Vulnerabilities

Summary — last 7 days

New vulnerabilities3,085▲ 506 vs. last week
Critical / high1,460▲ 60 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

21 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (6.3)0.25%—Cisco Crosswork Network Controller6/17/20266/22/2026
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.
Awaiting AnalysisNone (0)0.31%—Cisco Crosswork Network ControllerAICisco Network Services OrchestratorAI5/6/20266/17/2026
Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis,…
Awaiting AnalysisHigh (7.7)0.11%—UI Unifi Network ControllerAI3/27/20266/17/2026
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and…
Awaiting AnalysisCritical (9)0.08%—UI Unifi Network ControllerAIUI UAPAIUI UAP ACAIUI USWAI+13/27/20266/17/2026
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow…
AnalyzedMedium (5.4)0.29%—Cisco Crosswork Network ControllerCisco Common Services Platform Collector1/8/20256/17/2026
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the…
AnalyzedMedium (5.4)0.29%—Cisco Crosswork Network ControllerCisco Common Services Platform Collector1/8/20256/17/2026
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the…
AnalyzedMedium (5.4)0.37%—Cisco Crosswork Network ControllerCisco Common Services Platform Collector1/8/20256/17/2026
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the…
AnalyzedMedium (4.8)0.27%—Cisco Crosswork Network Controller1/8/20256/17/2026
Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users of the interface of an affected system. These vulnerabilities exist because the web-based management interface…
DeferredHigh (7)0.39%—Intel Ethernet Network Controllers E810 SeriesAI8/14/20246/17/2026
Protection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access.
DeferredCritical (9.3)0.21%—Intel Ethernet Network ControllersAILinux KernelAI8/14/20246/17/2026
Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
DeferredCritical (9.3)0.18%—Intel Ethernet Network ControllersAILinux KernelAI8/14/20246/17/2026
Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
DeferredMedium (6.8)0.16%—Intel Ethernet Network Controller E810AILinux KernelAI8/14/20246/17/2026
Improper conditions check in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access.
ModifiedMedium (4.7)0.11%—Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware8/11/20236/17/2026
Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access.
ModifiedHigh (8.8)0.36%—Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller2/23/20236/17/2026
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This…
ModifiedMedium (4.4)0.19%—Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+112/16/20236/17/2026
Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access.
ModifiedCritical (9.8)1.1%—UI Unifi Network Controller1/14/20226/17/2026
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.
AnalyzedCritical (10)100%⚠ Active exploitation💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13912/10/20218/11/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModifiedMedium (4.4)0.23%—Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware11/17/20216/17/2026
Improper input validation in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.6.0.6 may allow a privileged user to potentially enable a denial of service via local access.
ModifiedMedium (4.4)0.23%—Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware11/17/20216/17/2026
Improper access control in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to potentially enable a denial of service via local access.
ModifiedMedium (4.4)0.23%—Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware11/17/20216/17/2026
Protection mechanism failure in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to enable a denial of service via local access.
ModifiedHigh (7.5)1.8%—Johnsoncontrols Network ControllerJohnsoncontrols Network Controller Firmware7/16/20126/16/2026
The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).
Orbitaley — Vulnerabilities