← Back to News Iceland Security Dashboard Browse all tags
T1190

Exploit Public-Facing App

View on attack.mitre.org →

CVEs tagged with this technique (50)

CVE-2026-20182 🚨 CVSS 10.0 Cisco / Catalyst SD-WAN
CVE-2026-20182 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager, allowing unauthenticated remote attackers to o…
CVE-2026-20127 🚨 CVSS 10.0 Cisco / Catalyst SD-WAN Controller and Manager
CVE-2026-20127 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager that allows unauthenticated remote attackers to…
CVE-2026-34908 🚨 CVSS 10.0 Ubiquiti / UniFi OS
CVE-2026-34908 is a critical (CVSS 10.0) Improper Access Control vulnerability (CWE-284) affecting UniFi OS devices. It allows a malicious actor with network ac…
CVE-2026-34909 🚨 CVSS 10.0 Ubiquiti / UniFi OS
UniFi OS devices are affected by a critical Path Traversal vulnerability (CWE-22) with a CVSS score of 10.0. A malicious actor with network access can exploit t…
CVE-2026-34910 🚨 CVSS 10.0 Ubiquiti / UniFi OS
CVE-2026-34910 is a critical command injection vulnerability in UniFi OS devices caused by improper input validation. The vulnerability has a CVSS v3.1 score of…
CVE-2026-10520 🚨 CVSS 10.0 Ivanti / Sentry
CVE-2026-10520 is a critical OS Command Injection vulnerability (CWE-78) in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. It allows a remote un…
CVE-2026-20131 🚨 CVSS 10.0 Cisco / Secure Firewall Management Center (FMC)
CVE-2026-20131 is an actively exploited vulnerability in Cisco Secure Firewall Management Center (FMC) listed on CISA's Known Exploited Vulnerabilities catalog.…
CVE-2026-21643 🚨 CVSS 9.8 Fortinet / FortiClient EMS
CVE-2026-21643 is a critical SQL injection vulnerability (CWE-89) in Fortinet FortiClientEMS 7.4.4, allowing unauthenticated attackers to execute unauthorized c…
CVE-2026-41940 🚨 CVSS 9.8 WebPros / cPanel & WHM and WP2 (WordPress Squared)
CVE-2026-41940 is a critical authentication bypass vulnerability (CWE-306) affecting cPanel and WHM versions after 11.40, allowing unauthenticated remote attack…
CVE-2026-0300 🚨 CVSS 9.8 Palo Alto Networks / PAN-OS
CVE-2026-0300 is a critical buffer overflow vulnerability (CWE-787) in the User-ID Authentication Portal of Palo Alto Networks PAN-OS, allowing unauthenticated …
CVE-2026-42208 🚨 CVSS 9.8 BerriAI / LiteLLM
CVE-2026-42208 is a critical SQL injection vulnerability (CWE-89) in LiteLLM versions 1.81.16 through 1.83.6, where unauthenticated attackers can inject malicio…
CVE-2026-8398 🚨 CVSS 9.8 Daemon / Daemon Tools Lite
CVE-2026-8398 is a critical supply chain vulnerability (CWE-506) affecting DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, where attackers trojanize…
CVE-2026-45247 🚨 CVSS 9.8 Mirasvit / Mirasvit Full Page Cache Warmer
CVE-2026-45247 is a critical remote code execution vulnerability in Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12. The flaw stems from…
CVE-2026-1340 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1340 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-35616 🚨 CVSS 9.8 Fortinet / FortiClient EMS
CVE-2026-35616 is a critical improper access control vulnerability (CWE-284) in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6, allowing unauthenticated a…
CVE-2026-25089 🚨 CVSS 9.8 Fortinet / FortiSandbox
CVE-2026-25089 is a critical OS command injection vulnerability (CWE-78) affecting Fortinet FortiSandbox versions 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, 4.2,…
CVE-2026-35273 🚨 CVSS 9.8 Oracle / PeopleSoft Enterprise PeopleTools
CVE-2026-35273 is a critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, specifically within the Updates Environment Manag…
CVE-2026-39808 🚨 CVSS 9.8 Fortinet / FortiSandbox
Fortinet FortiSandbox versions 4.4.0 through 4.4.8 contain a critical OS command injection vulnerability (CWE-78) allowing unauthorized code execution. The vuln…
CVE-2026-56290 🚨 CVSS 9.8 Joomlack / Page Builder
CVE-2026-56290 is a critical vulnerability in the Joomla extension Page Builder CK, allowing unauthenticated attackers to upload arbitrary executable files. Thi…
CVE-2026-56291 🚨 CVSS 9.8 Balbooa / Forms
CVE-2026-56291 is a critical remote code execution vulnerability in the Balbooa Forms Joomla extension, classified under CWE-434 (Open File Upload). It allows u…
CVE-2026-24858 🚨 CVSS 9.8 Fortinet / Multiple Products
CVE-2026-24858 is a critical authentication bypass vulnerability (CWE-288) affecting multiple Fortinet products including FortiAnalyzer, FortiManager, FortiOS, …
CVE-2026-1281 🚨 CVSS 9.8 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-1281 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-45321 🚨 CVSS 9.6 TanStack / TanStack
CVE-2026-45321 is a critical supply-chain vulnerability affecting 42 TanStack packages, including TanStack/router, where 84 malicious versions were published to…
CVE-2026-50751 🚨 CVSS 9.3 Check Point / Security Gateway
CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point Security Gateway affecting the deprecated IKEv1 key exchange. It allows unauthen…
CVE-2026-16232 🚨 CVSS 9.1 Check Point / SmartConsole
CVE-2026-16232 is a critical authentication bypass vulnerability in Check Point SmartConsole that allows unauthenticated remote attackers to obtain administrati…
