{"page":2,"per_page":25,"total_vulns":1662,"total_pages":67,"vulnerabilities":[{"_id":"6a3acbf946811d58d37c602b","cveID":"CVE-2026-34909","dateAdded":"2026-06-23","dueDate":"2026-06-26","notes":"https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34909","product":"UniFi OS","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.","vendorProject":"Ubiquiti","vulnerabilityName":"Ubiquiti UniFi OS Path Traversal Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":10.0,"nvdReferences":[{"url":"https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b","source":"support@hackerone.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Deferred"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a3acbf946811d58d37c602a","cveID":"CVE-2026-34910","dateAdded":"2026-06-23","dueDate":"2026-06-26","notes":"https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34910","product":"UniFi OS","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.","vendorProject":"Ubiquiti","vulnerabilityName":"Ubiquiti UniFi OS Improper Input Validation Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":10.0,"nvdReferences":[{"url":"https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b","source":"support@hackerone.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Deferred"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a3acbf946811d58d37c6029","cveID":"CVE-2025-67038","dateAdded":"2026-06-23","dueDate":"2026-06-26","notes":"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-67038","product":"EDS5000","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.","vendorProject":"Lantronix","vulnerabilityName":"Lantronix EDS5000 Code Injection Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"http://eds5000.com","source":"cve@mitre.org","tags":["Broken Link"]},{"url":"http://lantronix.com","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/HORKimhab/CVE-2025-67038"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a342669bccd92e47fbc4ad4","cveID":"CVE-2026-20253","dateAdded":"2026-06-18","dueDate":"2026-06-21","notes":"https://advisory.splunk.com/advisories/SVD-2026-0603 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20253","product":"Enterprise","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.","vendorProject":"Splunk","vulnerabilityName":"Splunk Enterprise Missing Authentication for Critical Function Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-0603","source":"psirt@cisco.com","tags":["Vendor Advisory"]},{"url":"https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/HORKimhab/CVE-2026-20253","https://github.com/0xBlackash/CVE-2026-20253","https://github.com/pssec-io/CVE-2026-20253"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a31ad9a21f245bdfd235282","cveID":"CVE-2026-48907","dateAdded":"2026-06-16","dueDate":"2026-06-19","notes":"https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites ; https://www.joomlacontenteditor.net/support/changelog/editor ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48907","product":"Joomla Content Editor ","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. ","vendorProject":"Widget Factory","vulnerabilityName":"Widget Factory Joomla Content Editor Improper Access Control Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://www.joomlacontenteditor.net/","source":"security@joomla.org","tags":["Product"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48907","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]},{"url":"https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Release Notes","Vendor Advisory"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/0xBlackash/CVE-2026-48907","https://github.com/ywh-jfellus/CVE-2026-48907","https://github.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE","https://github.com/g0thamRabb1t/joomla-jce-cve-2026-48907-detection","https://github.com/wearehackers160/CVE-2026-48907","https://github.com/HORKimhab/CVE-2026-48907","https://github.com/grayxploit/CVE-2026-48907","https://github.com/gh1mau/masta-cve-2026-48907","https://github.com/NoXiVaR/CVE-2026-48907","https://github.com/pssec-io/CVE-2026-48907","https://github.com/K3ysTr0K3R/CVE-2026-48907","https://github.com/Almavj/Joomla_CVE_2026_48907","https://github.com/bayu06802/CVE-2026-48907","https://github.com/amnsecurity/CVE-2026-48907-Joomla-JCE-RCE"],"openThreatData":[{"adversaries":["WP-SHELLSTORM"],"malwareFamiles":["Snowlight","Vshell","Bestshell","Godzilla"],"affectedIndustries":["Retail","Finance","Technology"],"communityAdversaries":["ShinyHunters OAuth abuse, Jscrambler npm Packages, StealC, GigaWiper, GodDamn Ransomware","WP-SHELLSTORM"],"communityMalwareFamilies":["Snowlight","Vshell","Bestshell","Godzilla"],"communityAffectedIndustries":["Retail","Finance","Technology"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a305c19d27f18f4d25b3041","cveID":"CVE-2026-20262","dateAdded":"2026-06-15","dueDate":"2026-06-29","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20262","product":"Catalyst SD-WAN Manager","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.","vendorProject":"Cisco","vulnerabilityName":"Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"MEDIUM","exploitabilityScore":2.8,"baseScore":6.5,"nvdReferences":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ","source":"psirt@cisco.