Top Exploited Vulnerabilities
The most actively exploited vulnerabilities across the companies tracked by Rankiteo. Aggregated from real incident data to help you prioritize patching.
6629
Vulnerabilities Tracked
5427
Critical Severity
707
High Severity
8,403
Total Exposures
Vulnerability Rankings
| # | Vulnerability | Severity | CVSS | Incidents | Attack Type |
|---|---|---|---|---|---|
| 1 | Human Error | critical | 10.0 | 150 | Ransomware, Phishing, Data Breach |
| 2 | Unauthorized Access | critical | 10.0 | 80 | Data Exfiltration, Data Breach, Security Concerns |
| 3 | Email Account | critical | 8.5 | 54 | Data Breach, Phishing Scam |
| 4 | Lack of Multi-Factor Authentication (MFA) | critical | 10.0 | 43 | Ransomware, election fraud, fraud |
| 5 | Physical Security | critical | 10.0 | 40 | Data Breach, Data Theft |
| 6 | Misconfiguration | critical | 10.0 | 33 | Ransomware, Data Breach, Data Exposure |
| 7 | Human | critical | 10.0 | 31 | Phishing, Data Breach |
| 8 | Improper Access Control | critical | 10.0 | 31 | Data Breach, Unauthorized Data Access, Data Exposure |
| 9 | Social Engineering | critical | 10.0 | 29 | Ransomware, Phishing, Data Breach |
| 10 | Email Account Compromise | critical | 10.0 | 28 | Data Breach |
| 11 | Employee Email Account | critical | 8.5 | 27 | Data Breach |
| 12 | SQL Injection | critical | 10.0 | 21 | AI-driven attack, Data Breach, vulnerability_exploitation |
| 13 | Unauthorized Access to Email Account | critical | 10.0 | 21 | Data Breach, Data Theft |
| 14 | unpatched systems | critical | 10.0 | 21 | Ransomware, state-sponsored cyberattack, AI-driven attack |
| 15 | Insider Threat | critical | 10.0 | 18 | Data Breach, Malicious Insider, Insider Wrongdoing |
| 16 | Weak Password | critical | 10.0 | 17 | Ransomware, Phishing, Sextortion |
| 17 | Inadequate security measures | critical | 10.0 | 16 | Data Breach |
| 18 | MOVEit software vulnerability | critical | 10.0 | 15 | Data Breach |
| 19 | Website Vulnerability | critical | 10.0 | 14 | Data Breach |
| 20 | Improper Data Handling | critical | 10.0 | 14 | Fraud, Data Breach, Data Exposure |
| 21 | Unsecured Database | critical | 10.0 | 13 | Data Exposure, Data Breach, Data Leak |
| 22 | Human Error (Phishing Susceptibility) | critical | 10.0 | 12 | Data Breach (Phishing), Phishing, Data Breach |
| 23 | Unencrypted Data | critical | 10.0 | 12 | ransomware, Data Breach, data breach |
| 24 | CVE-2024-57727 | critical | 10.0 | 11 | Ransomware, ransomware, Supply-Chain Attack |
| 25 | Weak or Stolen Credentials | critical | 10.0 | 11 | Data Breach (General Discussion), Data Breach, ransomware |
| 26 | Lack of Physical Security | critical | 10.0 | 11 | cybercrime, Data Breach, Data Leak |
| 27 | Unpatched vulnerabilities | critical | 10.0 | 11 | Ransomware, ransomware, AI-driven cyberattack |
| 28 | Lack of Password Protection | critical | 10.0 | 11 | Data Exposure, Data Breach |
| 29 | Compromised Email Account | critical | 10.0 | 11 | Data Breach |
| 30 | Stolen Credentials | critical | 10.0 | 11 | Ransomware, Phishing, Data Breach |
| 31 | Unsecured cloud environment | critical | 10.0 | 10 | Data Breach |
| 32 | Human Error (Social Engineering) | critical | 10.0 | 10 | Phishing, Data Breach, spear-phishing |
