RSS Parrot

BETA

🦜 Aggregated Known Exploited Vulnerabilities Catalogs

@vulnerability.circl.lu.kev-catalogs@rss-parrot.net

I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline! Brought to you by the RSS Parrot.

---

Aggregated feed of KEV entries across all catalogs explorable via this instance, conforming to GCVE BCP-07. Contains the most recent 20 entries.

Your feed and you don't want it here? Just e-mail the birb.

Site URL: vulnerability.circl.lu/kev-catalogs

Feed URL: vulnerability.circl.lu/kev-catalogs/feed.rss

Posts: 35

Followers: 1

[KEVIntel] CVE-2026-63077 - Confirmed Exploitation

Published: August 5, 2026 16:50

CVE-2026-63077 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-05 16:50 UTC Evidence Sources: 1 First Seen: 2026-08-05 Asserted: 2026-08-05 Scope Notes: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code…

[KEVIntel] CVE-2025-8943 - Confirmed Exploitation

Published: August 5, 2026 08:45

CVE-2025-8943 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-05 08:45 UTC Evidence Sources: 1 First Seen: 2026-08-05 Asserted: 2026-08-05 Scope Notes: Unsupervised OS command execution leads to remote code execution by…

[KEVIntel] CVE-2026-9198 - Confirmed Exploitation

Published: August 4, 2026 16:45

CVE-2026-9198 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-04 16:45 UTC Evidence Sources: 1 First Seen: 2026-08-04 Asserted: 2026-08-04 Scope Notes: Unauthenticated Remote Code Execution via Auto-Login Bypass and Code…

[KEVIntel] CVE-2026-34486 - Confirmed Exploitation

Published: August 4, 2026 16:45

CVE-2026-34486 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-04 16:45 UTC Evidence Sources: 1 First Seen: 2026-08-04 Asserted: 2026-08-04 Scope Notes: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor |…

[KEVIntel] CVE-2026-48313 - Confirmed Exploitation

Published: August 4, 2026 10:48

CVE-2026-48313 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-04 10:48 UTC Evidence Sources: 1 First Seen: 2026-08-04 Asserted: 2026-08-04 Scope Notes: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory…

[KEVIntel] CVE-2026-18577 - Confirmed Exploitation

Published: August 3, 2026 18:55

CVE-2026-18577 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-03 18:55 UTC Evidence Sources: 1 First Seen: 2026-08-03 Asserted: 2026-08-03 Scope Notes: Incomplete patch leads to administrative account takeover | Affected: N-able…

[CISA] CVE-2026-18577 - Confirmed Exploitation

Published: August 3, 2026 00:00

CVE-2026-18577 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-08-03 00:00 UTC Evidence Sources: 1 First Seen: 2026-08-03 Asserted: 2026-08-03 Scope Notes: N-able N-central Authentication Bypass Using an Alternate Path or Channel…

[KEVIntel] CVE-2025-71324 - Confirmed Exploitation

Published: August 2, 2026 00:00

CVE-2025-71324 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-02 00:00 UTC Evidence Sources: 1 First Seen: 2026-08-02 Asserted: 2026-08-02 Scope Notes: Flowise - Arbitrary File Read via chatId Parameter | Affected: Flowise /…

[KEVIntel] CVE-2023-2825 - Confirmed Exploitation

Published: August 2, 2026 00:00

CVE-2023-2825 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-02 00:00 UTC Evidence Sources: 1 First Seen: 2026-08-02 Asserted: 2026-08-02 Scope Notes: An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.…

[KEVIntel] CVE-2023-54359 - Confirmed Exploitation

Published: August 2, 2026 00:00

CVE-2023-54359 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-02 00:00 UTC Evidence Sources: 1 First Seen: 2026-08-02 Asserted: 2026-08-02 Scope Notes: WordPress adivaha Travel Plugin 2.3 SQL Injection via pid | Affected:…

[KEVIntel] CVE-2026-18556 - Confirmed Exploitation

Published: August 1, 2026 13:51

CVE-2026-18556 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-01 13:51 UTC Evidence Sources: 1 First Seen: 2026-08-01 Asserted: 2026-08-01 Scope Notes: Unauthenticated administrative account takeover | Affected: N-able /…