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20262","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/fevar54/CVE-2026-20262-Cisco-Catalyst-SD-WAN-Manager-Arbitrary-File-Write-","https://github.com/HORKimhab/CVE-2026-20262"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a305c19d27f18f4d25b3040","cveID":"CVE-2026-54420","dateAdded":"2026-06-15","dueDate":"2026-06-18","notes":"https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-54420","product":"cPanel Plugin","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.","vendorProject":"LiteSpeed","vulnerabilityName":"LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"HIGH","baseSeverity":"HIGH","exploitabilityScore":1.8,"baseScore":8.5,"nvdReferences":[{"url":"https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-54420","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/fevar54/CVE-2026-54420-LiteSpeed-Symlink-Exploit","https://github.com/HORKimhab/CVE-2026-54420"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2c4b793caedadb74536e3f","cveID":"CVE-2026-35273","dateAdded":"2026-06-12","dueDate":"2026-06-15","notes":"https://www.oracle.com/security-alerts/alert-cve-2026-35273.html ; https://support.oracle.com/signin/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-35273","product":" PeopleSoft Enterprise PeopleTools","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.","vendorProject":"Oracle","vulnerabilityName":"Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://www.oracle.com/security-alerts/alert-cve-2026-35273.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory","US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/0xBlackash/CVE-2026-35273","https://github.com/HORKimhab/CVE-2026-35273"],"openThreatData":[{"adversaries":["UNC6240"],"malwareFamiles":["Meshcentral"],"affectedIndustries":["Education"],"communityAdversaries":["Kudelski","UNC6240","Cloud Atlas"],"communityMalwareFamilies":["Meshcentral"],"communityAffectedIndustries":["Government","Education","Diplomatic"]}],"knownRansomwareCampaignUse":"Known"},{"_id":"6a2b16194f292e2c29753df4","cveID":"CVE-2026-10520","dateAdded":"2026-06-11","dueDate":"2026-06-14","notes":"https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-10520","product":"Sentry","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","shortDescription":"Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.","vendorProject":"Ivanti","vulnerabilityName":"Ivanti Sentry OS Command Injection Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":10.0,"nvdReferences":[{"url":"https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US","source":"3c1d8aa1-5a33-4ea4-8992-aadd6440af75","tags":["Patch","Vendor Advisory"]},{"url":"https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/0xBlackash/CVE-2026-10520","https://github.com/HORKimhab/CVE-2026-10520-10523","https://github.com/ogenich/CVE-2026-10520","https://github.com/error-inside/CVE-2026-10520"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2865098d4af7de1adfbdaf","cveID":"CVE-2026-20245","dateAdded":"2026-06-09","dueDate":"2026-06-23","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx ; https://nvd.nist.gov/vuln/detail/CVE-2026-20245","product":"Catalyst SD-WAN Manager","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.","vendorProject":"Cisco","vulnerabilityName":"Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability","nvdData":[{"attackVector":"LOCAL","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":1.8,"baseScore":7.8,"nvdReferences":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx","source":"psirt@cisco.com","tags":["Vendor Advisory"]},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW","source":"psirt@cisco.