NAVANEM

Documented vulnerability advisories

Every entry documented: technical breakdown, impact, mitigation and detection, with severity, CVSS and exploitation status at a glance.

124advisories
75critical
95exploited in the wild

124 advisories

QNAP QVR Pro, missing authentication for critical function (QVR Pro Auth Bypass)
CVE-2026-22898· Mar 20, 2026critical

QNAP QVR Pro, missing authentication for critical function (QVR Pro Auth Bypass)

A missing authentication for critical function vulnerability has been reported to affect QNAP QVR Pro. Remote attackers can exploit the vulnerability to gain access to the system without supplying valid credentials. Successful exploitation allows an attacker to interact directly with sensitive QVR Pro surveillance functionality over the network.

Apple dyld Memory Corruption (Targeted iOS Zero-Day)
CVE-2026-20700· Feb 11, 2026high

Apple dyld Memory Corruption (Targeted iOS Zero-Day)

A memory corruption issue in Apple's dyld dynamic linker was addressed with improved state management. Successful exploitation could lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. It was reported by Google's Threat Analysis Group and is the first Apple flaw flagged by CISA as actively exploited in 2026.

Microsoft Windows Remote Desktop, improper privilege management elevation of privilege
CVE-2026-21533· Feb 10, 2026high

Microsoft Windows Remote Desktop, improper privilege management elevation of privilege

An improper privilege management flaw in Windows Remote Desktop allows an authorized local attacker to elevate privileges to SYSTEM. Reported exploit tooling abuses the weakness by modifying an attacker-controllable service configuration to gain elevated execution. Microsoft confirmed in-the-wild exploitation, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on the disclosure date.

Microsoft Windows Desktop Window Manager (DWM) Core, type-confusion elevation of privilege
CVE-2026-21519· Feb 10, 2026high

Microsoft Windows Desktop Window Manager (DWM) Core, type-confusion elevation of privilege

A type-confusion flaw in the Desktop Window Manager (DWM) Core Library allows an authorized local attacker to elevate privileges to SYSTEM. The component accesses a resource using an incompatible type, letting an attacker who controls the object layout corrupt memory and gain kernel-level code execution. Microsoft confirmed exploitation in the wild as a zero-day, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on the day it was disclosed.

SAP CRM and S/4HANA, code injection via Scripting Editor (SAP Scripting Editor Injection)
CVE-2026-0488· Feb 9, 2026critical

SAP CRM and S/4HANA, code injection via Scripting Editor (SAP Scripting Editor Injection)

A code injection vulnerability in the Scripting Editor of SAP CRM and SAP S/4HANA (WebClient UI Framework) allows an authenticated attacker to abuse a generic function module call to execute unauthorized critical functionality, including the execution of arbitrary SQL statements. The flaw stems from a missing authorization check on the affected function module. Successful exploitation leads to full database compromise with high impact on confidentiality, integrity, and availability.

Fortinet FortiClient EMS, unauthenticated SQL injection
CVE-2026-21643· Feb 6, 2026critical

Fortinet FortiClient EMS, unauthenticated SQL injection

An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Fortinet FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. The flaw affects FortiClientEMS 7.4.0 through 7.4.4. Successful exploitation can lead to execution of unauthorized code or commands on the affected management server.

BeyondTrust Remote Support / Privileged Remote Access, pre-authentication OS command injection RCE
CVE-2026-1731· Feb 6, 2026critical

BeyondTrust Remote Support / Privileged Remote Access, pre-authentication OS command injection RCE

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user. The flaw is an OS command injection (CWE-78) reachable without authentication or user interaction.

Ivanti Endpoint Manager Mobile, unauthenticated code injection
CVE-2026-1281· Jan 29, 2026critical

Ivanti Endpoint Manager Mobile, unauthenticated code injection

A code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allows a remote, unauthenticated attacker to achieve remote code execution on affected systems. The issue stems from improper control of code generation and affects EPMM versions up to and including 12.7.0.0. Successful exploitation results in arbitrary code execution in the context of the EPMM application.

Juniper Networks Session Smart Router, API authentication bypass (Juniper SSR Auth Bypass)
CVE-2025-21589· Jan 27, 2026critical

Juniper Networks Session Smart Router, API authentication bypass (Juniper SSR Auth Bypass)

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router, Session Smart Conductor, and WAN Assurance Managed Routers may allow a network-based attacker to bypass authentication and take administrative control of the device. The flaw lets an unauthenticated, remote attacker reach administrative functionality through an alternate path. Successful exploitation grants full administrative control of the affected device.

Fortinet multiple products, authentication bypass via FortiCloud SSO (alternate-channel)
CVE-2026-24858· Jan 27, 2026critical

Fortinet multiple products, authentication bypass via FortiCloud SSO (alternate-channel)

An authentication bypass using an alternate path or channel in multiple Fortinet products, including FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiWeb and FortiNAC-F, may allow an attacker holding a FortiCloud account and a registered device to log into other devices registered to other accounts, when FortiCloud SSO authentication is enabled on those devices. Fortinet confirmed the flaw was being exploited in the wild by malicious FortiCloud accounts.

