CVE List – Find High-Risk & Exploited Vulnerabilities

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Assigner (CNA / source):[email protected] Remove this filter

Showing 120 of 746 results
«« First « Prev Page 1 / 38 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2026-41031 A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials. 9.3 0.04% 2026-06-09 2026-06-09
CVE-2026-35075 An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. 9.3 0.08% 2026-06-03 2026-06-08
CVE-2026-35076 The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. 7.2 0.10% 2026-06-03 2026-06-08
CVE-2026-35077 The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. 7.2 0.10% 2026-06-03 2026-06-08
CVE-2026-35078 The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. 7.2 0.10% 2026-06-03 2026-06-08
CVE-2026-35079 The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. 7.2 0.10% 2026-06-03 2026-06-08
CVE-2026-35080 The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. 7.2 0.10% 2026-06-03 2026-06-08
CVE-2026-35081 The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input. 7.2 0.10% 2026-06-03 2026-06-08
CVE-2026-35082 The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input. 8.7 0.15% 2026-06-03 2026-06-08
CVE-2026-35083 A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. 8.7 0.10% 2026-06-03 2026-06-08
CVE-2026-35084 A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root. 8.7 0.10% 2026-06-03 2026-06-08
CVE-2026-35085 A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root. 8.7 0.10% 2026-06-03 2026-06-08
CVE-2024-56123 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A 2026-06-08 2026-06-08
CVE-2024-56122 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A 2026-06-08 2026-06-08
CVE-2024-56121 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A 2026-06-08 2026-06-08
CVE-2024-56120 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. N/A N/A 2026-06-08 2026-06-08
CVE-2026-41032 It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information. 7.5 0.03% 2026-06-03 2026-06-04
CVE-2026-0393 The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session. 6.9 0.04% 2026-05-21 2026-06-01
CVE-2026-44468 The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components. 8.5 0.01% 2026-05-26 2026-05-28
CVE-2026-44469 The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation. 8.5 0.01% 2026-05-26 2026-05-28
«« First « Prev Page 1 / 38 Next »
cvelogic Threat Intelligence