| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-1731 KEV 📌 💣 | Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) EPSS 0.91 | BeyondTrust | Remote Support(RS) & Privileged Remote Access(PRA) | - | - | 2026-02-06 21:49:21 | Deep Dive |
| CVE-2026-21643 KEV 📌 💣 | Fortinet FortiClientEMS SQL注入漏洞 EPSS 0.94 | Fortinet | FortiClientEMS | Critical | 9.8 | 2026-02-06 08:24:44 | Deep Dive |
| CVE-2026-1340 KEV 📌 💣 | Ivanti Endpoint Manager Mobile 代码注入漏洞 EPSS 0.99 | Ivanti | Endpoint Manager Mobile | Critical | 9.8 | 2026-01-29 21:33:12 | Deep Dive |
| CVE-2026-1281 KEV 📌 💣 | Ivanti Endpoint Manager Mobile 代码注入漏洞 EPSS 0.99 | Ivanti | Endpoint Manager Mobile | Critical | 9.8 | 2026-01-29 21:31:17 | Deep Dive |
| CVE-2025-40551 KEV 📌 💣 | SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability EPSS 0.84 | SolarWinds | Web Help Desk | Critical | 9.8 | 2026-01-28 07:33:10 | Deep Dive |
| CVE-2025-40536 KEV 📌 💣 | SolarWinds Web Help Desk Security Control Bypass Vulnerability EPSS 0.74 | SolarWinds | Web Help Desk | High | 8.1 | 2026-01-28 07:30:10 | Deep Dive |
| CVE-2026-24858 KEV 📌 | Fortinet多款产品 安全漏洞 EPSS 0.86 | Fortinet | FortiWeb | Critical | 9.8 | 2026-01-27 19:18:24 | Deep Dive |
| CVE-2026-21509 KEV 📌 | Microsoft Office Security Feature Bypass Vulnerability EPSS 0.71 | Microsoft | Microsoft 365 Apps for Enterprise | High | 7.8 | 2026-01-26 17:06:36 | Deep Dive |
| CVE-2026-24423 KEV 📌 💣 | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API EPSS 0.88 | SmarterTools | SmarterMail | Critical | 9.3 | 2026-01-23 16:53:35 | Deep Dive |
| CVE-2026-23760 KEV 📌 💣 | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API EPSS 0.97 | SmarterTools | SmarterMail | Critical | 9.3 | 2026-01-22 14:35:17 | Deep Dive |
| CVE-2026-24061 KEV 📌 💣 | GNU Inetutils 参数注入漏洞 EPSS 0.99 | GNU | Inetutils | Critical | 9.8 | 2026-01-21 06:42:17 | Deep Dive |
| CVE-2026-21962 KEV 📌 | Oracle Fusion Middleware 安全漏洞 EPSS 0.71 | Oracle Corporation | Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in | Critical | 10.0 | 2026-01-20 21:56:33 | Deep Dive |
| CVE-2026-22200 📌 💣 | osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read EPSS 0.74 | Enhancesoft | osTicket | - | - | 2026-01-12 18:34:13 | Deep Dive |
| CVE-2026-21858 📌 💣 | n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling EPSS 0.78 | n8n-io | n8n | Critical | 10.0 | 2026-01-07 23:57:52 | Deep Dive |
| CVE-2025-52691 KEV 📌 💣 | Upload Arbitrary Files EPSS 0.86 | SmarterTools | SmarterMail | Critical | 10.0 | 2025-12-29 02:15:58 | Deep Dive |
| CVE-2025-68613 KEV 📌 💣 | n8n Vulnerable to Remote Code Execution via Expression Injection EPSS 0.99 | n8n-io | n8n | Critical | 9.9 | 2025-12-19 22:23:48 | Deep Dive |
| CVE-2025-14847 KEV 📌 💣 | Zlib compressed protocol header length confusion may allow memory read EPSS 0.83 | MongoDB Inc. | MongoDB Server | High | 7.5 | 2025-12-19 11:00:22 | Deep Dive |
| CVE-2025-37164 KEV 📌 💣 | HPE OneView 安全漏洞 EPSS 0.90 | Hewlett Packard Enterprise (HPE) | HPE OneView | Critical | 10.0 | 2025-12-16 16:30:35 | Deep Dive |
| CVE-2025-8110 KEV 📌 💣 | File overwrite in file update API in Gogs EPSS 0.85 | Gogs | Gogs | - | - | 2025-12-10 13:23:47 | Deep Dive |
| CVE-2025-34291 KEV 📌 💣 | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE EPSS 0.93 | Langflow | Langflow | 中危 | - | 2025-12-05 22:27:26 | Deep Dive |