PatchSiren

PatchSiren public CVE debriefs

Critical CVEs organized by vendor.

PatchSiren public pages turn official CVE, NVD, CISA, and vendor evidence into defensive debriefs for operators who need fast context without losing source links.

Relying on luck is not a patch strategy.

Total CVEs
15,564

published debriefs

New Daily Average
135/day

last 30 days

Covered Vendors
2,920

public vendor sections

Latest 2026 critical and known-exploited CVEs

CRITICAL langflow-ai CVE published 2026-06-23

CVE-2026-55450

CVE-2026-55450 is a critical vulnerability in Langflow, a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.1, the vulnerability allows unauthenticated users to upload any amount of data to the server without limitations, potentially leading to server space exhaustion. Additionally, the absolute path of the uploaded file is reported to the attacker in the response, whic [truncated]

CRITICAL langflow-ai CVE published 2026-06-23

CVE-2026-55255

CVE-2026-55255 is a critical vulnerability in Langflow, a tool for building and deploying AI-powered agents and workflows. The vulnerability is an Insecure Direct Object Reference (IDOR) in the /api/v1/responses endpoint, which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability has a CVSS score of 9.9 and is [truncated]

CRITICAL NetComm Wireless Pty Ltd CVE published 2026-06-23

CVE-2026-35019

CVE-2026-35019 is a critical authentication bypass vulnerability affecting NetComm NF20MESH routers with firmware R6B031 and earlier. The vulnerability stems from a hardcoded AES-256 key used to encrypt session cookies for the web management interface. This allows unauthenticated attackers to forge valid encrypted session cookies and bypass authentication checks, gaining full administrative control of the [truncated]

CRITICAL FOSSBilling CVE published 2026-06-23

CVE-2026-27604

CVE-2026-27604 is a critical authorization bypass vulnerability in FOSSBilling, a free, open-source billing and client management system. The vulnerability allows unauthenticated access to privileged `/api/system/*` endpoints, enabling attackers to invoke admin API methods without valid credentials, session, or CSRF token. FOSSBilling version 0.8.0 patches the issue. Some workarounds are available, includ [truncated]

CRITICAL picklescan CVE published 2026-06-23

CVE-2026-56315

The CVE-2026-56315 vulnerability in picklescan before version 1.0.4 allows for remote code execution. This is due to the failure of picklescan to block at least seven Python standard library modules, including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib, which expose eight functions. These functions can be exploited by crafting malicious pickle files that import these unblocked modules, t [truncated]

CRITICAL Crawl4AI CVE published 2026-06-23

CVE-2026-56258

CVE-2026-56258 is a critical vulnerability in Crawl4AI before version 0.8.8. The vulnerability allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. This can lead to potential code execution on systems where the runtime user has write access to executable or cron locations. The vulnerability h [truncated]

CRITICAL Totolink CVE published 2026-06-23

CVE-2026-44089

The Totolink EX1200L router is vulnerable to a buffer overflow in the login functionality of the cgi-bin/cstecgi.cgi endpoint. This vulnerability, CVE-2026-44089, could be exploited to cause the program to crash and execute code remotely. An attacker could perform actions as root, including reading and editing data, as well as bricking the router. The vulnerability has been confirmed in version 9.3.5u.614 [truncated]

CRITICAL zohocorp CVE published 2026-06-23

CVE-2026-11374

CVE-2026-11374 is a critical vulnerability in ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus. The issue allows an unauthenticated user to predict SSO tickets, potentially leading to account takeover. The vulnerability has a CVSS score of 9 and is considered critical. ManageEngine has released an advisory for this vulnerability. Users of these products should rev [truncated]

Known exploited Ubiquiti Inc CVE published 2026-06-23

CVE-2026-34910

CVE-2026-34910 is a Critical vulnerability disclosed on 2026-05-22 affecting UniFi OS devices, where improper input validation could allow a network-accessible command injection. The NVD record rates the issue CVSS 10.0 with no privileges required and no user interaction, making it a high-priority exposure for any environment running the affected platform.