Oracle Fusion Middleware WebLogic Server Proxy Plug-in, unauthenticated improper access control RCE
CVE-2026-21962· Jan 20, 2026critical

Oracle Fusion Middleware WebLogic Server Proxy Plug-in, unauthenticated improper access control RCE

A vulnerability in the Oracle HTTP Server / Oracle WebLogic Server Proxy Plug-in component of Oracle Fusion Middleware (WebLogic Server Proxy Plug-in for Apache HTTP Server and for IIS) allows an unauthenticated attacker with network access via HTTP to compromise the affected products. Supported versions affected are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. The easily exploitable flaw can result in unauthorized data access and modification, and while the vulnerability is in the proxy plug-in, attacks may significantly impact additional products.

WatchGuard Firebox, IKEv2 out-of-bounds write pre-auth RCE
CVE-2025-14733· Dec 18, 2025critical

WatchGuard Firebox, IKEv2 out-of-bounds write pre-auth RCE

An out-of-bounds write vulnerability in WatchGuard Fireware OS may allow a remote, unauthenticated attacker to execute arbitrary code. The issue affects IKEv2 VPN configurations that use dynamic gateway peers, impacting Fireware OS versions 11.10.2 through 12.11.5 and 2025.1 through 2025.1.3. Successful exploitation can lead to remote code execution on the Firebox appliance.

Apple WebKit Use-After-Free (Arbitrary Code Execution Zero-Day)
CVE-2025-43529· Dec 17, 2025high

Apple WebKit Use-After-Free (Arbitrary Code Execution Zero-Day)

A use-after-free issue in Apple's WebKit browser engine was addressed with improved memory management. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. The flaw affects Safari and every browser on iOS/iPadOS, since all of them are required to use WebKit.

Fortinet FortiWeb, relative path traversal authentication bypass to admin RCE
CVE-2025-64446· Nov 14, 2025critical

Fortinet FortiWeb, relative path traversal authentication bypass to admin RCE

A relative path traversal in Fortinet FortiWeb allows an unauthenticated remote attacker to execute administrative commands via crafted HTTP/HTTPS requests. By traversing to a privileged internal endpoint, attackers can create new administrator accounts and take full control of the WAF appliance. Fortinet observed exploitation in the wild.

Microsoft SQL Server, SQL injection enabling network privilege escalation
CVE-2025-59499· Nov 11, 2025high

Microsoft SQL Server, SQL injection enabling network privilege escalation

An SQL injection vulnerability in Microsoft SQL Server arises from improper neutralization of special elements in SQL commands, allowing an authorized attacker to elevate privileges over a network. An attacker with limited but legitimate database access can craft statements that bypass authorization checks and obtain higher database privileges. Microsoft assessed exploitation as less likely, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.

KingAddons King Addons for Elementor, unauthenticated arbitrary file upload (King Addons File Upload)
CVE-2025-6327· Nov 6, 2025critical

KingAddons King Addons for Elementor, unauthenticated arbitrary file upload (King Addons File Upload)

An unrestricted file upload vulnerability exists in the King Addons for Elementor WordPress plugin in all versions up to and including 51.1.36. The plugin's form upload AJAX handler exposes its nonce to every site visitor and fails to validate the uploaded file type, allowing an unauthenticated attacker to upload arbitrary files, including a PHP web shell, to a web-accessible directory. Successful exploitation leads to remote code execution on the underlying web server.

AI Engine plugin for WordPress, unauthenticated sensitive information exposure to privilege escalation (AI Engine MCP Token Leak)
CVE-2025-11749· Nov 5, 2025critical

AI Engine plugin for WordPress, unauthenticated sensitive information exposure to privilege escalation (AI Engine MCP Token Leak)

The AI Engine plugin for WordPress in all versions up to and including 3.1.3 exposes the MCP bearer token through the /mcp/v1/ REST API endpoint when the 'No-Auth URL' feature is enabled. This allows unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session. With the captured token an attacker can invoke privileged MCP actions and escalate to full administrative control of the site.

F5 BIG-IP APM, unauthenticated remote code execution via crafted access-policy traffic
CVE-2025-53521· Oct 15, 2025critical

F5 BIG-IP APM, unauthenticated remote code execution via crafted access-policy traffic

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to remote code execution in the access-policy daemon. The vulnerability is unauthenticated and was reclassified from a denial-of-service issue to a remote-code-execution issue after real-world exploitation and post-compromise activity were observed. F5 published fixes and CISA added the flaw to its Known Exploited Vulnerabilities catalog.

Microsoft Windows Server Update Services (WSUS), deserialization RCE
CVE-2025-59287· Oct 14, 2025critical

Microsoft Windows Server Update Services (WSUS), deserialization RCE

Deserialization of untrusted data in Windows Server Update Services (WSUS) allows an unauthenticated remote attacker to execute code as SYSTEM with no user interaction. An attacker sends a crafted event to a WSUS server that triggers unsafe object deserialization on servers with the WSUS Server Role enabled. The flaw was mass-exploited within hours of Microsoft's out-of-band patch.

vLLM Timing Attack on API Key Validation - CVE-2025-59425 Analysis
CVE-2025-59425· Oct 7, 2025high

vLLM Timing Attack on API Key Validation - CVE-2025-59425 Analysis

CVE-2025-59425 is a high-severity timing attack vulnerability in vLLM's built-in API key validation that allows remote attackers to bypass authentication without credentials. Fixed in version 0.11.0rc2.

show