Exploit & Zero-Day Registry

89 vulnerabilities tracked

89
Total Exploits
13
Active Zero-Days
12
Avg Days in Wild
74
CISA KEV Listed
Severity
Status
IDCVETitlePlatformSeverityStatusDays WildKEV
TP-EXP-2009-0002CVE-2009-3459Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability (CVE-2009-3459)Adobe Acrobat and Readerhighpatched
TP-EXP-2026-0008CVE-2026-34621Adobe Acrobat and Reader Prototype Pollution RCE (CVE-2026-34621)Adobe Acrobat and Readerhighpatched
TP-EXP-2020-0001CVE-2020-9715Adobe Acrobat Use-After-Free Vulnerability (CVE-2020-9715)Adobe Acrobathighpatched
TP-EXP-2025-0007CVE-2025-48595Android Framework Integer Overflow Vulnerability (CVE-2025-48595)Android Frameworkhighpatched
TP-EXP-2026-0009CVE-2026-34197Apache ActiveMQ Improper Input Validation Vulnerability (CVE-2026-34197)Apache ActiveMQhighpatched
TP-EXP-2017-0001CVE-2017-5638Apache Struts Content-Type RCE (CVE-2017-5638)Apache Struts 2.3.x before 2.3.32, 2.5.x before 2.5.10.1criticalpatched
TP-EXP-2026-0319CVE-2026-7473Arista EOS Tunnel Decapsulation Bypass (CVE-2026-7473)Arista Extensible Operating Systemmediummitigated
TP-EXP-2026-0021CVE-2026-42208BerriAI LiteLLM SQL Injection in Proxy API Key Verification (CVE-2026-42208)BerriAI LiteLLMcriticalactive
TP-EXP-2026-0316CVE-2026-42271BerriAI LiteLLM MCP Stdio Command Injection (CVE-2026-42271)BerriAI LiteLLMhighpatched
TP-EXP-2026-0001CVE-2026-33825BlueHammer — Microsoft Defender Local Privilege EscalationWindows 10 / 11 with Microsoft Defender enabledhighpatched
TP-EXP-2019-0001CVE-2019-0708BlueKeep Remote Desktop Services Remote Code Execution Vulnerability (CVE-2019-0708)Microsoft Remote Desktop Services on legacy Windows versionscriticalpatched
TP-EXP-2026-0315CVE-2026-50751Check Point Security Gateway Improper Authentication Vulnerability (CVE-2026-50751)Check Point Security Gatewaycriticalactive
TP-EXP-2026-0311CVE-2026-45829ChromaDB pre-auth remote code execution in Python FastAPI server (CVE-2026-45829)ChromaDB Python FastAPI serverhighactive
TP-EXP-2026-0006CVE-2026-5281Chrome Dawn WebGPU Use-After-Free — CVE-2026-5281Google Chrome < 146.0.7680.177highpatched
TP-EXP-2026-0286CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE-2026-20182)Cisco Catalyst SD-WAN Controller and Managercriticalpatched
TP-EXP-2026-0013CVE-2026-20122Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite via Privileged API (CVE-2026-20122)Cisco Catalyst SD-WAN Manager < 20.15.4.2mediumpatched0
TP-EXP-2026-0011CVE-2026-20128Cisco Catalyst SD-WAN Manager — DCA Credential File Exposure (CVE-2026-20128)Cisco Catalyst SD-WAN Manager prior to 20.18highpatched
TP-EXP-2026-0012CVE-2026-20133Cisco Catalyst SD-WAN Manager — OS-Level Sensitive Information Disclosure (CVE-2026-20133)Cisco Catalyst SD-WAN Manager prior to 20.18.2.1highpatched
TP-EXP-2026-0318CVE-2026-20245Cisco Catalyst SD-WAN Command Injection Privilege Escalation (CVE-2026-20245)Cisco Catalyst SD-WAN Managerhighpatched
TP-EXP-2026-0323CVE-2026-20262Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)Cisco Catalyst SD-WAN Managermediumpatched
TP-EXP-2026-0002CVE-2026-20131Cisco FMC Insecure Deserialization — Interlock Ransomware Zero-DayCisco Secure FMCcriticalpatched37
TP-EXP-2026-0307CVE-2026-45793Composer GitHub Actions Token Disclosure Vulnerability (CVE-2026-45793)Composerhighpatched