| 33 | Lack of Network Segmentation | critical | 10.0 | 10 | Data Breach, phishing, ransomware |
| 34 | Weak Access Controls | critical | 10.0 | 10 | Data Breach, cyber espionage, Unauthorized Access and Data Manipulation |
| 35 | Unsecured Laptop | critical | 10.0 | 9 | Data Breach |
| 36 | Previously unknown vulnerability | critical | 10.0 | 9 | Data Breach, Ransomware Attack, Ransomware |
| 37 | Zero-day vulnerability | critical | 10.0 | 9 | Data Breach, ransomware, Cyberattack |
| 38 | Weak authentication | critical | 10.0 | 9 | AI-driven attack, Ransomware, Data Breach |
| 39 | Outdated software | critical | 10.0 | 9 | Ransomware, Data Breach, phishing |
| 40 | Compromised credentials | critical | 10.0 | 9 | Data Breach, Extortion, Source Code Theft, Quantum Computing Threat |
| 41 | lack of access controls | critical | 10.0 | 9 | Data Breach, data exposure, ransomware |
| 42 | Insufficient access controls | critical | 10.0 | 9 | Data Breach, Insider Threat, Supply Chain Attack |
| 43 | MOVEit Transfer application vulnerability | critical | 8.5 | 9 | Data Breach |
| 44 | CVE-2025-55182 (React2Shell) | critical | 10.0 | 8 | Ransomware, Remote Code Execution (RCE), Vulnerability Exploitation |
| 45 | Unknown | critical | 10.0 | 8 | Data Breach, Data Breach, Website Defacement, Malware |
| 46 | Inadequately secured network | critical | 10.0 | 8 | Data Breach |
| 47 | Phishing | critical | 10.0 | 8 | Ransomware, Phishing, Data Breach |
| 48 | Unencrypted Laptop | critical | 10.0 | 8 | Data Breach |
| 49 | Unprotected Database | critical | 10.0 | 8 | Data Exposure, Data Breach, Data Leak |
| 50 | Weak Password Policies | critical | 10.0 | 8 | Ransomware, Data Breach, election fraud |
| 51 | MOVEit Transfer software vulnerability | critical | 8.5 | 8 | Data Breach |
| 52 | Unencrypted Data Storage | critical | 8.5 | 8 | Data Breach, Data Security Incident |
| 53 | Lack of MFA | critical | 10.0 | 7 | Compliance Failure, Ransomware, Data Breach |
| 54 | CVE-2025-61882 | critical | 10.0 | 7 | ransomware, Data Breach, Cyberattack |
| 55 | MOVEit file transfer software | critical | 10.0 | 7 | Ransomware, Data Breach, Ransomware Attack |
| 56 | Zero-day vulnerabilities | critical | 10.0 | 7 | Ransomware, Zero-day Exploit, Data Theft |
| 57 | Unpatched vulnerability | critical | 10.0 | 7 | Ransomware, Data Breach, Data Breach, Ransomware |
| 58 | Inadequate Access Controls | critical | 10.0 | 7 | Data Breach, ransomware, unauthorized access |
| 59 | Configuration Error | critical | 8.5 | 7 | Data Breach, Data Leak |
| 60 | MOVEit Transfer software | critical | 8.5 | 7 | Data Breach |
| 61 | Email Compromise | critical | 8.5 | 7 | Data Breach |
| 62 | Weak or Reused Passwords | critical | 8.5 | 7 | Credential Stuffing, Data Breach, Credential-Stuffing Attack |
| 63 | MOVEit Transfer application | critical | 10.0 | 6 | Data Breach |
| 64 | CVE-2024-57726 | critical | 10.0 | 6 | Ransomware, ransomware, Supply-Chain Attack |
| 65 | CVE-2025-47812 | critical | 10.0 | 6 | Information Disclosure, Remote Code Execution, Vulnerability Exploitation, Remote Code Execution |
| 66 | Weak OAuth Token Security | critical | 10.0 | 6 | Data Breach, Supply Chain Attack |
| 67 | Human Error (Phishing) | critical | 10.0 | 6 | Data Breach, Targeted Cyberattack, Targeted Attack |