Known exploited Ubiquiti Inc CVE published 2026-06-23

CVE-2026-34909

Published on 2026-05-22, CVE-2026-34909 is a critical path traversal vulnerability in UniFi OS devices. A network-accessible attacker could access files on the underlying system and, according to the CVE description, potentially manipulate that access to reach an underlying account. NVD rates the issue CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and maps it to CWE-22.

Known exploited Ubiquiti Inc CVE published 2026-06-23

CVE-2026-34908

CVE-2026-34908 is a critical improper access control issue affecting UniFi OS devices. According to the CVE description and NVD metadata, a network-accessible attacker could abuse the flaw to make unauthorized changes to the system. The NVD record lists the issue as remotely exploitable with no privileges or user interaction required, and the impact is rated high across confidentiality, integrity, and availability.

CRITICAL BerriAI CVE published 2026-06-22

CVE-2026-49468

CVE-2026-49468 is a critical vulnerability in the LiteLLM proxy server, which acts as an AI Gateway to call LLM APIs in OpenAI or native format. The vulnerability has a CVSS score of 9.5 and was published on June 22, 2026. The issue is fixed in version 1.84.0 of LiteLLM. Users of affected versions should upgrade to 1.84.0 to mitigate the vulnerability. The CVE record and NVD detail provide further informa [truncated]

