Vulnerability intelligence

From disclosure to hands-on learning.

Recent NVD vulnerabilities, enriched with CISA's known-exploitation signal and connected to the BLT University labs that teach the underlying weakness.

Dataset window live

19 May 2026 – 16 Aug 2026

Generated 16 Aug 2026, 17:19 UTC

Published CVEs

26557

NVD records in this 90-day window

Mapped to OWASP

17230

64.9% classification coverage

Known exploited

44

Confirmed in the CISA KEV catalog

Critical severity

2586

CVSS critical among mapped records

Classification path

Structured evidence first.

NLP is reserved for records without a usable CWE. Every fallback is labeled with its method and confidence.

16613 structured CWE 617 fallback 9327 unclassified
01

CVE record

NVD publication, CVSS, products

02

CWE weakness

Structured classification signal

03

OWASP Top 10

Curated educational grouping

04

BLT lab

Practice the defensive concept

Intelligence at a glance

See where vulnerability activity concentrates.

Compare the most frequent categories, their share of classified CVEs, and how the leading categories change over time. Select any chart element to filter the learning map and CVE explorer below.

Top five categories

Mapped CVEs by frequency

90-day window
The five most frequent OWASP vulnerability categories.

Category share

Classified CVE breakdown

Percentage of mapped records across every OWASP category.

Percentage breakdown of classified CVEs.

Monthly movement

Trend for the top three categories

Only fully covered calendar months are compared; partial months are excluded.

Month-over-month trends for the three leading categories.
Your next learning step A01 · Broken Access Control

Insecure Direct Object Reference

Practice object-level authorization checks. This recommendation balances current CVE activity, known exploitation, and your saved progress on this device.

Activity

6156 CVEs

Exploitation

9 CISA KEV

Your progress

0% complete

Recommended match Start learning

Progress stays in your browser and is never mixed into the shared vulnerability dataset.

Learning map

Vulnerabilities by OWASP category

Compare the vulnerability volume, exploitation signal, and labs available for each category.

A01

Broken Access Control

6156 mapped CVEs

+55.6%

Authorization failures let users act outside their intended permissions or access resources they do not own.

Defend

Deny by default and enforce object- and function-level authorization on every request.

Severity mix9 KEV
CWE-284CWE-862CWE-22CWE-200
A02

Cryptographic Failures

456 mapped CVEs

-8.3%

Sensitive information is exposed when encryption, key management, or transport protection is missing or incorrectly implemented.

Defend

Minimize sensitive data, use modern cryptography, and protect data both at rest and in transit.

Severity mix1 KEV
CWE-347CWE-327CWE-321CWE-338

Recommended labs

A03

Injection

5745 mapped CVEs

-2.4%

Untrusted data changes the meaning of a command, query, or document interpreted by another component.

Defend

Keep commands and data separate, validate input, and encode output for its exact context.

Severity mix13 KEV
CWE-79CWE-89CWE-20CWE-78
A04

Insecure Design

1528 mapped CVEs

+5.7%

Missing or ineffective security controls in the design create weaknesses that implementation fixes alone cannot address.

Defend

Use threat modeling, abuse cases, secure design patterns, and verifiable security requirements.

Severity mix6 KEV
CWE-269CWE-266CWE-434CWE-451
A05

Security Misconfiguration

143 mapped CVEs

+21.4%

Unsafe defaults, unnecessary features, exposed diagnostics, and inconsistent hardening leave systems vulnerable.

Defend

Apply repeatable hardening, least functionality, safe defaults, and environment-specific configuration review.

Severity mix0 KEV
CWE-611CWE-942CWE-614CWE-15
A06

Vulnerable and Outdated Components

37 mapped CVEs

-8.3%

Applications inherit known risk from unsupported or vulnerable libraries, frameworks, and platforms.

Defend

Maintain an inventory, monitor disclosures, remove unused dependencies, and patch according to risk.

Severity mix0 KEV
CWE-1104CWE-667CWE-400CWE-1321

Recommended labs

A07

Identification and Authentication Failures

1832 mapped CVEs

+43.5%

Weak identity, credential, and session controls let attackers impersonate users or retain unauthorized access.

Defend

Use strong authentication, secure recovery, rate limiting, and correctly managed sessions.

Severity mix8 KEV
CWE-306CWE-287CWE-346CWE-295

Recommended labs

A08

Software and Data Integrity Failures

689 mapped CVEs

-20.8%

Software updates, pipelines, and serialized data are trusted without sufficient integrity verification.

Defend

Verify provenance and integrity, protect delivery pipelines, and deserialize only trusted data safely.

