Critical vulnerability intelligence.
New critical security flaws land every day. Vulnary tells you what each one actually is, who it hits, how serious it really is, and the exact steps to shut it down.
Spiking now
what’s blowing upCVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that lets unauthenticated attackers access restricted functions or data. It has a CVSS score of 9.8 and is known exploitation. CISA advises applying vendor-provided mitigations or discontinuing use of the product if mitigations are not available.
- added to CISA KEV
- 100% likely to be exploited
Microsoft SharePoint Server is vulnerable to a critical deserialization flaw that lets attackers run arbitrary code over the network. The flaw affects on‑premises SharePoint Server 2016 and 2019, and any public‑facing instances that are no longer supported. Microsoft is testing a fix, but users should apply the mitigations outlined by CISA and disconnect unsupported servers.
- added to CISA KEV
- 100% likely to be exploited
Rejetto HTTP File Server up to version 2.3m contains a critical template injection flaw that lets attackers run arbitrary commands on the server. The vulnerability is remote, requires no authentication or user interaction, and is no longer supported by the vendor.
- added to CISA KEV
- 99% likely to be exploited
The feed (latest)
2,506 entriesAdd the software you run to see what affects you.