Critical vulnerability intelligence.
New critical security flaws land every day. Vulnary tells you what each one actually is, who it hits, how serious it really is, and the exact steps to shut it down.
Spiking now
what’s blowing upAn authentication bypass in Check Point SmartConsole lets an attacker obtain an admin login token without credentials. The flaw can be exploited remotely to change security policies and configurations. It is rated critical due to its high impact and ease of exploitation.
- added to CISA KEV
- EPSS jumped +57 pts
- 70% likely to be exploited
Ivanti Sentry software has a critical OS command injection flaw that lets anyone on the internet run commands as root. The vulnerability exists in versions before R10.5.2, R10.6.2, and R10.7.1. An attacker could take full control of the affected system.
- added to CISA KEV
- 100% likely to be exploited
A flaw in the WordPress REST API allows for route confusion, which can be combined with a separate SQL injection vulnerability. This combination allows an attacker to execute malicious commands on the server.
- added to CISA KEV
- 98% likely to be exploited
The feed (latest)
1,541 entriesAdd the software you run to see what affects you.