Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-64849
Known exploited
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
CVSS Score
9.3
EPSS Score
0.164
Published
2026-08-17
CVE-2026-73570
Known exploited
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS Score
8.9
EPSS Score
0.324
Published
2026-08-13
CVE-2026-42018
Known exploited
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVSS Score
7.5
EPSS Score
0.009
Published
2026-08-12
CVE-2026-66384
Known exploited
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVSS Score
5.3
EPSS Score
0.006
Published
2026-08-12
CVE-2026-68820
Known exploited
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.062
Published
2026-08-11
CVE-2026-20349
Known exploited
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
CVSS Score
8.6
EPSS Score
0.022
Published
2026-08-11
CVE-2026-72898
Known exploited
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
CVSS Score
10.0
EPSS Score
0.942
Published
2026-08-10
CVE-2026-65400
Known exploited
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVSS Score
9.8
EPSS Score
0.105
Published
2026-08-06
CVE-2026-18577
Known exploited
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
CVSS Score
8.2
EPSS Score
0.541
Published
2026-08-02
CVE-2026-18556
Known exploited
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
CVSS Score
8.2
EPSS Score
0.402
Published
2026-08-01


Contact Us

Shodan ® - All rights reserved