PatchSiren

PatchSiren public CVE debriefs

Critical CVEs organized by vendor.

PatchSiren public pages turn official CVE, NVD, CISA, and vendor evidence into defensive debriefs for operators who need fast context without losing source links.

Relying on luck is not a patch strategy.

Latest critical and known-exploited CVEs

CRITICAL Wordpress CVE published 2026-05-10

CVE-2021-47933

CVE-2021-47933 is a critical unauthenticated arbitrary file upload issue affecting the MStore API WordPress plugin, described as allowing attackers to POST malicious files to a REST API endpoint and potentially reach remote code execution on vulnerable servers. The supplied NVD record maps the issue to CWE-306, and the record’s references point to the plugin page plus external VulnCheck and Exploit-DB mat [truncated]

CRITICAL Wordpress CVE published 2026-05-10

CVE-2021-47932

CVE-2021-47932 is a critical unauthenticated privilege-escalation issue affecting TheCartPress 1.5.3.6. Crafted POST requests to the tcp_register_and_login_ajax action can set tcp_role=administrator, allowing an attacker to create administrator accounts and gain full administrative access without credentials.

CRITICAL Git CVE published 2026-05-08

CVE-2026-43341

CVE-2026-43341 is a Linux kernel vulnerability in net/ipv6 ioam6 trace filling where a schema-length value could wrap around and defeat a remaining-space check. The resulting cursor miscalculation could allow writes past the trace buffer, and the upstream fix keeps the length in a wider integer type so the size checks and cursor math use the full value.

Known exploited BerriAI CVE published 2026-05-08

CVE-2026-42208

CVE-2026-42208 is a SQL injection vulnerability affecting BerriAI LiteLLM. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-08 and set a remediation due date of 2026-05-11. In practical terms, this means defenders should treat it as an actively exploited issue and move quickly on vendor guidance, compensating controls, or removal where mitigation is not available.

Known exploited Ivanti CVE published 2026-05-07

CVE-2026-6973

CVE-2026-6973 is an Ivanti Endpoint Manager Mobile (EPMM) vulnerability described as improper input validation. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-07, which means it is treated as a known-exploited issue and should be addressed urgently. The supplied corpus does not include deeper technical detail or a CVSS score, so defensive response should focus on confirming exposu [truncated]

CRITICAL Cern CVE published 2026-05-06

CVE-2026-29090

CVE-2026-29090 is a critical SQL injection issue in Rucio's `FilterEngine.create_postgres_query()` path. When the `postgres_meta` metadata plugin is enabled, authenticated users can supply attacker-controlled filter keys and values through the DID search endpoint and have them interpolated into raw PostgreSQL SQL. The result can include exposure, modification, or deletion of metadata, and in some environm [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1952

CVE-2026-1952 is a critical-severity vulnerability affecting Delta Electronics AS320T firmware. NVD describes it as a denial-of-service issue tied to an undocumented subfunction, with a network attack vector and no privileges or user interaction required. The NVD record also lists vulnerable AS320T firmware versions prior to 1.16. For industrial or OT environments, this is most important where the device [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1951

CVE-2026-1951 is a critical Delta Electronics AS320T firmware flaw tied to missing length checks for a directory-name buffer. NVD assigns it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with no privileges or user interaction required. NVD’s affected CPE range marks AS320T firmware versions earlier than 1.12 as vulnerable. The vendor advisory linked in NVD cover [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1950

CVE-2026-1950 is a critical vulnerability in Delta Electronics AS320T firmware affecting versions before 1.16. The issue is described as missing length checking on a buffer that handles file names, and NVD maps it to CWE-121 (stack-based buffer overflow). NVD rates the flaw 9.8/CRITICAL with a network attack vector and no privileges or user interaction required, so exposed or remotely reachable devices sh [truncated]

CRITICAL Deltaww CVE published 2026-04-24

CVE-2026-1949

CVE-2026-1949 is a critical vulnerability in Delta Electronics AS320T firmware affecting the web service GET/PUT request handler. The issue is an incorrect calculation of stack buffer size, which can have high impact because the published CVSS vector rates the flaw as network-reachable, unauthenticated, and capable of affecting confidentiality, integrity, and availability. NVD lists firmware versions befo [truncated]

Known exploited Microsoft CVE published 2026-04-14

CVE-2026-32201

CVE-2026-32201 is a Microsoft SharePoint Server improper input validation vulnerability that CISA has added to the Known Exploited Vulnerabilities (KEV) catalog. KEV inclusion means CISA considers the issue to have known exploitation risk, so this should be treated as an urgent remediation item. The supplied corpus does not include CVSS scoring or deeper technical exploitation details, so defensive priori [truncated]

Known exploited Microsoft CVE published 2026-04-14

CVE-2009-0238

CVE-2009-0238 is a Microsoft Office remote code execution vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is operational urgency: treat it as an actively exploited issue and prioritize vendor-guided mitigation or patching immediately.

