// CVE TrackerSHOWING 23 OF 23
17CRITICAL
6HIGH
0MEDIUM
0LOW
11KEV LISTED
1NO PATCH
| CVE ID | VULNERABILITY | VENDOR | CVSS | SEVERITY | PATCH | EXPLOIT | PUBLISHED | |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48172 | LiteSpeed cPanel Plugin Root Privilege Escalation | LiteSpeed Technologies | 10 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-05-21 | ▶ |
| CVE-2026-20182KEV | Cisco Catalyst SD-WAN Controller Authentication Bypass (Zero-Day) | Cisco | 10 | ■ CRITICAL | AVAILABLE | LIMITED | 2026-05-14 | ▶ |
| CVE-2026-42826 | Azure DevOps Unauthenticated Information Disclosure | Microsoft | 10 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-07 | ▶ |
| CVE-2026-42898 | Microsoft Dynamics 365 On-Premises Authenticated Code Injection RCE (Scope Change) | Microsoft | 9.9 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-12 | ▶ |
| CVE-2026-9082KEV | Drupal Core PostgreSQL Unauthenticated SQL Injection | Drupal | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-05-20 | ▶ |
| CVE-2026-41089 | Windows Netlogon Stack-Based Buffer Overflow Unauthenticated RCE (Domain Controller) | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-12 | ▶ |
| CVE-2026-41096 | Windows DNS Client Heap Buffer Overflow Unauthenticated RCE | Microsoft | 9.8 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-12 | ▶ |
| CVE-2026-42208KEV | BerriAI LiteLLM Pre-Auth SQL Injection (AI Gateway Credential Theft) | BerriAI | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-05-08 | ▶ |
| CVE-2026-41940KEV | cPanel & WHM Pre-Auth CRLF Injection Authentication Bypass (Zero-Day, Ransomware) | WebPros | 9.8 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-04-28 | ▶ |
| CVE-2026-44112 | OpenClaw AI Agent TOCTOU Sandbox Write Escape ('Claw Chain') | OpenClaw (BerriAI / OpenClaw Project) | 9.6 | ■ CRITICAL | AVAILABLE | POC | 2026-05-15 | ▶ |
| CVE-2025-34291KEV | Langflow AI Workflow Platform CORS/CSRF Token-Hijack RCE (KEV Added May 21) | Langflow (DataStax) | 9.4 | ■ CRITICAL | AVAILABLE | LIMITED | 2025-12-05 | ▶ |
| CVE-2026-40402 | Windows Hyper-V Guest-to-Host Use-After-Free Privilege Escalation | Microsoft | 9.3 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-12 | ▶ |
| CVE-2026-0300KEV | Palo Alto PAN-OS Unauthenticated Root RCE via Captive Portal Buffer Overflow | Palo Alto Networks | 9.3 | ■ CRITICAL | PARTIAL | PUBLIC | 2026-05-05 | ▶ |
| CVE-2026-42945KEV | NGINX Rift — ngx_http_rewrite_module Heap Buffer Overflow (RCE) | F5 / NGINX | 9.2 | ■ CRITICAL | AVAILABLE | PUBLIC | 2026-05-13 | ▶ |
| CVE-2026-8992 | Ivanti Secure Access Client Improper Certificate Validation RCE | Ivanti | 9.1 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-22 | ▶ |
| CVE-2026-45158 | OPNsense DHCP Hostname Command Injection RCE as Root | OPNsense | 9.1 | ■ CRITICAL | AVAILABLE | POC | 2026-05-13 | ▶ |
| CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence Privilege Escalation / Identity Forgery | Microsoft | 9.1 | ■ CRITICAL | AVAILABLE | NONE | 2026-05-12 | ▶ |
| CVE-2026-45584 | Microsoft Defender Malware Protection Engine Heap Buffer Overflow RCE | Microsoft | 8.1 | ■ HIGH | AVAILABLE | NONE | 2026-05-20 | ▶ |
| CVE-2026-42897 | Microsoft Exchange Server OWA XSS Spoofing Zero-Day (Unpatched) | Microsoft | 8.1 | ■ HIGH | NO PATCH | LIMITED | 2026-05-14 | ▶ |
| CVE-2026-41091KEV | Microsoft Defender Malware Protection Engine Link-Following LPE (RedSun) | Microsoft | 7.8 | ■ HIGH | AVAILABLE | PUBLIC | 2026-05-20 | ▶ |
| CVE-2026-31431KEV | Linux Kernel 'Copy Fail' Local Privilege Escalation to Root (Cross-Distro, KEV) | Linux | 7.8 | ■ HIGH | AVAILABLE | PUBLIC | 2026-04-29 | ▶ |
| CVE-2026-34926KEV | Trend Micro Apex One On-Premise Directory Traversal (KEV Added May 21) | Trend Micro | 7.2 | ■ HIGH | AVAILABLE | LIMITED | 2026-05-21 | ▶ |
| CVE-2026-6973KEV | Ivanti EPMM Authenticated Admin RCE Exploited as Zero-Day (CISA KEV) | Ivanti | 7.2 | ■ HIGH | AVAILABLE | LIMITED | 2026-05-07 | ▶ |