Vendor sections

Siemens

1921 published CVE debriefs, 93 critical or known-exploited

Google

979 published CVE debriefs, 148 critical or known-exploited

Linux

948 published CVE debriefs, 56 critical or known-exploited

Microsoft

664 published CVE debriefs, 397 critical or known-exploited

Apple

305 published CVE debriefs, 96 critical or known-exploited

IBM

278 published CVE debriefs, 25 critical or known-exploited

Oracle

268 published CVE debriefs, 52 critical or known-exploited

Adobe

194 published CVE debriefs, 86 critical or known-exploited

Red Hat

184 published CVE debriefs, 18 critical or known-exploited

Cisco

149 published CVE debriefs, 94 critical or known-exploited

Schneider Electric

144 published CVE debriefs, 16 critical or known-exploited

Festo Didactic SE

138 published CVE debriefs, 24 critical or known-exploited

Rockwell Automation

126 published CVE debriefs, 17 critical or known-exploited

Mozilla

100 published CVE debriefs, 30 critical or known-exploited

Apache Software Foundation

93 published CVE debriefs, 12 critical or known-exploited

ABB

76 published CVE debriefs, 17 critical or known-exploited

Hitachi Energy

76 published CVE debriefs, 5 critical or known-exploited

Apache

75 published CVE debriefs, 46 critical or known-exploited

OpenClaw

70 published CVE debriefs, 0 critical or known-exploited

Spring

67 published CVE debriefs, 0 critical or known-exploited

CODESYS

66 published CVE debriefs, 1 critical or known-exploited

cPanel

63 published CVE debriefs, 4 critical or known-exploited

open-webui

51 published CVE debriefs, 1 critical or known-exploited

Redhat

50 published CVE debriefs, 7 critical or known-exploited

Debian

46 published CVE debriefs, 2 critical or known-exploited

Palo Alto Networks

44 published CVE debriefs, 16 critical or known-exploited

Delta Electronics

44 published CVE debriefs, 6 critical or known-exploited

Open ISES

42 published CVE debriefs, 2 critical or known-exploited

Fortinet

40 published CVE debriefs, 30 critical or known-exploited

SourceCodester

39 published CVE debriefs, 0 critical or known-exploited

Concrete CMS

39 published CVE debriefs, 0 critical or known-exploited

AutomationDirect

38 published CVE debriefs, 8 critical or known-exploited

D-Link

37 published CVE debriefs, 26 critical or known-exploited

Citrix

37 published CVE debriefs, 25 critical or known-exploited

Tcpdump

37 published CVE debriefs, 37 critical or known-exploited

Ivanti

35 published CVE debriefs, 35 critical or known-exploited

ImageMagick

34 published CVE debriefs, 3 critical or known-exploited

NVIDIA

34 published CVE debriefs, 1 critical or known-exploited

Shenzhen Tenda Technology Co., Ltd

34 published CVE debriefs, 0 critical or known-exploited

Synacor

34 published CVE debriefs, 19 critical or known-exploited

Mattermost

33 published CVE debriefs, 0 critical or known-exploited

Tenda

33 published CVE debriefs, 13 critical or known-exploited

Git

33 published CVE debriefs, 6 critical or known-exploited

VMware

33 published CVE debriefs, 27 critical or known-exploited

Festo

32 published CVE debriefs, 10 critical or known-exploited

Dell

31 published CVE debriefs, 5 critical or known-exploited

Edimax

30 published CVE debriefs, 1 critical or known-exploited

Moxa

30 published CVE debriefs, 5 critical or known-exploited

ThemeREX

29 published CVE debriefs, 4 critical or known-exploited

misp

28 published CVE debriefs, 4 critical or known-exploited

Oracle Corporation

28 published CVE debriefs, 10 critical or known-exploited

JetBrains

27 published CVE debriefs, 6 critical or known-exploited

Samsung

27 published CVE debriefs, 15 critical or known-exploited

Exploit Db

27 published CVE debriefs, 3 critical or known-exploited

Fuji Electric

27 published CVE debriefs, 0 critical or known-exploited

Fedoraproject

27 published CVE debriefs, 5 critical or known-exploited

Imagemagick

27 published CVE debriefs, 0 critical or known-exploited

netty

26 published CVE debriefs, 0 critical or known-exploited

Canonical

26 published CVE debriefs, 3 critical or known-exploited

Honeywell

26 published CVE debriefs, 3 critical or known-exploited

Growatt

26 published CVE debriefs, 2 critical or known-exploited

Libdwarf Project

26 published CVE debriefs, 1 critical or known-exploited

Mybb

25 published CVE debriefs, 6 critical or known-exploited

Totolink

24 published CVE debriefs, 1 critical or known-exploited

Wordpress

24 published CVE debriefs, 1 critical or known-exploited

Mitsubishi Electric

24 published CVE debriefs, 3 critical or known-exploited

TP-Link Systems Inc.

23 published CVE debriefs, 0 critical or known-exploited

Copeland

23 published CVE debriefs, 2 critical or known-exploited

Advantech

23 published CVE debriefs, 2 critical or known-exploited

Capgo

22 published CVE debriefs, 0 critical or known-exploited

GitLab

21 published CVE debriefs, 4 critical or known-exploited

Jenkins Project

21 published CVE debriefs, 0 critical or known-exploited

TYPO3

21 published CVE debriefs, 1 critical or known-exploited

Roundcube

21 published CVE debriefs, 11 critical or known-exploited

Netatalk

21 published CVE debriefs, 1 critical or known-exploited

F5

21 published CVE debriefs, 7 critical or known-exploited

Ntp

21 published CVE debriefs, 0 critical or known-exploited

Budibase

20 published CVE debriefs, 2 critical or known-exploited

free5gc

20 published CVE debriefs, 5 critical or known-exploited

Joomla! Project

20 published CVE debriefs, 1 critical or known-exploited

National Instruments

20 published CVE debriefs, 0 critical or known-exploited

Netapp

20 published CVE debriefs, 4 critical or known-exploited

Gstreamer

20 published CVE debriefs, 0 critical or known-exploited

thorsten

19 published CVE debriefs, 2 critical or known-exploited

QNAP Systems Inc.