Severity mix5 KEV
CWE-502CWE-345CWE-427CWE-829
A09

Security Logging and Monitoring Failures

75 mapped CVEs

-16.0%

Insufficient security telemetry and response allow attacks to continue without detection or investigation.

Defend

Log security-relevant events without secrets, monitor them, and maintain tested response procedures.

Severity mix0 KEV
CWE-532CWE-117CWE-778CWE-126

Recommended labs

A10

Server-Side Request Forgery

569 mapped CVEs

+70.9%

A server fetches an attacker-controlled destination without enforcing trusted network and protocol boundaries.

Defend

Allowlist destinations, validate resolved addresses, restrict protocols, and segment outbound network access.

Severity mix2 KEV
CWE-918CWE-367CWE-436CWE-1389
CVE explorer

High-signal vulnerabilities

Known-exploited and high-severity records are surfaced first. Filter the educational shortlist without losing the NVD source trail.

CVE-2026-72898

10 Aug 2026

CRITICAL · 10.0 CISA KEV
A03 Injection Structured CWE

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CWE-89 Metabase Metabase
CVE-2026-16812

27 Jul 2026

CRITICAL · 10.0 CISA KEV
A03 Injection Structured CWE

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrat...

CWE-78 Arista Velocloud Orchestrator
CVE-2026-15409

14 Jul 2026

CRITICAL · 10.0 CISA KEV
A10 Server-Side Request Forgery Structured CWE

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CWE-918 Sonicwall Sma6210 FirmwareSonicwall Sma6210

Learn the weakness

CVE-2026-56291

09 Jul 2026

CRITICAL · 10.0 CISA KEV
A04 Insecure Design Structured CWE

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CWE-434 Balbooa Forms
CVE-2026-48282

30 Jun 2026

CRITICAL · 10.0 CISA KEV
A01 Broken Access Control Structured CWE

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not r...

CWE-22 Adobe Coldfusion
CVE-2026-56290

29 Jun 2026

CRITICAL · 10.0 CISA KEV
A04 Insecure Design Structured CWE

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CWE-434 Joomlack Page Builder Ck
CVE-2026-48908

20 Jun 2026

CRITICAL · 10.0 CISA KEV
A04 Insecure Design Structured CWE

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CWE-434 Ollyo Sp Page Builder
CVE-2026-48939

20 Jun 2026

CRITICAL · 10.0 CISA KEV
A04 Insecure Design Structured CWE

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CWE-434 Joomlic Icagenda
CVE-2026-10520

09 Jun 2026

CRITICAL · 10.0 CISA KEV
A03 Injection Structured CWE

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

CWE-78 Ivanti Standalone Sentry
CVE-2026-48907

05 Jun 2026

CRITICAL · 10.0 CISA KEV
A01 Broken Access Control Structured CWE

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CWE-284 Widgetfactorylimited Jce
CVE-2026-34908

22 May 2026

CRITICAL · 10.0 CISA KEV
A01 Broken Access Control Structured CWE

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

CWE-284 Ui Unifi Os ServerUi Unifi Cloud Gateway Industrial Firmware
CVE-2026-34909

22 May 2026

CRITICAL · 10.0 CISA KEV
A01 Broken Access Control Structured CWE

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

CWE-22 Ui Unifi Os ServerUi Unifi Cloud Gateway Industrial Firmware
CVE-2026-34910

22 May 2026

CRITICAL · 10.0 CISA KEV
A03 Injection Structured CWE

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

CWE-20 Ui Unifi Os ServerUi Unifi Cloud Gateway Industrial Firmware
CVE-2026-48172

21 May 2026

CRITICAL · 10.0 CISA KEV
A04 Insecure Design Structured CWE

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bas...

CWE-266 Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed Whm Plugin
CVE-2026-63077

27 Jul 2026

CRITICAL · 9.8 CISA KEV
A08 Software and Data Integrity Failures Structured CWE

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CWE-502 Jetbrains Teamcity

Learn the weakness

CVE-2026-9198

17 Jul 2026

CRITICAL · 9.8 CISA KEV
A03 Injection Structured CWE

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

CWE-94 Langflow Langflow
CVE-2026-63030

17 Jul 2026

CRITICAL · 9.8 CISA KEV
A03 Injection Description fallback · 65%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

CWE-436 Wordpress Wordpress
CVE-2026-50522

14 Jul 2026

CRITICAL · 9.8 CISA KEV
A08 Software and Data Integrity Failures Structured CWE

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CWE-502 Microsoft Sharepoint Server

Learn the weakness

CVE-2026-56164

14 Jul 2026

CRITICAL · 9.8 CISA KEV
A07 Identification and Authentication Failures Structured CWE

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CWE-306 Microsoft Sharepoint Server

Learn the weakness

CVE-2026-58644

14 Jul 2026

CRITICAL · 9.8 CISA KEV
A08 Software and Data Integrity Failures Structured CWE

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CWE-502 Microsoft Sharepoint Server

Learn the weakness

CVE-2026-35273

11 Jun 2026

CRITICAL · 9.8 CISA KEV
A07 Identification and Authentication Failures Structured CWE

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTT...

