Published CVEs
26557
NVD records in this 90-day window
Recent NVD vulnerabilities, enriched with CISA's known-exploitation signal and connected to the BLT University labs that teach the underlying weakness.
19 May 2026 – 16 Aug 2026
Generated 16 Aug 2026, 17:19 UTC
Published CVEs
26557
NVD records in this 90-day window
Mapped to OWASP
17230
64.9% classification coverage
Known exploited
44
Confirmed in the CISA KEV catalog
Critical severity
2586
CVSS critical among mapped records
NLP is reserved for records without a usable CWE. Every fallback is labeled with its method and confidence.
CVE record
NVD publication, CVSS, products
CWE weakness
Structured classification signal
OWASP Top 10
Curated educational grouping
BLT lab
Practice the defensive concept
Compare the most frequent categories, their share of classified CVEs, and how the leading categories change over time. Select any chart element to filter the learning map and CVE explorer below.
Top five categories
The category chart could not load. The same counts remain available in the category cards below.
Category share
Percentage of mapped records across every OWASP category.
The category-share chart could not load. The same counts remain available in the category cards below.
Monthly movement
Only fully covered calendar months are compared; partial months are excluded.
At least two complete calendar months are needed to draw a meaningful trend.
Practice object-level authorization checks. This recommendation balances current CVE activity, known exploitation, and your saved progress on this device.
Activity
6156 CVEs
Exploitation
9 CISA KEV
Your progress
0% complete
Progress stays in your browser and is never mixed into the shared vulnerability dataset.
Compare the vulnerability volume, exploitation signal, and labs available for each category.
6156 mapped CVEs
Authorization failures let users act outside their intended permissions or access resources they do not own.
Defend
Deny by default and enforce object- and function-level authorization on every request.
Recommended labs
456 mapped CVEs
Sensitive information is exposed when encryption, key management, or transport protection is missing or incorrectly implemented.
Defend
Minimize sensitive data, use modern cryptography, and protect data both at rest and in transit.
Recommended labs
5745 mapped CVEs
Untrusted data changes the meaning of a command, query, or document interpreted by another component.
Defend
Keep commands and data separate, validate input, and encode output for its exact context.
Recommended labs
1528 mapped CVEs
Missing or ineffective security controls in the design create weaknesses that implementation fixes alone cannot address.
Defend
Use threat modeling, abuse cases, secure design patterns, and verifiable security requirements.
Recommended labs
143 mapped CVEs
Unsafe defaults, unnecessary features, exposed diagnostics, and inconsistent hardening leave systems vulnerable.
Defend
Apply repeatable hardening, least functionality, safe defaults, and environment-specific configuration review.
Recommended labs
37 mapped CVEs
Applications inherit known risk from unsupported or vulnerable libraries, frameworks, and platforms.
Defend
Maintain an inventory, monitor disclosures, remove unused dependencies, and patch according to risk.
Recommended labs
1832 mapped CVEs
Weak identity, credential, and session controls let attackers impersonate users or retain unauthorized access.
Defend
Use strong authentication, secure recovery, rate limiting, and correctly managed sessions.
Recommended labs
689 mapped CVEs
Software updates, pipelines, and serialized data are trusted without sufficient integrity verification.
Defend
Verify provenance and integrity, protect delivery pipelines, and deserialize only trusted data safely.
Recommended labs
75 mapped CVEs
Insufficient security telemetry and response allow attacks to continue without detection or investigation.
Defend
Log security-relevant events without secrets, monitor them, and maintain tested response procedures.
Recommended labs
569 mapped CVEs
A server fetches an attacker-controlled destination without enforcing trusted network and protocol boundaries.
Defend
Allowlist destinations, validate resolved addresses, restrict protocols, and segment outbound network access.
Recommended labs
Known-exploited and high-severity records are surfaced first. Filter the educational shortlist without losing the NVD source trail.
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Learn the weakness
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrat...
Learn the weakness
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Learn the weakness
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Learn the weakness
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not r...
Learn the weakness
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Learn the weakness
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Learn the weakness
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Learn the weakness
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Learn the weakness
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Learn the weakness
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
Learn the weakness
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
Learn the weakness
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
Learn the weakness
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bas...
Learn the weakness
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Learn the weakness
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Learn the weakness
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Learn the weakness
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Learn the weakness
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Learn the weakness
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Learn the weakness
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTT...
Learn the weakness
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authenti...
Learn the weakness
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5...
Learn the weakness
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Learn the weakness
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ...
Learn the weakness
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before ...
Learn the weakness
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic s...
Learn the weakness
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to mo...
Learn the weakness
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerabil...
Learn the weakness
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Learn the weakness
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can explo...
Learn the weakness
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Learn the weakness
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected d...
Learn the weakness
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying th...
Learn the weakness
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Learn the weakness
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Learn the weakness
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Learn the weakness
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary command...
Learn the weakness
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Learn the weakness
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute a...
Learn the weakness
Try a broader search or clear one of the filters.