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20245","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/HORKimhab/CVE-2026-20245","https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit","https://github.com/0xBlackash/CVE-2026-20245","https://github.com/0xBlackash/CVE-2026-20245"],"openThreatData":[{"adversaries":["Turla"],"malwareFamiles":["Stockstay.marketmaker","Wildday","Stockstay.stockmarket","Kazuar - s0265","Stockstay.stocktrader","Stockstay.stockbroker","Diamondback","Stockstay"],"affectedIndustries":["Defense","Government"],"communityAdversaries":["Doppelganger","Turla"],"communityMalwareFamilies":["Stockstay.marketmaker","Wildday","Stockstay.stockmarket","Csv","Kazuar - s0265","Stockstay.stocktrader","Stockstay.stockbroker","Diamondback","Stockstay"],"communityAffectedIndustries":["Critical infrastructure","Healthcare","Government","Technology","Defense","Banks","Retail","Transportation"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2856f976dc289c7ef888a3","cveID":"CVE-2026-7473","dateAdded":"2026-06-09","dueDate":"2026-06-23","notes":"https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 ; https://nvd.nist.gov/vuln/detail/CVE-2026-7473","product":"Extensible Operating System","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.","vendorProject":"Arista","vulnerabilityName":"Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"MEDIUM","exploitabilityScore":3.9,"baseScore":5.8,"nvdReferences":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137","source":"psirt@arista.com","tags":["Broken Link"]},{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Vendor Advisory","Mitigation"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/fevar54/CVE-2026-7473---Arista-EOS-Tunnel-Decapsulation-Bypass"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2856f976dc289c7ef888a2","cveID":"CVE-2026-11645","dateAdded":"2026-06-09","dueDate":"2026-06-23","notes":"https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html ; https://issues.chromium.org/issues/506689381 ; https://nvd.nist.gov/vuln/detail/CVE-2026-11645","product":"Chromium V8","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.","vendorProject":"Google","vulnerabilityName":"Google Chromium V8 Out-of-Bounds Read and Write Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":2.8,"baseScore":8.8,"nvdReferences":[{"url":"https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html","source":"chrome-cve-admin@google.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/506689381","source":"chrome-cve-admin@google.com","tags":["Permissions Required"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/0xBlackash/CVE-2026-11645","https://github.com/fevar54/CVE-2026-11645-Out-of-bounds-Read-Write"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":["Skia"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2721992f2d8f20965e7b29","cveID":"CVE-2026-50751","dateAdded":"2026-06-08","dueDate":"2026-06-11","notes":"https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751","product":"Security Gateway","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.","vendorProject":"Check Point","vulnerabilityName":"Check Point Security Gateway Improper Authentication Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.3,"nvdReferences":[{"url":"https://support.checkpoint.com/results/sk/sk185033","source":"cve@checkpoint.com","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/0xBlackash/CVE-2026-50751","https://github.com/WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts","https://github.com/fernstedt/CVE-2026-50751","https://github.com/fevar54/CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit","https://github.com/hlkysipv/CVE-2026-50751-Check-Point-IKEv1-Authentication-Bypass","https://github.com/WadesWeaponShed/CheckPoint-CVE-Webscanner","https://github.com/bolubey/CVE-2026-50751"],"openThreatData":[{"adversaries":["Qilin"],"malwareFamiles":["Qilin"],"affectedIndustries":[],"communityAdversaries":["Qilin","Multi-Stage LNK Malware, Splinter, MLTBackdoor, Malspam delivering .NET loader, BackDoor.Farfli.130","Kudelski"],"communityMalwareFamilies":["Qilin","Qilin linux"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2705795607c48bfee43fe4","cveID":"CVE-2026-42271","dateAdded":"2026-06-08","dueDate":"2026-06-22","notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g ; https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable ; https://nvd.nist.gov/vuln/detail/CVE-2026-42271","product":"LiteLLM","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.","vendorProject":"BerriAI","vulnerabilityName":"BerriAI LiteLLM Command Injection Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":2.8,"baseScore":8.8,"nvdReferences":[{"url":"https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g","source":"security-advisories@github.com","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42271","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/learner202649/CVE-2026-42271-PoC","https://github.com/HORKimhab/CVE-2026-42271","https://github.com/amnsecurity/CVE-2026-42271-LiteLLM-RCE"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a2310f9545c1c62df328a13","cveID":"CVE-2026-28318","dateAdded":"2026-06-05","dueDate":"2026-06-19","notes":"https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318 ; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm#link7 ; https://nvd.nist.gov/vuln/detail/CVE-2026-28318","product":"Serv-U","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.","vendorProject":"SolarWinds","vulnerabilityName":"SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":3.9,"baseScore":7.5,"nvdReferences":[{"url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm","source":"psirt@solarwinds.com","tags":["Release Notes"]},{"url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318","source":"psirt@solarwinds.