Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-66384
Known exploited
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVSS Score
5.3
EPSS Score
0.006
Published
2026-08-12
CVE-2026-71362
Known exploited
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
CVSS Score
9.1
EPSS Score
0.023
Published
2026-08-11
CVE-2026-68820
Known exploited
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.062
Published
2026-08-11
CVE-2026-20349
Known exploited
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
CVSS Score
8.6
EPSS Score
0.022
Published
2026-08-11
CVE-2026-72898
Known exploited
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
CVSS Score
10.0
EPSS Score
0.942
Published
2026-08-10
CVE-2026-65400
Known exploited
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVSS Score
9.8
EPSS Score
0.105
Published
2026-08-06
CVE-2026-5430
Known exploited
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-08-06
CVE-2026-18577
Known exploited
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
CVSS Score
8.2
EPSS Score
0.541
Published
2026-08-02
CVE-2026-18556
Known exploited
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
CVSS Score
8.2
EPSS Score
0.402
Published
2026-08-01
CVE-2026-59310
Known exploited
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.497
Published
2026-07-30


Contact Us

Shodan ® - All rights reserved