Top 10 CVE's Trending op Sociale Media

Bijgewerkt: 25 maart 2026 | Bron: CVEmon (Intruder.io) | Data: Shodan CVEDB, CISA KEV, FIRST EPSS

#1
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
CVSS 7.5 HOOG EPSS 71.0% (P99) β†’ KEV: Nee Hype: 26
#2
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and T...
CVSS 8.8 HOOG EPSS 35.2% (P97) β†’ KEV: Nee Hype: 21
#3
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains ...
CVSS 10.0 KRITIEK EPSS 0.1% (P38) β†’ KEV: Nee Hype: 12
#4
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12. Processing a malicious image file may ...
CVSS 10.0 KRITIEK EPSS 0.5% (P68) β†’ KEV: Ja Hype: 12
#5
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated ac...
CVSS 7.5 HOOG EPSS 0.1% (P21) β†’ KEV: Nee Hype: 9
#6
AnΒ Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2....
CVSS 9.8 KRITIEK EPSS 94.2% (P100) β†’ KEV: Ja Ransomware Hype: 6
#7
Secure Boot Security Feature Bypass Vulnerability
CVSS 6.7 MIDDEL EPSS 0.6% (P69) β†’ KEV: Nee Hype: 4
#8
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to...
CVSS 10.0 KRITIEK EPSS 89.4% (P100) ↑ KEV: Ja Hype: 2
#9
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, rea...
CVSS 10.0 KRITIEK EPSS 65.1% (P98) ↓ KEV: Ja Ransomware Hype: 1
#10
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciousl...
CVSS 8.8 HOOG EPSS 0.3% (P50) β†’ KEV: Ja Hype: 1
Legenda: CVSS = ernst-score (0-10): 9.0-10 Kritiek 7.0-8.9 Hoog 4.0-6.9 Middel 0.1-3.9 Laag | EPSS = kans op exploitatie (FIRST.org) | KEV = CISA Known Exploited Vulnerabilities | Hype = trending score op sociale media