CVE-2026-20963
Microsoft · SharePoint
Added Mar 18, 2026
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2025-47813
Wing FTP Server · Wing FTP Server
Added Mar 16, 2026
Wing FTP Server Information Disclosure Vulnerability
Critical
CVE-2026-3910
Google · Chromium V8
Added Mar 13, 2026
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Critical
CVE-2026-3909
Google · Skia
Added Mar 13, 2026
Google Skia Out-of-Bounds Write Vulnerability
Critical
CVE-2025-68613
n8n · n8n
Added Mar 11, 2026
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
Critical
CVE-2021-22054
Omnissa · Workspace One UEM
Added Mar 9, 2026
Omnissa Workspace ONE Server-Side Request Forgery
Critical
CVE-2026-1603
Ivanti · Endpoint Manager (EPM)
Added Mar 9, 2026
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Critical
CVE-2025-26399
SolarWinds · Web Help Desk
Added Mar 9, 2026
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Critical
CVE-2017-7921
Hikvision · Multiple Products
Added Mar 5, 2026
Hikvision Multiple Products Improper Authentication Vulnerability
Critical
CVE-2021-22681
Rockwell · Multiple Products
Added Mar 5, 2026
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Critical
CVE-2023-43000
Apple · Multiple Products
Added Mar 5, 2026
Apple Multiple products Use-After-Free Vulnerability
Critical
CVE-2021-30952
Apple · Multiple Products
Added Mar 5, 2026
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
Critical
CVE-2023-41974
Apple · iOS and iPadOS
Added Mar 5, 2026
Apple iOS and iPadOS Use-After-Free Vulnerability
Critical
CVE-2026-22719
Broadcom · VMware Aria Operations
Added Mar 3, 2026
Broadcom VMware Aria Operations Command Injection Vulnerability
Critical
CVE-2026-21385
Qualcomm · Multiple Chipsets
Added Mar 3, 2026
Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Critical
CVE-2022-20775
Cisco · SD-WAN
Added Feb 25, 2026
Cisco SD-WAN Path Traversal Vulnerability
Critical
CVE-2026-20127
Cisco · Catalyst SD-WAN Controller and Manager
Added Feb 25, 2026
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Critical
CVE-2026-25108
Soliton Systems K.K · FileZen
Added Feb 24, 2026
Soliton Systems K.K FileZen OS Command Injection Vulnerability
Critical
CVE-2025-49113
Roundcube · Webmail
Added Feb 20, 2026
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Critical
CVE-2025-68461
Roundcube · Webmail
Added Feb 20, 2026
RoundCube Webmail Cross-site Scripting Vulnerability
Critical
CVE-2021-22175
GitLab · GitLab
Added Feb 18, 2026
GitLab Server-Side Request Forgery (SSRF) Vulnerability
Critical
CVE-2026-22769
Dell · RecoverPoint for Virtual Machines (RP4VMs)
Added Feb 18, 2026
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Critical
CVE-2008-0015
Microsoft · Windows
Added Feb 17, 2026
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Critical
CVE-2026-2441
Google · Chromium
Added Feb 17, 2026
Google Chromium CSS Use-After-Free Vulnerability
Critical
CVE-2020-7796
Synacor · Zimbra Collaboration Suite
Added Feb 17, 2026
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.