| 68 | CVE-2024-57728 | critical | 10.0 | 6 | Ransomware, ransomware, Supply-Chain Attack |
| 69 | MOVEit file transfer software vulnerability | critical | 10.0 | 6 | Ransomware, Data Breach, Cyber Attack |
| 70 | Human Factor | critical | 10.0 | 6 | Data Breach, Data Theft, Social Engineering, Ransomware |
| 71 | Software Vulnerability | critical | 10.0 | 6 | Data Breach, Cyber Attack |
| 72 | Insecure Direct Object Reference (IDOR) | critical | 10.0 | 6 | Data Breach, API Vulnerability, unauthorized access |
| 73 | Lack of Multi-Factor Authentication (MFA) Enforcement | critical | 10.0 | 6 | phishing, Phishing, Data Breach |
| 74 | Lack of Multifactor Authentication (MFA) | critical | 10.0 | 6 | Ransomware, Data Breach, Cybersecurity Incident |
| 75 | Lack of multi-factor authentication | critical | 10.0 | 6 | Ransomware, Data Breach, Sextortion |
| 76 | legacy systems | critical | 10.0 | 6 | Ransomware, Data Breach, ransomware |
| 77 | Third-Party Risks | critical | 10.0 | 6 | Data Breach, AI-driven vulnerability exploitation, Cyberattack |
| 78 | unpatched software | critical | 10.0 | 6 | Ransomware, ransomware, Data Breach |
| 79 | Cloud misconfiguration | critical | 10.0 | 6 | Data Breach, Data Breach, Extortion, Cyber-Attack |
| 80 | MOVEit Transfer | critical | 8.5 | 6 | Data Breach, Cyber Attack |
| 81 | Password Reuse | critical | 8.5 | 6 | Data Breach, Credential Leak, Credential Theft |
| 82 | Unauthorized Data Transfer | critical | 8.0 | 6 | Data Breach |
| 83 | CVE-2025-11953 | critical | 10.0 | 5 | OS Command Injection, Botnet Infection, Remote Code Execution (RCE) |
| 84 | CVE-2023-34362 | critical | 10.0 | 5 | Data Breach and Ransomware Attack, Data Breach, Ransomware |
| 85 | Inadequately secured systems | critical | 10.0 | 5 | Data Breach |
| 86 | CVE-2023-27532 | critical | 10.0 | 5 | Ransomware, ransomware, Ransomware Attack |
| 87 | CVE-2025-61882 (Oracle E-Business Suite) | critical | 10.0 | 5 | Data Breach, Data Breach, Ransomware, Cybercriminal Alliance Formation |
| 88 | Inadequate cybersecurity measures | critical | 10.0 | 5 | Ransomware, Data Breach |
| 89 | React2Shell | critical | 10.0 | 5 | Ransomware, Data Breach, Malware Campaign |
| 90 | CVE-2026-55040 | critical | 10.0 | 5 | Data Breach, Authentication Bypass, Remote Code Execution (RCE) |
| 91 | Default passwords | critical | 10.0 | 5 | Data Exposure, Exposure of Critical Infrastructure, espionage |
| 92 | Default credentials | critical | 10.0 | 5 | Ransomware, DDoS Attack, Cyber Espionage |
| 93 | Online Payment System | critical | 10.0 | 5 | Data Breach |
| 94 | Unsecured cloud storage | critical | 10.0 | 5 | Data Exposure, Data Breach, Data Leak |
| 95 | Human Vulnerability | critical | 10.0 | 5 | Phishing, Data Breach, Sex Trafficking and Deepfake Pornography |
| 96 | MOVEit Transfer programme | critical | 8.5 | 5 | Data Breach |
| 97 | Lack of Authentication | critical | 8.5 | 5 | Data Exposure, Data Leak |
| 98 | Lack of Encryption | critical | 8.5 | 5 | Data Breach |
| 99 | Human (Employee Email Compromise) | critical | 8.5 | 5 | Data Breach |
| 100 | Inadequate data protection measures | critical | 8.5 | 5 | Data Breach |
| 101 | Compromised Employee Email Account | critical | 8.5 | 5 | Data Breach |