CVE-2026-5281 🚨 CVSS 8.8 Google / Dawn
CVE-2026-5281 is a high-severity memory corruption vulnerability (CWE-416) in Google's Dawn component, affecting versions prior to 146.0.7680.178. It involves a…
CVE-2026-25108 🚨 CVSS 8.8 Soliton Systems K.K / FileZen
CVE-2026-25108 is a command injection vulnerability in Soliton Systems K.K.'s FileZen product, specifically affecting the Antivirus Check Option when enabled. I…
CVE-2026-2441 🚨 CVSS 8.8 Google / Chromium
CVE-2026-2441 is a high-severity memory corruption vulnerability (CWE-416) in Google Chrome prior to version 145.0.7632.75, specifically involving a use-after-f…
CVE-2026-34197 🚨 CVSS 8.8 Apache / ActiveMQ
CVE-2026-34197 is a high-severity code injection vulnerability in Apache ActiveMQ (versions before 5.19.4 and 6.0.0-6.2.3) caused by improper input validation i…
CVE-2026-42271 🚨 CVSS 8.8 BerriAI / LiteLLM
CVE-2026-42271 is a command injection vulnerability in LiteLLM versions 1.74.2 through 1.83.6 affecting the MCP server preview endpoints. The flaw allows any au…
CVE-2026-11645 🚨 CVSS 8.8 Google / Chromium V8
CVE-2026-11645 is a high-severity memory corruption vulnerability (CWE-125, CWE-787) in Google Chrome prior to version 149.0.7827.103, affecting the V8 engine. …
CVE-2026-34621 🚨 CVSS 8.6 Adobe / Acrobat and Reader
Adobe Acrobat Reader versions 24.001.30356, 26.001.21367, and earlier are affected by a Prototype Pollution vulnerability (CWE-1321) that allows for arbitrary c…
CVE-2026-20230 🚨 CVSS 8.6 Cisco / Unified Communications Manager
CVE-2026-20230 is a critical server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager and Unified CM SME due to improper input v…
CVE-2026-1603 🚨 CVSS 8.6 Ivanti / Endpoint Manager (EPM)
CVE-2026-1603 is a high-severity authentication bypass vulnerability in Ivanti Endpoint Manager versions prior to 2024 SU5, allowing remote unauthenticated atta…
CVE-2026-54420 🚨 CVSS 8.5 LiteSpeed / cPanel Plugin
CVE-2026-54420 affects the LiteSpeed cPanel plugin before version 2.4.8, specifically when distributed in LiteSpeed WHM PlugIn before 5.3.2.0, due to mishandlin…
CVE-2026-22719 🚨 CVSS 8.1 Broadcom / VMware Aria Operations
CVE-2026-22719 is a high-severity command injection vulnerability (CWE-77) in VMware Aria Operations that allows unauthenticated remote code execution during su…
CVE-2026-3502 🚨 CVSS 7.8 TrueConf / Client
CVE-2026-3502 is a supply-chain vulnerability in TrueConf Client where the application downloads and applies updates without verification, allowing an attacker …
CVE-2026-20245 🚨 CVSS 7.8 Cisco / Catalyst SD-WAN Manager
CVE-2026-20245 is a command injection vulnerability in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) caused by insufficient validation of u…
CVE-2026-20128 🚨 CVSS 7.5 Cisco / Catalyst SD-WAN Manager
CVE-2026-20128 is a high-severity vulnerability in Cisco Catalyst SD-WAN Manager affecting versions prior to 20.18, allowing unauthenticated remote attackers to…
CVE-2026-6973 🚨 CVSS 7.2 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-6973 is a high-severity (CVSS 7.2) remote code execution vulnerability in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, caused by imp…
CVE-2026-20262 🚨 CVSS 6.5 Cisco / Catalyst SD-WAN Manager
CVE-2026-20262 is a path traversal vulnerability in Cisco Catalyst SD-WAN Manager that allows authenticated attackers to overwrite arbitrary files on the underl…
CVE-2025-68686 🚨 CVSS 5.9 Fortinet / FortiOS
CVE-2025-68686 is a medium severity (CVSS 5.9) information disclosure vulnerability in Fortinet FortiOS versions 7.6.0-7.6.1, 7.4.0-7.4.6, and all versions of 7…
CVE-2026-20122 🚨 CVSS 5.4 Cisco / Catalyst SD-WAN Manger
CVE-2026-20122 is a medium severity vulnerability (CVSS 5.4) in Cisco Catalyst SD-WAN Manager affecting the API interface. It allows authenticated attackers wit…
CVE-2026-32202 🚨 Microsoft / Windows
CVE-2026-32202 is a vulnerability in Microsoft Windows that is currently listed on CISA's Known Exploited Vulnerabilities catalog as actively exploited in the w…
CVE-2025-29635 🚨 D-Link / DIR-823X
CVE-2025-29635 is a command injection vulnerability (CWE-77) affecting D-Link DIR-823X firmware versions 240126 and 240802, allowing authorized attackers to exe…
CVE-2025-32975 🚨 Quest / KACE Systems Management Appliance (SMA)
CVE-2025-32975 is a critical authentication bypass vulnerability (CVSS 10.0) in Quest KACE Systems Management Appliance versions 13.0.x through 14.1.x, allowing…
CVE-2009-0238 🚨 Microsoft / Office
CVE-2009-0238 is a remote code execution vulnerability affecting Microsoft Office Excel versions 2000 through 2007 and Excel Viewer, caused by an invalid object…
CVE-2012-1854 🚨 Microsoft / Visual Basic for Applications (VBA)
CVE-2012-1854 is an untrusted search path vulnerability affecting Microsoft Office 2003 SP3, 2007 SP2/SP3, 2010 Gold/SP1, and the Summit Microsoft Visual Basic …
CVE-2020-9715 🚨 Adobe / Acrobat
CVE-2020-9715 is a use-after-free vulnerability (CWE-416) affecting Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171…
CVE-2026-33634 🚨 Aquasecurity / Trivy
CVE-2026-33634 involves a supply chain attack against Aquasecurity's Trivy ecosystem, where compromised credentials were used to publish malicious versions of t…