19 published CVE debriefs, 0 critical or known-exploited

ISC

19 published CVE debriefs, 0 critical or known-exploited

AVEVA

18 published CVE debriefs, 2 critical or known-exploited

Samsung Open Source

18 published CVE debriefs, 0 critical or known-exploited

Veritas

18 published CVE debriefs, 5 critical or known-exploited

Vuldb

18 published CVE debriefs, 0 critical or known-exploited

goTenna

18 published CVE debriefs, 1 critical or known-exploited

mcdope

17 published CVE debriefs, 0 critical or known-exploited

Gen Digital

17 published CVE debriefs, 0 critical or known-exploited

MongoDB

17 published CVE debriefs, 2 critical or known-exploited

itsourcecode

17 published CVE debriefs, 0 critical or known-exploited

haxtheweb

17 published CVE debriefs, 4 critical or known-exploited

Acer

17 published CVE debriefs, 4 critical or known-exploited

SonicWall

17 published CVE debriefs, 15 critical or known-exploited

Yokogawa

17 published CVE debriefs, 0 critical or known-exploited

SAP

17 published CVE debriefs, 14 critical or known-exploited

NodeJS

17 published CVE debriefs, 2 critical or known-exploited

OpenStack

16 published CVE debriefs, 0 critical or known-exploited

CodeAstro

16 published CVE debriefs, 0 critical or known-exploited

duck-organization

16 published CVE debriefs, 2 critical or known-exploited

Huawei

16 published CVE debriefs, 0 critical or known-exploited

Drupal

16 published CVE debriefs, 6 critical or known-exploited

Android

16 published CVE debriefs, 16 critical or known-exploited

Atlassian

16 published CVE debriefs, 13 critical or known-exploited

picklescan

15 published CVE debriefs, 4 critical or known-exploited

Zyxel

15 published CVE debriefs, 12 critical or known-exploited

GPAC

15 published CVE debriefs, 0 critical or known-exploited

Arista Networks

15 published CVE debriefs, 1 critical or known-exploited

FlowiseAI

15 published CVE debriefs, 2 critical or known-exploited

GNU

15 published CVE debriefs, 5 critical or known-exploited

Trend Micro, Inc.

15 published CVE debriefs, 2 critical or known-exploited

Freebsd

15 published CVE debriefs, 0 critical or known-exploited

Johnson Controls Inc.

