
Django SQL Injection (CVE-2025-57833)
|
|
High
|
10 Feb 2026 |
10 Feb 2026 |
CPAI-2025-12050
|
|
CVE-2025-34441 CVE-2025-34442
|
WWBN AVideo Information Disclosure (CVE-2025-34441; CVE-2025-34442)
|
|
High
|
9 Feb 2026 |
9 Feb 2026 |
CPAI-2025-12015
|
|
CVE-2025-63459 CVE-2025-63460 CVE-2025-63461
|
TOTOLINK A7000R Buffer Overflow (CVE-2025-63459; CVE-2025-63460; CVE-2025-63461)
|
|
High
|
9 Feb 2026 |
9 Feb 2026 |
CPAI-2025-11883
|
|
CVE-2025-43400
|
Apple Multiple Products Out Of Bounds Write (CVE-2025-43400)
|
|
Critical
|
9 Feb 2026 |
9 Feb 2026 |
CPAI-2025-12013
|
|
CVE-2025-4453 CVE-2025-4454
|
D-Link DIR-619L Command Injection (CVE-2025-4453; CVE-2025-4454)
|
|
High
|
19 Jan 2026 |
9 Feb 2026 |
CPAI-2026-0710
|
|
CVE-2026-23550
|
WordPress Modular DS Plugin Privilege Escalation (CVE-2026-23550)
|
|
Critical
|
1 Feb 2026 |
8 Feb 2026 |
CPAI-2026-0637
|
|
CVE-2026-1281 CVE-2026-1340
|
Ivanti Endpoint Manager Mobile Command Injection (CVE-2026-1281; CVE-2026-1340)
|
|
Critical
|
29 Jan 2026 |
8 Feb 2026 |
CPAI-2025-11651
|
|
CVE-2025-40536 CVE-2025-40554
|
SolarWinds Web Help Desk Authentication Bypass (CVE-2025-40536; CVE-2025-40554)
|
|
Critical
|
8 Feb 2026 |
8 Feb 2026 |
CPAI-2025-11986
|
|
CVE-2024-0297 CVE-2025-55893 CVE-2025-7154
|
TOTOLINK N200RE Command Injection (CVE-2024-0297; CVE-2025-55893; CVE-2025-7154)
|
|
Critical
|
8 Feb 2026 |
8 Feb 2026 |
CPAI-2025-11983
|
|
CVE-2024-0579 CVE-2025-5504 CVE-2025-5515
|
TOTOLINK X2000R Command Injection (CVE-2024-0579; CVE-2025-5504; CVE-2025-5515)
|
|
High
|
8 Feb 2026 |
8 Feb 2026 |
CPAI-2026-0681
|
|
CVE-2026-1056
|
WordPress Snow Monkey Forms Plugin Arbitrary File Deletion (CVE-2026-1056)
|
|
High
|
8 Feb 2026 |
8 Feb 2026 |
CPAI-2020-4588
|
|
CVE-2020-36962
|
Tendenci Command Injection (CVE-2020-36962)
|
|
High
|
8 Feb 2026 |
8 Feb 2026 |
CPAI-2024-5330
|
|
CVE-2024-12284
|
Citrix NetScaler Console Privilege Escalation (CVE-2024-12284)
|
|
High
|
8 Feb 2026 |
8 Feb 2026 |
CPAI-2025-11714
|
|
CVE-2025-59501
|
Microsoft Configuration Manager Authentication Bypass (CVE-2025-59501)
|