UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 19)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-59822
LiteLLM improper authentication allows unauthenticated MCP session creationHIGH 8.2
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- CVE-2026-15583 HIGH 8.6
- CVE-2026-48019 HIGH 8.9
- CVE-2026-15733 CRITICAL 9.8
-
CVE-2026-72530
TrueConf Server code injection allows remote unauthenticated code executionCRITICAL 9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2021-23758
Ajax.NET Professional deserialization pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2023-49105
OwnCloud pre-auth improper authentication lets attackers modify or delete filesCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2025-39682
Linux Kernel TLS zero-length record handling leads to remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-46817
Oracle E-Business Suite Payments unauthenticated takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-48939
ICagenda file upload leads to remote PHP code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-48908
SP Page Builder unrestricted file upload leads to remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-56290
Page Builder unauthenticated file upload leading to remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-72529
TrueConf Server missing-authentication remote script execution via port 4307CRITICAL 9.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-81578
PaperCut NG/MF missing authentication lets unauthenticated remote modify configsCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-86218
N-central pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-49869
Kestra OSS unauthenticated remote code executionCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-48282
ColdFusion path traversal pre-auth remote code executionCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-16812
VeloCloud Orchestrator pre-auth command injection in on‑prem VCOCRITICAL 10
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-5430
WSO2 Multiple Products JWT verification bypass remote code executionCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-93952 CRITICAL 10
No CVEs on this page match the filters.
20 CVEs · page 19 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.