UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 18)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-58048
CPanel SQL injection lets low-privilege users run SQL as rootCRITICAL 9.4
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-77179
Docker Sandboxes virtio-fs symlink escape to host code executionCRITICAL 9.4
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-14382
Chrome ANGLE sandbox escape via crafted HTMLCRITICAL 9.6
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-76036
Chrome Dawn buffer overflow remote code executionCRITICAL 9.6
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-78904
Chrome ANGLE type confusion remote code executionCRITICAL 9.6
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-87492
Chrome DevTools incorrect authorization allows remote code executionCRITICAL 9.6
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-12944
Langflow OSS remote code execution as root via component importsCRITICAL 9.6
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-19295
Langflow OSS authenticated OS command execution via crafted flowCRITICAL 9.9
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-67401
CPanel EmailTrack SQL injection remote code executionCRITICAL 9.9
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-14802 HIGH 7.3
-
CVE-2026-18556
N-central authentication bypass via alternate path (pre-auth)HIGH 7.4
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2023-4346
KNX Protocol Connection Authorization Option 1 account lockout vulnerabilityHIGH 7.5
- CISA KEV
- EXPLOITED
-
CVE-2026-42018
Artifactory improper authentication returns internal anonymous tokenHIGH 7.5
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
- CVE-2026-73633 HIGH 7.5
-
CVE-2026-65343
IOS and iPadOS use-after-free causes remote denial of serviceHIGH 7.5
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-63072
OpenSSL CMS heap out-of-bounds write via CMS_decryptHIGH 7.5
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-84543
MacOS out-of-bounds SMB client access from a remote serverHIGH 7.5
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-42533
NGINX Plus heap buffer overflow with regex map leading to remote code executionHIGH 8.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2021-27137
DD-WRT UPnP stack buffer overflow allows remote code executionHIGH 8.1
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-63520
Microsoft SharePoint Enterprise Server 2016 improper input validation RCEHIGH 8.1
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 18 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.