Articles tagged with T1190 (30)

HIGH
Coding Agent Horror Stories: The 29 Million Secret Problem
Docker Blog · 2026-07-28
HIGH
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Infosecurity Magazine · 2026-07-28
HIGH
Exposed BMCs hand out password hashes before login
Help Net Security · 2026-07-28
CRITICAL
[NEU] [hoch] Apache Airflow FAB provider: Schwachstelle ermöglicht Erlangen von Administratorrechten
BSI Germany · 2026-07-28
HIGH
USN-8621-1: Samba vulnerabilities
Ubuntu Security · 2026-07-28
HIGH
[NEU] [hoch] JFrog Artifactory: Mehrere Schwachstellen
BSI Germany · 2026-07-28
HIGH
Vatican’s Click To Pray app exposed personal data from 700,000 users
Malwarebytes Labs · 2026-07-28
CRITICAL
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
Help Net Security · 2026-07-28
HIGH
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Infosecurity Magazine · 2026-07-28
MEDIUM
[NEU] [mittel] Apache Wicket: Mehrere Schwachstellen
BSI Germany · 2026-07-28
MEDIUM
[NEU] [mittel] Apple Safari: Mehrere Schwachstellen
BSI Germany · 2026-07-28
HIGH
[NEU] [hoch] Progress Software LoadMaster und MOVEit WAF: Mehrere Schwachstellen
BSI Germany · 2026-07-28
CRITICAL
[NEU] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellen
BSI Germany · 2026-07-28
MEDIUM
[NEU] [mittel] Devolutions Server: Mehrere Schwachstellen
BSI Germany · 2026-07-28
MEDIUM
[NEU] [mittel] Flowise: Mehrere Schwachstellen
BSI Germany · 2026-07-28
CRITICAL
[NEU] [hoch] Apache Axis2: Schwachstelle ermöglicht Codeausführung
BSI Germany · 2026-07-28
HIGH
[NEU] [hoch] GIMP Plugins: Mehrere Schwachstellen
BSI Germany · 2026-07-28
HIGH
[NEU] [hoch] OpenCTI: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
BSI Germany · 2026-07-28
HIGH
[NEU] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellen
BSI Germany · 2026-07-28
CRITICAL
[NEU] [hoch] Microsoft Azure Portal: Schwachstelle ermöglicht Offenlegung von Informationen
BSI Germany · 2026-07-28
CRITICAL
[NEU] [hoch] JetBrains TeamCity: Schwachstelle ermöglicht Codeausführung
BSI Germany · 2026-07-28
CRITICAL
[NEU] [hoch] Erlang/OTP: Mehrere Schwachstellen
BSI Germany · 2026-07-28
HIGH
[NEU] [mittel] Netty: Schwachstelle ermöglicht Denial of Service
BSI Germany · 2026-07-28
HIGH
[NEU] [mittel] Moodle: Schwachstelle ermöglicht Offenlegung von Informationen
BSI Germany · 2026-07-28
HIGH
[NEU] [mittel] Apache ActiveMQ: Mehrere Schwachstellen
BSI Germany · 2026-07-28
HIGH
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Cisco Talos · 2026-07-28
CRITICAL
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
The Register Security · 2026-07-28
MEDIUM
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Help Net Security · 2026-07-28
HIGH
NCSC-2026-0266 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS
NCSC Netherlands · 2026-07-28
CRITICAL
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
The Hacker News · 2026-07-28