15 published CVE debriefs, 3 critical or known-exploited

NousResearch

14 published CVE debriefs, 0 critical or known-exploited

discourse

14 published CVE debriefs, 0 critical or known-exploited

Veeam

14 published CVE debriefs, 9 critical or known-exploited

SAP_SE

14 published CVE debriefs, 3 critical or known-exploited

Xen

14 published CVE debriefs, 0 critical or known-exploited

Emerson

14 published CVE debriefs, 2 critical or known-exploited

Sungrow

14 published CVE debriefs, 0 critical or known-exploited

Gnu

14 published CVE debriefs, 1 critical or known-exploited

Libav

14 published CVE debriefs, 0 critical or known-exploited

Libtiff

14 published CVE debriefs, 1 critical or known-exploited

Emc

14 published CVE debriefs, 4 critical or known-exploited

fission

13 published CVE debriefs, 4 critical or known-exploited

roxy-wi

13 published CVE debriefs, 4 critical or known-exploited

Lenovo

13 published CVE debriefs, 1 critical or known-exploited

QNAP

13 published CVE debriefs, 12 critical or known-exploited

NETGEAR

13 published CVE debriefs, 8 critical or known-exploited

Arm

13 published CVE debriefs, 10 critical or known-exploited

code-projects

13 published CVE debriefs, 0 critical or known-exploited

Samsung Mobile

13 published CVE debriefs, 0 critical or known-exploited

Elastic

13 published CVE debriefs, 3 critical or known-exploited

mantisbt

13 published CVE debriefs, 0 critical or known-exploited

Dlink

13 published CVE debriefs, 4 critical or known-exploited

Opensuse

13 published CVE debriefs, 2 critical or known-exploited

BerriAI

12 published CVE debriefs, 3 critical or known-exploited

Grafana

12 published CVE debriefs, 1 critical or known-exploited

Autodesk

12 published CVE debriefs, 5 critical or known-exploited

Devolutions

12 published CVE debriefs, 1 critical or known-exploited

frappe

12 published CVE debriefs, 1 critical or known-exploited

Erlang

12 published CVE debriefs, 1 critical or known-exploited

NLnet Labs

12 published CVE debriefs, 0 critical or known-exploited

TRENDnet

12 published CVE debriefs, 0 critical or known-exploited

golang.org/x/crypto

12 published CVE debriefs, 6 critical or known-exploited

Anviz

12 published CVE debriefs, 1 critical or known-exploited

Qualcomm

12 published CVE debriefs, 12 critical or known-exploited

Jenkins

12 published CVE debriefs, 7 critical or known-exploited

Potrace Project

12 published CVE debriefs, 0 critical or known-exploited

n8n-io

11 published CVE debriefs, 0 critical or known-exploited

libexpat project

11 published CVE debriefs, 0 critical or known-exploited

Splunk

11 published CVE debriefs, 1 critical or known-exploited

Jetimpex Inc.

11 published CVE debriefs, 7 critical or known-exploited

Ruijie

11 published CVE debriefs, 1 critical or known-exploited

nezhahq

11 published CVE debriefs, 2 critical or known-exploited

axios

11 published CVE debriefs, 0 critical or known-exploited

SolarWinds

11 published CVE debriefs, 11 critical or known-exploited

Dokploy

11 published CVE debriefs, 9 critical or known-exploited

Pavel Odintsov

11 published CVE debriefs, 2 critical or known-exploited

silex technology, Inc.