TP-EXP-2024-0006CVE-2024-1708ConnectWise ScreenConnect Path Traversal — Authentication Bypass via Directory Traversal (CVE-2024-1708)ConnectWise ScreenConnect < 23.9.8highpatched
TP-EXP-2025-0005CVE-2025-29635D-Link DIR-823X Authenticated Command Injection via set_prohibiting API (CVE-2025-29635)D-Link DIR-823X firmware 240126 / 240802highactive
TP-EXP-2026-0308CVE-2026-8398Daemon Tools Lite Embedded Malicious Code Vulnerability (CVE-2026-8398)Daemon Tools Litecriticalactive
TP-EXP-2026-0291CVE-2026-9082Drupal Core SQL Injection Vulnerability (CVE-2026-9082)Drupal Corehighpatched
TP-EXP-2017-0002CVE-2017-0144EternalBlue — SMBv1 Remote Code Execution (CVE-2017-0144)Microsoft Windows SMBv1 (Windows XP through Server 2008 R2)criticalpatched
TP-EXP-2026-0310CVE-2026-45185Exim BDAT Use-After-Free Remote Code Execution (CVE-2026-45185)Exim Mail Transfer Agentcriticalpatched
TP-EXP-2026-0004CVE-2026-35616FortiClient EMS API Authentication Bypass — Pre-Auth RCEFortiClient EMS 7.4.5–7.4.6criticalpatched4
TP-EXP-2026-0007CVE-2026-21643Fortinet FortiClient EMS SQL Injection (CVE-2026-21643)Fortinet FortiClient EMScriticalpatched
TP-EXP-2026-0023CVE-2026-42511FreeBSD dhclient Remote Code Execution via DHCP BOOTP File Field Injection (CVE-2026-42511)FreeBSD 13.5, 14.3, 14.4, and 15.0 (supported stable and releng branches)highpatched
TP-EXP-2026-0016CVE-2026-3854GitHub Enterprise Server Git Push Option Injection RCE (CVE-2026-3854)GitHub Enterprise Server ≤ 3.19.3; GitHub.com (mitigated)highpatched
TP-EXP-2026-0317CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write (CVE-2026-11645)Google Chromium V8highpatched
TP-EXP-2026-0284PendingGreenPlasma — Windows CTFMON Arbitrary Section Creation Privilege EscalationMicrosoft Windows 11 and Windows Server 2022/2026, per public researcher claimshighunknown
TP-EXP-2014-0002CVE-2014-0160Heartbleed — OpenSSL TLS Heartbeat Buffer Over-read (CVE-2014-0160)OpenSSL 1.0.1 through 1.0.1fcriticalpatched
TP-EXP-2026-0020CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Remote Code Execution (CVE-2026-6973)Ivanti Endpoint Manager Mobile (EPMM)highactive
TP-EXP-2026-0003CVE-2026-1340Ivanti EPMM Code Injection — Bash Arithmetic Expansion RCEIvanti EPMM ≤ 12.7.0.0criticalpatched
TP-EXP-2026-0320CVE-2026-10520Ivanti Sentry OS Command Injection Vulnerability (CVE-2026-10520)Ivanti Sentry before R10.5.2, R10.6.2, and R10.7.1criticalpatched
TP-EXP-2024-0002CVE-2024-27199JetBrains TeamCity Relative Path Traversal — Unauthenticated Limited Admin Actions (CVE-2024-27199)JetBrains TeamCity prior to 2023.11.4highpatched
TP-EXP-2025-0003CVE-2025-2749Kentico Xperience Staging Sync Server Path Traversal and RCE (CVE-2025-2749)Kentico Xperience CMS (through version 13.0.178)highpatched
TP-EXP-2026-0313CVE-2026-5426KnowledgeDeliver LMS ViewState Deserialization Zero-DayDigital Knowledge KnowledgeDeliver deployments before 2026-02-24criticalpatched
TP-EXP-2025-0006CVE-2025-34291Langflow Origin Validation Error Vulnerability (CVE-2025-34291)Langflowhighpatched
TP-EXP-2022-0001CVE-2022-0492Linux Kernel Improper Authentication (CVE-2022-0492)Linux Kernelhighactive
TP-EXP-2026-0018CVE-2026-31431Linux Kernel algif_aead In-Place Page-Cache Write Local Privilege Escalation (CVE-2026-31431)Linux Kernel (algif_aead crypto interface, versions 4.14 through 6.19.11)highpatched
TP-EXP-2026-0022CVE-2026-43284Dirty Frag Linux Kernel Local Privilege Escalation (CVE-2026-43284)Linux kernel ESP/XFRM networking subsystemhighpatched
