Internet Exposure Likelihood: HIGH
CVSS: 7.2
CVE-2026-6973 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated administrators to achieve remote code execution. EPMM is typically deployed as an internet-facing mobile device management server, making this a direct network exploitation risk.
CVE ADDED: 2026-05-07
0 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.3
Critical unauthenticated buffer overflow vulnerability in Palo Alto PAN-OS User-ID Authentication Portal allowing remote code execution with root privileges. Already under active exploitation in the wild against internet-facing firewalls.
CVE ADDED: 2026-05-06
0 DAY BETWEEN CVE AND KEV
2 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.8
RANSOMWARE USE
Critical authentication bypass vulnerability in cPanel and WHM control panels allowing unauthenticated remote attackers to gain unauthorized access. These web hosting management platforms are almost universally internet-facing by design and widely exploited in the wild.
CVE ADDED: 2026-04-29
1 DAY BETWEEN CVE AND KEV
8 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.3
Marimo Python notebook server has a critical pre-authentication RCE vulnerability allowing unauthenticated attackers to execute arbitrary system commands via an unprotected terminal WebSocket endpoint. This vulnerability is actively exploited in the wild and was added to CISA KEV catalog after being exploited within 10 hours of disclosure.
CVE ADDED: 2026-04-09
14 DAYS BETWEEN CVE AND KEV
15 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 5.4
CVE-2026-20122 is a critical arbitrary file overwrite vulnerability in Cisco Catalyst SD-WAN Manager's API that allows authenticated attackers to gain elevated privileges. This vulnerability is actively exploited in the wild and listed in CISA's KEV catalog.
CVE ADDED: 2026-02-25
54 DAYS BETWEEN CVE AND KEV
18 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 6.5
CVE-2026-20133 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager that allows unauthenticated, remote attackers to view sensitive information by accessing the API. SD-WAN Manager is typically deployed as an internet-facing centralized management platform.
CVE ADDED: 2026-02-25
54 DAYS BETWEEN CVE AND KEV
18 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 8.8
Critical remote code execution vulnerability in Apache ActiveMQ through the Jolokia JMX-HTTP bridge exposed on web console. Authenticated attackers can exploit crafted discovery URIs to trigger remote Spring XML loading, leading to arbitrary code execution via bean factory methods.
CVE ADDED: 2026-04-07
9 DAYS BETWEEN CVE AND KEV
22 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 6.5
SharePoint Server spoofing vulnerability allowing unauthorized attackers to exploit via network access without authentication or user interaction. Listed in CISA KEV indicating active exploitation.
CVE ADDED: 2026-04-14
0 DAY BETWEEN CVE AND KEV
24 DAYS SINCE KEV
View Details →