11 published CVE debriefs, 1 critical or known-exploited

SenseLive

11 published CVE debriefs, 5 critical or known-exploited

Trend Micro

11 published CVE debriefs, 11 critical or known-exploited

PHP

11 published CVE debriefs, 5 critical or known-exploited

Baxter

11 published CVE debriefs, 8 critical or known-exploited

Artifex

11 published CVE debriefs, 2 critical or known-exploited

Ubiquiti Inc

10 published CVE debriefs, 7 critical or known-exploited

angular

10 published CVE debriefs, 0 critical or known-exploited

WWBN

10 published CVE debriefs, 0 critical or known-exploited

pgadmin.org

10 published CVE debriefs, 2 critical or known-exploited

apostrophecms

10 published CVE debriefs, 2 critical or known-exploited

CyberArk Software, a Palo Alto Networks Company

10 published CVE debriefs, 1 critical or known-exploited

Broadcom

10 published CVE debriefs, 5 critical or known-exploited

Rapid7

10 published CVE debriefs, 0 critical or known-exploited

Waterfall

10 published CVE debriefs, 5 critical or known-exploited

Gladinet

10 published CVE debriefs, 7 critical or known-exploited

B&R Industrial Automation GmbH

10 published CVE debriefs, 0 critical or known-exploited

Langflow

10 published CVE debriefs, 3 critical or known-exploited

openises

10 published CVE debriefs, 0 critical or known-exploited

OpenHarmony

10 published CVE debriefs, 0 critical or known-exploited

Open5gs

10 published CVE debriefs, 0 critical or known-exploited

PHP Group

10 published CVE debriefs, 2 critical or known-exploited

Gardyn

10 published CVE debriefs, 4 critical or known-exploited

Johnson Controls

10 published CVE debriefs, 1 critical or known-exploited

mySCADA

10 published CVE debriefs, 6 critical or known-exploited

LOYTEC electronics GmbH

10 published CVE debriefs, 0 critical or known-exploited

Wireshark

10 published CVE debriefs, 0 critical or known-exploited

Zoneminder

10 published CVE debriefs, 1 critical or known-exploited

Metalgenix

10 published CVE debriefs, 5 critical or known-exploited

Python Software Foundation

9 published CVE debriefs, 0 critical or known-exploited

HCLSoftware

9 published CVE debriefs, 0 critical or known-exploited

Yokogawa Electric Corporation

9 published CVE debriefs, 0 critical or known-exploited

zephyrproject-rtos

9 published CVE debriefs, 1 critical or known-exploited

vllm-project

9 published CVE debriefs, 1 critical or known-exploited

strukturag

9 published CVE debriefs, 0 critical or known-exploited

nesquena

9 published CVE debriefs, 2 critical or known-exploited

Elated-Themes

9 published CVE debriefs, 0 critical or known-exploited

MariaDB

9 published CVE debriefs, 1 critical or known-exploited

Aqara

9 published CVE debriefs, 4 critical or known-exploited

AMD

9 published CVE debriefs, 0 critical or known-exploited

Eugeny

9 published CVE debriefs, 1 critical or known-exploited

nationalsecurityagency

9 published CVE debriefs, 0 critical or known-exploited

OpenSSL

9 published CVE debriefs, 1 critical or known-exploited

Altium

9 published CVE debriefs, 7 critical or known-exploited

Shibby

9 published CVE debriefs, 0 critical or known-exploited

HCL

9 published CVE debriefs, 1 critical or known-exploited

nextcloud

9 published CVE debriefs, 0 critical or known-exploited

microsoft

9 published CVE debriefs, 0 critical or known-exploited

benoitc

9 published CVE debriefs, 0 critical or known-exploited

Plugins

9 published CVE debriefs, 0 critical or known-exploited

GeoVision Inc.

9 published CVE debriefs, 6 critical or known-exploited

Ilevia

9 published CVE debriefs, 5 critical or known-exploited

Sophos

9 published CVE debriefs, 7 critical or known-exploited

CyberPower

9 published CVE debriefs, 4 critical or known-exploited

Zoho

9 published CVE debriefs, 9 critical or known-exploited

Jasper Project

9 published CVE debriefs, 0 critical or known-exploited

Trendmicro

9 published CVE debriefs, 2 critical or known-exploited

Moodle

9 published CVE debriefs, 0 critical or known-exploited

Cap-go

8 published CVE debriefs, 1 critical or known-exploited

langchain-ai

8 published CVE debriefs, 0 critical or known-exploited

NI

8 published CVE debriefs, 2 critical or known-exploited

Mitsubishi Electric Corporation

8 published CVE debriefs, 0 critical or known-exploited

AWS

8 published CVE debriefs, 1 critical or known-exploited

Wertheim GmbH

8 published CVE debriefs, 0 critical or known-exploited

GL.iNet

8 published CVE debriefs, 0 critical or known-exploited

Imagination Technologies

8 published CVE debriefs, 1 critical or known-exploited

steipete

8 published CVE debriefs, 0 critical or known-exploited

vim

8 published CVE debriefs, 0 critical or known-exploited

nimiq

8 published CVE debriefs, 0 critical or known-exploited

signalwire

8 published CVE debriefs, 2 critical or known-exploited

mcmilk

8 published CVE debriefs, 0 critical or known-exploited

Netty

8 published CVE debriefs, 0 critical or known-exploited

OTRS AG

8 published CVE debriefs, 1 critical or known-exploited

Aiopmsd

8 published CVE debriefs, 0 critical or known-exploited

portainer

8 published CVE debriefs, 2 critical or known-exploited

Casdoor

8 published CVE debriefs, 5 critical or known-exploited

Apphp

8 published CVE debriefs, 0 critical or known-exploited

OPEXUS

8 published CVE debriefs, 2 critical or known-exploited

Juniper

8 published CVE debriefs, 8 critical or known-exploited

Santesoft

8 published CVE debriefs, 0 critical or known-exploited

Planet Technology

8 published CVE debriefs, 7 critical or known-exploited

Progress

8 published CVE debriefs, 8 critical or known-exploited

Intel

8 published CVE debriefs, 2 critical or known-exploited

Gdraheim

8 published CVE debriefs, 0 critical or known-exploited

OpenLink

7 published CVE debriefs, 0 critical or known-exploited

ruby

7 published CVE debriefs, 0 critical or known-exploited

craftcms

7 published CVE debriefs, 0 critical or known-exploited