TP-EXP-2026-0292CVE-2026-48172LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-48172)LiteSpeed cPanel Pluginhighunknown
TP-EXP-2026-0322CVE-2026-54420LiteSpeed cPanel Plugin Symlink Following Privilege Escalation (CVE-2026-54420)LiteSpeed cPanel Pluginhighpatched
TP-EXP-2021-0001CVE-2021-44228Log4Shell — Apache Log4j2 Remote Code Execution (CVE-2021-44228)Apache Log4j2 2.0-beta9 through 2.14.1criticalpatched9
TP-EXP-2026-0014CVE-2026-39987Marimo Pre-Authentication Remote Code Execution via Terminal WebSocket (CVE-2026-39987)Marimo < 0.23.0criticalpatched0
TP-EXP-2026-0288CVE-2026-41091Microsoft Defender Link Following Vulnerability (CVE-2026-41091)Microsoft Defenderhighpatched
TP-EXP-2026-0289CVE-2026-45498Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)Microsoft Defendermediumactive
TP-EXP-2009-0003CVE-2009-1537Microsoft DirectX NULL Byte Overwrite Vulnerability (CVE-2009-1537)Microsoft DirectXhighpatched
TP-EXP-2023-0001CVE-2023-21529Microsoft Exchange Server Deserialization of Untrusted Data (CVE-2023-21529)Microsoft Exchange Server 2013, 2016, 2019highpatched
TP-EXP-2026-0287CVE-2026-42897Microsoft Exchange Server Cross-Site Scripting Vulnerability (CVE-2026-42897)Microsoft Exchange Server Outlook Web Accesshighmitigated
TP-EXP-2010-0002CVE-2010-0806Microsoft Internet Explorer Use-After-Free Vulnerability (CVE-2010-0806)Microsoft Internet Explorerhighpatched
TP-EXP-2009-0001CVE-2009-0238Microsoft Office Excel Remote Code Execution (CVE-2009-0238)Microsoft Office Excel 2000 through 2007highpatched
TP-EXP-2026-0010CVE-2026-32201Microsoft SharePoint Server Improper Input Validation Vulnerability (CVE-2026-32201)Microsoft SharePoint Servermediumpatched
TP-EXP-2012-0001CVE-2012-1854Microsoft Visual Basic for Applications Insecure Library Loading (CVE-2012-1854)Microsoft Visual Basic for Applications (VBA) in Office 2003 SP3, 2007 SP2/SP3, 2010 SP1highpatched
TP-EXP-2023-0002CVE-2023-36424Microsoft Windows Out-of-Bounds Read Vulnerability (CVE-2023-36424)Microsoft Windowshighpatched
TP-EXP-2025-0001CVE-2025-60710Microsoft Windows Host Process for Windows Tasks Link Following LPE (CVE-2025-60710)Microsoft Windows 11 (24H2, 25H2), Windows Server 2025highpatched
TP-EXP-2026-0015CVE-2026-32202Microsoft Windows Shell Spoofing Vulnerability (CVE-2026-32202)Microsoft Windowsmediumpatched
TP-EXP-2026-0312CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability (CVE-2026-45247)Mirasvit Mirasvit Full Page Cache Warmer for Magento 2criticalpatched
TP-EXP-2026-0305CVE-2026-42945NGINX Rift Heap Buffer Overflow (CVE-2026-42945)NGINX Open Source 0.6.27 through 1.30.0 and NGINX Plus R32 through R36criticalpatched
TP-EXP-2026-0309CVE-2026-48027Nx Console Embedded Malicious Code Vulnerability (CVE-2026-48027)Nx Consolecriticalactive
CVE-2026-7482Ollama GGUF Model Loader Heap Out-of-Bounds Read — Bleeding Llama (CVE-2026-7482)Ollama (all versions before 0.17.1)criticalpatched
TP-EXP-2026-0309CVE-2026-28517openDCIM Install and Config Poisoning RCE Chain (CVE-2026-28515 / CVE-2026-28517)openDCIM version 23.04 through commit 4467e9c4criticalunknown
TP-EXP-2026-0321CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools Missing Authentication Vulnerability (CVE-2026-35273)Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62criticalpatched
TP-EXP-2024-0007CVE-2024-21182Oracle WebLogic Server Unspecified Vulnerability (CVE-2024-21182)Oracle WebLogic Serverhighunknown