[KEVIntel] CVE-2024-37014 - Confirmed Exploitation

Published: August 1, 2026 10:55

CVE-2024-37014 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-08-01 10:55 UTC Evidence Sources: 1 First Seen: 2026-08-01 Asserted: 2026-08-01 Scope Notes: Langflow through 0.6.19 allows remote code execution if untrusted users are…

[KEVIntel] CVE-2026-59800 - Confirmed Exploitation

Published: July 31, 2026 00:00

CVE-2026-59800 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-31 00:00 UTC Evidence Sources: 1 First Seen: 2026-07-31 Asserted: 2026-07-31 Scope Notes: 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in…

[KEVIntel] CVE-2021-1472 - Confirmed Exploitation

Published: July 30, 2026 15:50

CVE-2021-1472 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-30 15:50 UTC Evidence Sources: 1 First Seen: 2026-07-30 Asserted: 2026-07-30 Scope Notes: Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco /…

[KEVIntel] CVE-2019-8942 - Confirmed Exploitation

Published: July 30, 2026 10:42

CVE-2019-8942 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-30 10:42 UTC Evidence Sources: 1 First Seen: 2026-07-30 Asserted: 2026-07-30 Scope Notes: WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution…

[KEVIntel] CVE-2026-1623 - Confirmed Exploitation

Published: July 30, 2026 05:53

CVE-2026-1623 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-30 05:53 UTC Evidence Sources: 1 First Seen: 2026-07-30 Asserted: 2026-07-30 Scope Notes: Totolink A7000R cstecgi.cgi setUpgradeFW command injection | Affected:…

[KEVIntel] CVE-2026-20316 - Confirmed Exploitation

Published: July 29, 2026 18:45

CVE-2026-20316 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-29 18:45 UTC Evidence Sources: 1 First Seen: 2026-07-29 Asserted: 2026-07-29 Scope Notes: Cisco Secure Firewall Management Center Software Static Credential…

[CIRCL] CVE-2026-16232 - Confirmed Exploitation

Published: July 29, 2026 08:41

CVE-2026-16232 Catalog: CIRCL Status: Confirmed Exploited: Yes Status Updated: 2026-07-29 08:41 UTC Characteristics: Remote Access First Seen: 2026-07-29 Asserted: 2026-07-29

[KEVIntel] CVE-2025-71334 - Confirmed Exploitation

Published: July 28, 2026 12:54

CVE-2025-71334 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-28 12:54 UTC Evidence Sources: 1 First Seen: 2026-07-28 Asserted: 2026-07-28 Scope Notes: Flowise - Arbitrary File Access via Missing Chat Flow ID Validation |…

[KEVIntel] CVE-2025-68686 - Confirmed Exploitation

Published: July 27, 2026 17:00

CVE-2025-68686 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 17:00 UTC Evidence Sources: 1 First Seen: 2026-07-27 Asserted: 2026-07-27 Scope Notes: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability…

[KEVIntel] CVE-2026-16812 - Confirmed Exploitation

Published: July 27, 2026 16:20

CVE-2026-16812 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 16:20 UTC Evidence Sources: 1 First Seen: 2026-07-27 Asserted: 2026-07-27 Scope Notes: VeloCloud Orchestrator OS Command Injection | Affected: Arista Networks /…

[KEVIntel] CVE-2026-58138 - Confirmed Exploitation

Published: July 27, 2026 10:20

CVE-2026-58138 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 10:20 UTC Evidence Sources: 1 First Seen: 2026-07-27 Asserted: 2026-07-27 Scope Notes: Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script…

[CISA] CVE-2026-16812 - Confirmed Exploitation

Published: July 27, 2026 00:00

CVE-2026-16812 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 00:00 UTC Evidence Sources: 1 First Seen: 2026-07-27 Asserted: 2026-07-27 Scope Notes: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability |…

[Shadowserver] CVE-2026-2699 - Confirmed Exploitation

Published: July 27, 2026 00:00

CVE-2026-2699 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 00:00 UTC Characteristics: Severity: 98 Evidence Sources: 1 First Seen: 2026-07-10 Asserted: 2026-07-10 Scope Notes: Affected: Progress / Citrix ShareFile…

