// THREAT RADAR

📡 The most dangerous CVEs right now

A self-updating ranking that combines three signals: whether it is actively exploited (CISA KEV), the exploit probability (EPSS) and the severity (CVSS). Not "the latest published", but what actually matters to prioritize.

On radar40
Exploited (KEV)40
Updated10 min ago
🎯 How it is ranked: score = EPSS + CVSS + KEV + recency. The KEV badge means active exploitation confirmed by CISA. Each CVE links to its NVD record and to the CVSS and patch prioritization tools.

📡 Subscribe via RSS · 🧩 Embed the “CVE of the day” on your site · 🌉 Turn a CVE into detection

Filter
#1
CVE-2026-8037 Critical 9.6 Exploited (KEV)
Progress LoadMaster
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endp…
99%EPSS
9.6CVSS
#2
CVE-2026-63030 Critical 9.8 Exploited (KEV)
WordPress Core
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Inje…
96%EPSS
9.8CVSS
#3
CVE-2026-48282 Critical 10.0 Exploited (KEV)
Adobe ColdFusion
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user.…
99%EPSS
10.0CVSS
#4
CVE-2026-10520 Critical 10.0 Exploited (KEV)
Ivanti Sentry
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
100%EPSS
10.0CVSS
#5
CVE-2026-39808 Critical 9.8 Exploited (KEV)
Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
91%EPSS
9.8CVSS
#6
CVE-2026-33824 Critical 9.8 Exploited (KEV)
Microsoft Internet Key Exchange (IKE) Service Extensions
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
78%EPSS
9.8CVSS
#7
CVE-2008-4250 Critical 9.8 Exploited (KEV)
n/a n/a
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overfl…
99%EPSS
9.8CVSS
#8
CVE-2026-20253 Critical 9.8 Exploited (KEV)
Splunk Enterprise
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL s…
97%EPSS
9.8CVSS
#9
CVE-2026-48908 Critical 10.0 Exploited (KEV)
JoomShaper SP Page Builder
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
88%EPSS
10.0CVSS
#10
CVE-2026-35273 Critical 9.8 Exploited (KEV) Ransomware
Oracle PeopleSoft Enterprise PeopleTools
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticate…
95%EPSS
9.8CVSS
#11
CVE-2026-41940 Critical 9.3 Exploited (KEV) Ransomware
WebPros cPanel & WHM and WP2 (WordPress Squared)
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
98%EPSS
9.3CVSS
#12
CVE-2026-39987 Critical 9.3 Exploited (KEV)
Marimo Marimo
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell a…
97%EPSS
9.3CVSS
#13
CVE-2026-20182 Critical 10.0 Exploited (KEV)
Cisco Catalyst SD-WAN
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection ha…
92%EPSS
10.0CVSS
#14
CVE-2026-48939 Critical 10.0 Exploited (KEV)
iCagenda iCagenda
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
83%EPSS
10.0CVSS
#15
CVE-2026-56290 Critical 10.0 Exploited (KEV)
Joomlack Page Builder
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
83%EPSS
10.0CVSS
#16
CVE-2026-34910 Critical 10.0 Exploited (KEV)
Ubiquiti UniFi OS
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
87%EPSS
10.0CVSS
#17
CVE-2026-50522 Critical 9.8 Exploited (KEV)
Microsoft Microsoft SharePoint Enterprise Server 2016
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
77%EPSS
9.8CVSS
#18
CVE-2026-9082 Critical 9.8 Exploited (KEV)
Drupal Core
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6…
88%EPSS
9.8CVSS
#19
CVE-2026-34908 Critical 10.0 Exploited (KEV)
Ubiquiti Inc UniFi OS Server
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
85%EPSS
10.0CVSS
#20
CVE-2026-31431 High 7.8 Exploited (KEV)
Linux Linux
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operati…
100%EPSS
7.8CVSS
#21
CVE-2026-42208 Critical 9.3 Exploited (KEV)
BerriAI LiteLLM
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text…
89%EPSS
9.3CVSS
#22
CVE-2024-7399 High 8.8 Exploited (KEV)
Samsung MagicINFO 9 Server
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
92%EPSS
8.8CVSS
#23
CVE-2010-0249 High 8.8 Exploited (KEV)
n/a n/a
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 all…
92%EPSS
8.8CVSS
#24
CVE-2026-56291 Critical 10.0 Exploited (KEV)
balbooa.com balbooa.com Balbooa Forms extension for Joomla
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads…
76%EPSS
10.0CVSS
#25
CVE-2026-15409 Critical 10.0 Exploited (KEV) Ransomware
SonicWall SMA1000
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
74%EPSS
10.0CVSS
#26
CVE-2026-34486 High 7.5 Exploited (KEV)
Apache Tomcat
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgr…
83%EPSS
7.5CVSS
#27
CVE-2026-25089 Critical 9.8 Exploited (KEV)
Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.…
74%EPSS
9.8CVSS
#28
CVE-2026-16232 Critical 9.3 Exploited (KEV)
Check Point SmartConsole
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful…
73%EPSS
9.3CVSS
#29
CVE-2025-34291 Critical 9.4 Exploited (KEV)
Langflow Langflow
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a re…
84%EPSS
9.4CVSS
#30
CVE-2026-0257 High 7.8 Exploited (KEV) Ransomware
Palo Alto Networks PAN-OS
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…
94%EPSS
7.8CVSS
#31
CVE-2009-3459 High 8.8 Exploited (KEV)
n/a n/a
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wil…
87%EPSS
8.8CVSS
#32
CVE-2026-50751 Critical 9.3 Exploited (KEV) Ransomware
Check Point Security Gateway
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a…
83%EPSS
9.3CVSS
#33
CVE-2024-1708 High 8.4 Exploited (KEV) Ransomware
ConnectWise ScreenConnect
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
88%EPSS
8.4CVSS
#34
CVE-2026-20230 High 8.6 Exploited (KEV)
Cisco Unified Communications Manager
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forger…
83%EPSS
8.6CVSS
#35
CVE-2026-42271 High 8.7 Exploited (KEV)
BerriAI LiteLLM
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp…
83%EPSS
8.7CVSS
#36
CVE-2010-0806 High 8.8 Exploited (KEV)
Microsoft Internet Explorer
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the dele…
82%EPSS
8.8CVSS
#37
CVE-2025-29635 High 7.2 Exploited (KEV)
n/a n/a
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, trigg…
90%EPSS
7.2CVSS
#38
CVE-2026-15410 High 7.2 Exploited (KEV) Ransomware
SonicWall SMA1000 Appliances
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated…
76%EPSS
7.2CVSS
#39
CVE-2026-42897 High 8.1 Exploited (KEV)
Microsoft Microsoft Exchange Server 2016 Cumulative Update 23
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
70%EPSS
8.1CVSS
#40
CVE-2026-60137 Medium 5.9 Exploited (KEV)
WordPress Core
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
73%EPSS
5.9CVSS

Sources: CISA KEV · EPSS · FIRST.org · CIRCL · NVD. Data is informational only; always verify against the vendor's official advisory.