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/BishopFox/CVE-2026-28318-check","https://github.com/EaEa0001/servu-cve-2026-28318-poc"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a205fe9d8bbd87f9a9b8409","cveID":"CVE-2026-45247","dateAdded":"2026-06-03","dueDate":"2026-06-06","notes":"https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247","product":"Mirasvit Full Page Cache Warmer","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.","vendorProject":"Mirasvit","vulnerabilityName":"Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer","source":"disclosure@vulncheck.com"},{"url":"https://sansec.io/research/mirasvit-cache-warmer-object-injection","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection","source":"disclosure@vulncheck.com"}],"vulnStatus":"Deferred"}],"githubPocs":["https://github.com/HORKimhab/CVE-2026-45247","https://github.com/fevar54/PoC-Funcional---CVE-2026-45247-Mirasvit-Full-Page-Cache-Warmer-RCE-"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a0deae9d5f9c3f2c2b822c3","cveID":"CVE-2010-0249","dateAdded":"2026-06-03","dueDate":"2026-06-03","notes":"https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2010/979352 ; https://nvd.nist.gov/vuln/detail/CVE-2010-0249","product":"Internet Explorer","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.","vendorProject":"Microsoft","vulnerabilityName":"Microsoft Internet Explorer Use-After-Free Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":2.8,"baseScore":8.8,"nvdReferences":[{"url":"http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx","source":"secure@microsoft.com","tags":["Broken Link","Vendor Advisory"]},{"url":"http://news.cnet.com/8301-27080_3-10435232-245.html","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"http://osvdb.org/61697","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"http://securitytracker.com/id?1023462","source":"secure@microsoft.com","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://support.microsoft.com/kb/979352","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.exploit-db.com/exploits/11167","source":"secure@microsoft.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.kb.cert.org/vuls/id/492515","source":"secure@microsoft.com","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.microsoft.com/technet/security/advisory/979352.mspx","source":"secure@microsoft.com","tags":["Broken Link","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/37815","source":"secure@microsoft.com","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-055A.html","source":"secure@microsoft.com","tags":["Broken Link","Third Party Advisory","US Government Resource"]},{"url":"http://www.vupen.com/english/advisories/2010/0135","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55642","source":"secure@microsoft.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6835","source":"secure@microsoft.com","tags":["Broken Link"]},{"url":"http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"]},{"url":"http://news.cnet.com/8301-27080_3-10435232-245.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://osvdb.org/61697","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://securitytracker.com/id?1023462","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://support.microsoft.com/kb/979352","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://www.exploit-db.com/exploits/11167","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.kb.cert.org/vuls/id/492515","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.microsoft.com/technet/security/advisory/979352.mspx","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/37815","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-055A.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","US Government Resource"]},{"url":"http://www.vupen.com/english/advisories/2010/0135","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55642","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6835","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}],"vulnStatus":"Modified"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[""]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a1f1c79f9abb3a8f4cd68ba","cveID":"CVE-2025-48595","dateAdded":"2026-06-02","dueDate":"2026-06-05","notes":"https://source.android.com/docs/security/bulletin/2026/2026-06-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48595","product":"Framework","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.","vendorProject":"Android","vulnerabilityName":"Android Framework Integer Overflow Vulnerability","nvdData":[{"attackVector":"LOCAL","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":2.5,"baseScore":8.4,"nvdReferences":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-06-01","source":"security@android.