[CISA] CVE-2025-68686 - Confirmed Exploitation

Published: July 27, 2026 00:00

CVE-2025-68686 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 00:00 UTC Evidence Sources: 1 First Seen: 2026-07-27 Asserted: 2026-07-27 Scope Notes: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor…

[Shadowserver] CVE-2026-42271 - Confirmed Exploitation

Published: July 27, 2026 00:00

CVE-2026-42271 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 00:00 UTC Characteristics: Severity: 88 Evidence Sources: 1 First Seen: 2026-07-06 Asserted: 2026-07-06 Scope Notes: Affected: LiteLLM / LiteLLM | Class:…

[Shadowserver] CVE-2026-1207 - Confirmed Exploitation

Published: July 27, 2026 00:00

CVE-2026-1207 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 00:00 UTC Characteristics: Severity: 88 Evidence Sources: 1 First Seen: 2026-07-06 Asserted: 2026-07-06 Scope Notes: Affected: Django / Django RasterField |…

[Shadowserver] CVE-2025-68493 - Confirmed Exploitation

Published: July 27, 2026 00:00

CVE-2025-68493 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-27 00:00 UTC Characteristics: Severity: 81 Evidence Sources: 1 First Seen: 2026-07-20 Asserted: 2026-07-20 Scope Notes: Affected: Apache / Struts | Class:…

[Shadowserver] CVE-2026-22679 - Confirmed Exploitation

Published: July 26, 2026 00:00

CVE-2026-22679 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-26 00:00 UTC Characteristics: Severity: 98 Evidence Sources: 1 First Seen: 2026-07-19 Asserted: 2026-07-19 Scope Notes: Affected: Weaver / Weaver E-cology |…

[Shadowserver] CVE-2026-4631 - Confirmed Exploitation

Published: July 26, 2026 00:00

CVE-2026-4631 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-26 00:00 UTC Characteristics: Severity: 98 Evidence Sources: 1 First Seen: 2026-07-08 Asserted: 2026-07-08 Scope Notes: Affected: Cockpit / Cockpit | Class:…

[Shadowserver] CVE-2026-34910 - Confirmed Exploitation

Published: July 26, 2026 00:00

CVE-2026-34910 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-26 00:00 UTC Characteristics: Severity: 100 Evidence Sources: 1 First Seen: 2026-07-06 Asserted: 2026-07-06 Scope Notes: Affected: Ubiquiti / Ubiquiti UniFi |…

[Shadowserver] CVE-2022-50992 - Confirmed Exploitation

Published: July 26, 2026 00:00

CVE-2022-50992 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-26 00:00 UTC Characteristics: Severity: 75 Evidence Sources: 1 First Seen: 2026-07-06 Asserted: 2026-07-06 Scope Notes: Affected: Weaver / Weaver E-cology |…

[Shadowserver] CVE-2023-39361 - Confirmed Exploitation

Published: July 26, 2026 00:00

CVE-2023-39361 Catalog: Shadowserver Status: Confirmed Exploited: Yes Status Updated: 2026-07-26 00:00 UTC Characteristics: Severity: 98 Evidence Sources: 1 First Seen: 2026-07-06 Asserted: 2026-07-06 Scope Notes: Affected: Cacti / Cacti | Class:…

[KEVIntel] CVE-2014-2383 - Confirmed Exploitation

Published: July 25, 2026 11:07

CVE-2014-2383 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-25 11:07 UTC Evidence Sources: 1 First Seen: 2026-07-25 Asserted: 2026-07-25 Scope Notes: dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows…

[KEVIntel] CVE-2026-16723 - Confirmed Exploitation

Published: July 25, 2026 02:23

CVE-2026-16723 Catalog: KEVIntel Status: Confirmed Exploited: Yes Status Updated: 2026-07-25 02:23 UTC Evidence Sources: 1 First Seen: 2026-07-25 Asserted: 2026-07-25 Scope Notes: Remote Code Execution in fastjson 1.2.68–1.2.83 | Affected: Alibaba /…