Vendor sections

Linux

63 published CVE debriefs, 4 critical or known-exploited

cPanel

37 published CVE debriefs, 0 critical or known-exploited

Microsoft

25 published CVE debriefs, 23 critical or known-exploited

Denx

21 published CVE debriefs, 14 critical or known-exploited

Redhat

16 published CVE debriefs, 0 critical or known-exploited

Wordpress

11 published CVE debriefs, 2 critical or known-exploited

Apple

10 published CVE debriefs, 2 critical or known-exploited

Google

9 published CVE debriefs, 4 critical or known-exploited

Ntp

9 published CVE debriefs, 0 critical or known-exploited

Unknown Vendor

8 published CVE debriefs, 0 critical or known-exploited

Ivanti

8 published CVE debriefs, 8 critical or known-exploited

Vuldb

7 published CVE debriefs, 0 critical or known-exploited

Netapp

6 published CVE debriefs, 1 critical or known-exploited

Metalgenix

6 published CVE debriefs, 2 critical or known-exploited

Gstreamer

6 published CVE debriefs, 0 critical or known-exploited

Git

5 published CVE debriefs, 1 critical or known-exploited

Cisco

5 published CVE debriefs, 5 critical or known-exploited

Debian

5 published CVE debriefs, 0 critical or known-exploited

Fedoraproject

5 published CVE debriefs, 0 critical or known-exploited

Deltaww

4 published CVE debriefs, 4 critical or known-exploited

Cert Portal

4 published CVE debriefs, 0 critical or known-exploited

Palo Alto Networks

4 published CVE debriefs, 4 critical or known-exploited

Openssl

4 published CVE debriefs, 0 critical or known-exploited

Spip

4 published CVE debriefs, 0 critical or known-exploited

B2evolution

4 published CVE debriefs, 0 critical or known-exploited

Brocade

4 published CVE debriefs, 1 critical or known-exploited

Matrixssl

4 published CVE debriefs, 0 critical or known-exploited

Adups

4 published CVE debriefs, 0 critical or known-exploited

Gist

3 published CVE debriefs, 1 critical or known-exploited

Android

3 published CVE debriefs, 3 critical or known-exploited

Oracle

3 published CVE debriefs, 3 critical or known-exploited

Fortinet

3 published CVE debriefs, 3 critical or known-exploited

VMware

3 published CVE debriefs, 3 critical or known-exploited

Imagemagick

3 published CVE debriefs, 0 critical or known-exploited

Artifex

3 published CVE debriefs, 1 critical or known-exploited

S9y

3 published CVE debriefs, 0 critical or known-exploited

Blackberry

3 published CVE debriefs, 0 critical or known-exploited

Barco

3 published CVE debriefs, 1 critical or known-exploited

Support

2 published CVE debriefs, 0 critical or known-exploited

Pgbouncer

2 published CVE debriefs, 0 critical or known-exploited

Jupyter

2 published CVE debriefs, 0 critical or known-exploited

Openclaw

2 published CVE debriefs, 0 critical or known-exploited

Sagedpw

2 published CVE debriefs, 0 critical or known-exploited

Access

2 published CVE debriefs, 0 critical or known-exploited

Elecom

2 published CVE debriefs, 0 critical or known-exploited

Jvn

2 published CVE debriefs, 0 critical or known-exploited

OpenPLC

2 published CVE debriefs, 2 critical or known-exploited

D-Link

2 published CVE debriefs, 2 critical or known-exploited

Advantive

2 published CVE debriefs, 2 critical or known-exploited

Zyxel

2 published CVE debriefs, 2 critical or known-exploited

Mitel

2 published CVE debriefs, 2 critical or known-exploited

Apache

2 published CVE debriefs, 2 critical or known-exploited

Graphicsmagick

2 published CVE debriefs, 1 critical or known-exploited

Samsung

2 published CVE debriefs, 0 critical or known-exploited

Hexchat Project

2 published CVE debriefs, 0 critical or known-exploited

Exponentcms

2 published CVE debriefs, 0 critical or known-exploited

Jasper Project

2 published CVE debriefs, 0 critical or known-exploited

A J Evolution

1 published CVE debriefs, 0 critical or known-exploited

Motopress

1 published CVE debriefs, 0 critical or known-exploited

Downloads

1 published CVE debriefs, 0 critical or known-exploited