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48595","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/HORKimhab/CVE-2025-48595","https://github.com/fevar54/CVE-2025-48595-Android-Framework-Integer-Overflow-"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a1f1c79f9abb3a8f4cd68b9","cveID":"CVE-2022-0492","dateAdded":"2026-06-02","dueDate":"2026-06-05","notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af ; https://www.kernel.org/ ; https://nvd.nist.gov/vuln/detail/CVE-2022-0492","product":"Kernel","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.","vendorProject":"Linux","vulnerabilityName":"Linux Kernel Improper Authentication Vulnerability","nvdData":[{"attackVector":"LOCAL","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":1.8,"baseScore":7.8,"nvdReferences":[{"url":"http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2051505","source":"secalert@redhat.com","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af","source":"secalert@redhat.com","tags":["Patch","Vendor Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20220419-0002/","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2022/dsa-5095","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2022/dsa-5096","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://packetstormsecurity.com/files/176099/Docker-cgroups-Container-Escape.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2051505","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=24f6008564183aa120d07c03d9289519c2fe02af","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20220419-0002/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2022/dsa-5095","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2022/dsa-5096","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/smallcat9612/CVE-2022-0492-Docker-Breakout-Checker-and-PoC","https://github.com/Perimora/cve_2022_0492","https://github.com/T1erno/CVE-2022-0492-Docker-Breakout-Checker-and-PoC","https://github.com/yoeelingBin/CVE-2022-0492-Container-Escape","https://github.com/chenaotian/CVE-2022-0492","https://github.com/SofianeHamlaoui/CVE-2022-0492-Checker","https://github.com/PaloAltoNetworks/can-ctr-escape-cve-2022-0492"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["Vulnerability Advisory"],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a1dcaf9ead6d3281cc6c696","cveID":"CVE-2024-21182","dateAdded":"2026-06-01","dueDate":"2026-06-04","notes":"https://www.oracle.com/security-alerts/cpujul2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-21182","product":"WebLogic Server","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.","vendorProject":"Oracle","vulnerabilityName":"Oracle WebLogic Server Unspecified Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"HIGH","exploitabilityScore":3.9,"baseScore":7.5,"nvdReferences":[{"url":"https://www.oracle.com/security-alerts/cpujul2024.html","source":"secalert_us@oracle.com","tags":["Vendor Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujul2024.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21182","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/kursadalsan/CVE-2024-21182","https://github.com/k4it0k1d/CVE-2024-21182"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":["Hyperion"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a19f299f29233df07f702b9","cveID":"CVE-2026-0257","dateAdded":"2026-05-29","dueDate":"2026-06-01","notes":"https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257","product":"PAN-OS","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.","vendorProject":"Palo Alto Networks","vulnerabilityName":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.1,"nvdReferences":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0257","source":"psirt@paloaltonetworks.