// intelligence feed
// intelligence feed
// intelligence feed
Normalised CVEs from NVD, cross-referenced with the CISA Known Exploited Vulnerabilities catalog. Filter by severity, KEV status, or date range click any CVE for the full record.
// kev highlights
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
// severity breakdown