Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-45659
Known exploited
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVSS Score
8.8
EPSS Score
0.761
Published
2026-05-22
CVE-2026-34908
Known exploited
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
CVSS Score
10.0
EPSS Score
0.852
Published
2026-05-22
CVE-2026-34909
Known exploited
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
CVSS Score
10.0
EPSS Score
0.65
Published
2026-05-22
CVE-2026-34910
Known exploited
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
CVSS Score
10.0
EPSS Score
0.875
Published
2026-05-22
CVE-2026-34926
Known exploited
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
CVSS Score
6.7
EPSS Score
0.127
Published
2026-05-21
CVE-2026-48172
Known exploited
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend you examine the IP addresses in the list, determine if they are valid IP addresses, and if not, block them. To determine damage done, examine the system logs for use by the detected IP addresses. The issue is related to mishandling of Redis enable/disable features. The recommended minimum version is 2.4.7.
CVSS Score
10.0
EPSS Score
0.189
Published
2026-05-21
CVE-2026-9082
Known exploited
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
CVSS Score
9.8
EPSS Score
0.9
Published
2026-05-20
CVE-2026-45498
Known exploited
Microsoft Defender Denial of Service Vulnerability
CVSS Score
4.0
EPSS Score
0.631
Published
2026-05-20
CVE-2026-41091
Known exploited
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.082
Published
2026-05-20
CVE-2026-8398
Known exploited
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
CVSS Score
9.3
EPSS Score
0.015
Published
2026-05-15


Contact Us

Shodan ® - All rights reserved