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"vulnStatus":"Modified"}],"githubPocs":["https://github.com/sfewer-r7/CVE-2026-0257","https://github.com/bolubey/CVE-2026-0257","https://github.com/Mr-Robot-LP/CVE-2026-0257","https://github.com/0xBlackash/CVE-2026-0257","https://github.com/HORKimhab/CVE-2026-0257","https://github.com/tushargurav28/CVE-2026-0257","https://github.com/grayxploit/CVE-2026-0257","https://github.com/Ez4rd1x1/CVE-2026-0257","https://github.com/amnsecurity/CVE-2026-0257-GlobalProtect-Bypass"],"openThreatData":[{"adversaries":[],"malwareFamiles":["Cyberstrike harvester","Ekz infostealer"],"affectedIndustries":["Defense","Government","Energy","Manufacturing","Retail","Education","Finance","Healthcare","Technology","Hospitality","Telecommunications","Transportation"],"communityAdversaries":["Multi-Stage LNK Malware, Splinter, MLTBackdoor, Malspam delivering .NET loader, BackDoor.Farfli.130","Cloud Atlas"],"communityMalwareFamilies":["Cyberstrike harvester","Ekz infostealer"],"communityAffectedIndustries":["Defense","Government","Energy","Manufacturing","Retail","Education","Diplomatic","Finance","Healthcare","Technology","Hospitality","Telecommunications","Transportation"]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a1733792ec8f49f68e82d78","cveID":"CVE-2026-8398","dateAdded":"2026-05-27","dueDate":"2026-05-30","notes":"https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398","product":"Daemon Tools Lite","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.","vendorProject":"Daemon","vulnerabilityName":"Daemon Tools Lite Embedded Malicious Code Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://blog.daemon-tools.cc/post/security-incident","source":"vulnerability@kaspersky.com","tags":["Vendor Advisory"]},{"url":"https://securelist.com/tr/daemon-tools-backdoor/119654/","source":"vulnerability@kaspersky.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8398","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a1733792ec8f49f68e82d77","cveID":"CVE-2026-45321","dateAdded":"2026-05-27","dueDate":"2026-06-10","notes":"This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321","product":"TanStack","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.","vendorProject":"TanStack","vulnerabilityName":"TanStack Unspecified Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":2.8,"baseScore":9.6,"nvdReferences":[{"url":"https://github.com/TanStack/router/issues/7383","source":"security-advisories@github.com","tags":["Issue Tracking"]},{"url":"https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://tanstack.com/blog/npm-supply-chain-compromise-postmortem","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem","source":"security-advisories@github.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45321","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/prashanthnataraj/mini-shai-hulud-detector","https://github.com/nkopylov/tanscript-exploit-check","https://github.com/digi4care/shai-scan","https://github.com/fabriziosalmi/tanstack-compromise-checker","https://github.com/Intrudify/mini-shai-hulud-scanner","https://github.com/shayr1/shai-hulud-scan","https://github.com/qi-scape/scan-shai-hulud","https://github.com/Caixa-git/tanstack-shield","https://github.com/Yomisana/are-you-get-tanstack-attack","https://github.com/ry-allan/tanstack-compromise-checker"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":["TeamPCP"],"communityMalwareFamilies":["Kics","Teampcp","Cyber criminal"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a1733792ec8f49f68e82d76","cveID":"CVE-2026-48027","dateAdded":"2026-05-27","dueDate":"2026-06-10","notes":"This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027","product":"Nx Console","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.","vendorProject":"Nx","vulnerabilityName":"Nx Console Embedded Malicious Code Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://github.com/nrwl/nx-console/issues/3139","source":"security-advisories@github.com","tags":["Issue Tracking"]},{"url":"https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised","source":"security-advisories@github.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":[],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":["Kics","Cyber criminal","Teampcp"],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"},{"_id":"6a15e1fa8c482ba31689464e","cveID":"CVE-2026-48172","dateAdded":"2026-05-26","dueDate":"2026-05-29","notes":"https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-48172","product":"cPanel Plugin","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.","vendorProject":"LiteSpeed","vulnerabilityName":"LiteSpeed cPanel Plugin Privilege Escalation Vulnerability","nvdData":[{"attackVector":"NETWORK","attackComplexity":"LOW","baseSeverity":"CRITICAL","exploitabilityScore":3.9,"baseScore":9.8,"nvdReferences":[{"url":"https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/release-log","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48172","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}],"vulnStatus":"Analyzed"}],"githubPocs":["https://github.com/retmakarunia/CVE-2026-48172","https://github.com/HORKimhab/CVE-2026-48172","https://github.com/fevar54/CVE-2026-48172---LiteSpeed-cPanel-Plugin-Version-Auditor"],"openThreatData":[{"adversaries":[],"malwareFamiles":[],"affectedIndustries":[],"communityAdversaries":[],"communityMalwareFamilies":[],"communityAffectedIndustries":[]}],"knownRansomwareCampaignUse":"Unknown"}]}