TP-EXP-2026-0311CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass (CVE-2026-0257)Palo Alto Networks PAN-OShighactive
TP-EXP-2026-0019CVE-2026-0300PAN-OS: Unauthenticated Buffer Overflow in User-ID Authentication Portal (CVE-2026-0300)Palo Alto Networks PAN-OScriticalactive
TP-EXP-2024-0001CVE-2024-3400Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)Palo Alto Networks PAN-OS 10.2, 11.0, 11.1criticalpatched26
TP-EXP-2023-0001CVE-2023-27351PaperCut NG/MF SecurityRequestFilter Authentication Bypass (CVE-2023-27351)PaperCut NG and PaperCut MF (versions prior to 20.1.7, 21.2.11, 22.0.9)highpatched
TP-EXP-2026-0306CVE-2026-44338PraisonAI Legacy API Authentication Bypass (CVE-2026-44338)PraisonAI legacy Flask API server versions 2.5.6 through 4.6.33highpatched0
CVE-2026-3965Qinglong Task Scheduler Authentication Bypass RCE (CVE-2026-3965)@whyour/qinglong before 2.20.2criticalpatched23
TP-EXP-2025-0002CVE-2025-32975Quest KACE SMA SSO Authentication Bypass (CVE-2025-32975)Quest KACE Systems Management Appliance (SMA)criticalpatched
TP-EXP-2024-0004CVE-2024-7399Samsung MagicINFO 9 Server Unauthenticated File Upload to Remote Code Execution (CVE-2024-7399)Samsung MagicINFO 9 Server <= 21.1050highpatched
TP-EXP-2014-0003CVE-2014-6271Shellshock — GNU Bash Environment Variable Command Injection (CVE-2014-6271)GNU Bash before patched vendor releases for CVE-2014-6271criticalpatched
TP-EXP-2024-0003CVE-2024-57726SimpleHelp Technician Privilege Escalation to Admin via API Key Creation (CVE-2024-57726)SimpleHelp <= 5.5.7criticalpatched
TP-EXP-2024-0005CVE-2024-57728SimpleHelp Admin Arbitrary File Upload via Zip Slip (CVE-2024-57728)SimpleHelp <= 5.5.7highpatched
TP-EXP-2026-0314CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability (CVE-2026-28318)SolarWinds Serv-U 15.5.4 and earlierhighpatched
TP-EXP-2026-0325CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function Vulnerability (CVE-2026-20253)Splunk Enterprise 10.2.x < 10.2.4; 10.0.x < 10.0.7highpatched
TP-EXP-2010-0001CVE-2010-2568Stuxnet — Windows Shell LNK Shortcut Remote Code Execution (CVE-2010-2568)Microsoft Windows / Siemens SIMATIC WinCC Step 7criticalpatched
TP-EXP-2025-0004CVE-2025-48700Synacor Zimbra Collaboration Suite (ZCS) — Cross-Site Scripting in Classic UI (CVE-2025-48700)Synacor Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, 10.1mediumpatched
TP-EXP-2026-0310CVE-2026-45321TanStack Unspecified Vulnerability (CVE-2026-45321)TanStack packages on npm registrycriticalactive
TP-EXP-2026-0290CVE-2026-34926Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability (CVE-2026-34926)Trend Micro Apex Onemediumpatched
TP-EXP-2026-0005CVE-2026-3502TrueConf Update Integrity Bypass — Supply Chain Code ExecutionTrueConf Windows Client < 8.5.3highpatched
TP-EXP-2026-0017CVE-2026-41940WebPros cPanel & WHM and WP2 (WordPress Squared) Authentication Bypass via Login Flow (CVE-2026-41940)WebPros cPanel & WHM (versions 11.40 through 136.x) and WP2 WordPress Squared (prior to 136.1.7)criticalpatched
TP-EXP-2026-0324CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control Vulnerability (CVE-2026-48907)Widget Factory Joomla Content Editorhighpatched
TP-EXP-2026-0285PendingYellowKey — Windows BitLocker Bypass (Pending CVE)Microsoft Windows 11 and Windows Server 2022/2025, per public researcher claimshighactive