CWE-306 Oracle Peoplesoft Enterprise Peopletools

Learn the weakness

CVE-2026-20253

10 Jun 2026

CRITICAL · 9.8 CISA KEV
A07 Identification and Authentication Failures Structured CWE

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authenti...

CWE-306 Splunk Splunk

Learn the weakness

CVE-2026-25089

09 Jun 2026

CRITICAL · 9.8 CISA KEV
A03 Injection Structured CWE

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5...

CWE-78 Fortinet FortisandboxFortinet Fortisandbox Cloud
CVE-2026-8037

04 Jun 2026

CRITICAL · 9.8 CISA KEV
A03 Injection Structured CWE

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

CWE-77 Progress Connection Manager For ObjectscaleProgress Ecs Connection Manager
CVE-2026-46817

28 May 2026

CRITICAL · 9.8 CISA KEV
A04 Insecure Design Structured CWE

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ...

CWE-269·CWE-287·CWE-306 Oracle E-Business Suite
CVE-2026-9082

20 May 2026

CRITICAL · 9.8 CISA KEV
A03 Injection Structured CWE

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before ...

CWE-89 Drupal Drupal
CVE-2026-48558

12 Jun 2026

CRITICAL · 9.5 CISA KEV
A02 Cryptographic Failures Structured CWE

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic s...

CWE-347 Simple-Help Simplehelp

Learn the weakness

CVE-2026-16232

22 Jul 2026

CRITICAL · 9.3 CISA KEV
A07 Identification and Authentication Failures Structured CWE

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to mo...

CWE-287 Checkpoint Multi-Domain Security ManagementCheckpoint Quantum Security Management

Learn the weakness

CVE-2026-12569

18 Jun 2026

CRITICAL · 9.3 CISA KEV
A03 Injection Structured CWE

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerabil...

CWE-20·CWE-502 Ptc FlexplmPtc Windchill Pdmlink
CVE-2026-50751

08 Jun 2026

CRITICAL · 9.3 CISA KEV
A07 Identification and Authentication Failures Structured CWE

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CWE-287 Checkpoint Gaia OsCheckpoint Gaia Embedded

Learn the weakness

CVE-2026-45247

26 May 2026

CRITICAL · 9.3 CISA KEV
A08 Software and Data Integrity Failures Structured CWE

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can explo...

CWE-502 Mirasvit Full Page Cache Warmer

Learn the weakness

CVE-2026-45659

22 May 2026

HIGH · 8.8 CISA KEV
A08 Software and Data Integrity Failures Structured CWE

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CWE-502 Microsoft Sharepoint Server

Learn the weakness

CVE-2026-20230

03 Jun 2026

HIGH · 8.6 CISA KEV
A10 Server-Side Request Forgery Structured CWE

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected d...

CWE-918 Cisco Unified Communications Manager

Learn the weakness

CVE-2026-55255

23 Jun 2026

HIGH · 8.4 CISA KEV
A01 Broken Access Control Structured CWE

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying th...

CWE-639 Langflow Langflow
CVE-2026-18577

02 Aug 2026

HIGH · 8.2 CISA KEV
A07 Identification and Authentication Failures Structured CWE

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CWE-288 N-Able N-Central

Learn the weakness

CVE-2026-18556

01 Aug 2026

HIGH · 8.2 CISA KEV
A07 Identification and Authentication Failures Structured CWE

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CWE-288 N-Able N-Central

Learn the weakness

CVE-2026-56155

14 Jul 2026

HIGH · 7.8 CISA KEV
A01 Broken Access Control Description fallback · 65%

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CWE-1220 Microsoft Windows 10 1607Microsoft Windows 10 1809
CVE-2026-20245

04 Jun 2026

HIGH · 7.8 CISA KEV
A03 Injection Structured CWE

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary command...

CWE-116 Cisco Catalyst Sd-Wan ManagerCisco Sd-Wan Vsmart Controller
CVE-2026-15410

14 Jul 2026

HIGH · 7.2 CISA KEV
A03 Injection Structured CWE

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute a...

CWE-94 Sonicwall Sma6210 FirmwareSonicwall Sma6210