Internet Exposure Likelihood: VERY_HIGH
CVSS: 9.8
Critical authentication bypass vulnerability in cPanel and WHM control panels allowing unauthenticated remote attackers to gain unauthorized access. These web hosting management platforms are almost universally internet-facing by design and widely exploited in the wild.
CVE ADDED: 2026-04-29
1 DAY BETWEEN CVE AND KEV
1 DAY SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.3
Marimo Python notebook server has a critical pre-authentication RCE vulnerability allowing unauthenticated attackers to execute arbitrary system commands via an unprotected terminal WebSocket endpoint. This vulnerability is actively exploited in the wild and was added to CISA KEV catalog after being exploited within 10 hours of disclosure.
CVE ADDED: 2026-04-09
14 DAYS BETWEEN CVE AND KEV
8 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 5.4
CVE-2026-20122 is a critical arbitrary file overwrite vulnerability in Cisco Catalyst SD-WAN Manager's API that allows authenticated attackers to gain elevated privileges. This vulnerability is actively exploited in the wild and listed in CISA's KEV catalog.
CVE ADDED: 2026-02-25
54 DAYS BETWEEN CVE AND KEV
11 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 6.5
CVE-2026-20133 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager that allows unauthenticated, remote attackers to view sensitive information by accessing the API. SD-WAN Manager is typically deployed as an internet-facing centralized management platform.
CVE ADDED: 2026-02-25
54 DAYS BETWEEN CVE AND KEV
11 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 8.8
Critical remote code execution vulnerability in Apache ActiveMQ through the Jolokia JMX-HTTP bridge exposed on web console. Authenticated attackers can exploit crafted discovery URIs to trigger remote Spring XML loading, leading to arbitrary code execution via bean factory methods.
CVE ADDED: 2026-04-07
9 DAYS BETWEEN CVE AND KEV
15 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: VERY_HIGH
CVSS: 6.5
SharePoint Server spoofing vulnerability allowing unauthorized attackers to exploit via network access without authentication or user interaction. Listed in CISA KEV indicating active exploitation.
CVE ADDED: 2026-04-14
0 DAY BETWEEN CVE AND KEV
17 DAYS SINCE KEV
View Details →
Internet Exposure Likelihood: HIGH
CVSS: 9.1
Critical unauthenticated remote code execution vulnerability in Fortinet FortiClient EMS management server. Allows attackers to execute arbitrary code via crafted network requests without authentication.
CVE ADDED: 2026-04-04
2 DAYS BETWEEN CVE AND KEV
25 DAYS SINCE KEV
View Details →