| 102 | Lack of encryption and password protection | critical | 8.5 | 5 | Data Exposure, Data Breach, data breach |
| 103 | Email Phishing Scam | high | 6.0 | 5 | Data Breach |
| 104 | Email Phishing | high | 6.0 | 5 | Data Breach |
| 105 | CVE-2025-49706 | critical | 10.0 | 4 | Ransomware, Cyber Espionage, Cyberattack |
| 106 | Zero-day vulnerability in MOVEit Transfer programme | critical | 10.0 | 4 | Data Breach |
| 107 | Lack of Oversight | critical | 10.0 | 4 | Unauthorized Disclosure, Data Breach, Data Breach (Alleged) |
| 108 | Internal Access | critical | 10.0 | 4 | Data Breach, Data Theft |
| 109 | Cloudbleed | critical | 10.0 | 4 | Data Breach |
| 110 | CVE-2025-49704 | critical | 10.0 | 4 | Cyber Espionage, Cyberattack, Ransomware |
| 111 | CVE-2026-56164 | critical | 10.0 | 4 | Data Breach, Zero-day exploit, Credential Theft |
| 112 | MOVEit Transfer tool | critical | 10.0 | 4 | Data Breach |
| 113 | Weak or Compromised Credentials | critical | 10.0 | 4 | Data Breach, Cyberattack |
| 114 | CVE-2024-40711 | critical | 10.0 | 4 | Ransomware, ransomware, Vulnerability |
| 115 | MOVEit | critical | 10.0 | 4 | Ransomware, Data Breach |
| 116 | Security breach on a third-party vendor | critical | 10.0 | 4 | Data Breach |
| 117 | SonicWall firewall vulnerability | critical | 10.0 | 4 | Ransomware, Data Breach |
| 118 | CVE-2025-53770 | critical | 10.0 | 4 | Ransomware, Ransomware Attack, Cyberattack |
| 119 | CVE-2026-31431 (Copy Fail) | critical | 10.0 | 4 | Malware (Botnet), Privilege Escalation |
| 120 | Unknown vulnerability | critical | 10.0 | 4 | Data Breach, Ransomware Attack, Data Breach, Ransomware |
| 121 | Employee email account compromise | critical | 10.0 | 4 | Phishing, Data Breach, Phishing Attack |
| 122 | human trust | critical | 10.0 | 4 | phishing, fraud, social engineering |
| 123 | Third-party software vulnerability | critical | 10.0 | 4 | Data Breach, Ransomware Attack |
| 124 | CVE-2026-50522 | critical | 10.0 | 4 | Data Breach, Credential Theft, Remote Code Execution (RCE) |
| 125 | Web Application Vulnerability | critical | 10.0 | 4 | Data Breach, Cyber Attack |
| 126 | Insufficient Employee Training | critical | 10.0 | 4 | Data Breach, Cyber Attack, Data Breach Risk |
| 127 | Network Vulnerability | critical | 10.0 | 4 | Data Breach, Ransomware Attack |
| 128 | Fortinet vulnerabilities | critical | 10.0 | 4 | Ransomware, ransomware, Vulnerability Exploitation |
| 129 | Excessive Permissions | critical | 10.0 | 4 | AI-driven attack, Data Breach, Malware Infiltration |
| 130 | MOVEit file transfer software vulnerabilities | critical | 10.0 | 4 | Data Breach, Data Breach, Unauthorized Access, Ransomware Attack |
| 131 | Improper Email Handling | critical | 10.0 | 4 | Data Breach |
| 132 | Publicly Accessible Server | critical | 10.0 | 4 | data exposure, Data Exposure, Data Breach |
| 133 | Weak Credential Management | critical | 10.0 | 4 | Data Breach, credential theft |
| 134 | Employee credentials | critical | 10.0 | 4 | Data Breach, Phishing Attack, Data Breach, Phishing |
| 135 | Weak email security | critical | 10.0 | 4 | Data Breach, Cyberattack, defacement |
| 136 | Zero-day exploit | critical | 10.0 | 4 | Ransomware, Data Breach, Compliance Failure |
| 137 | Weak Identity Controls | critical | 10.0 | 4 | Ransomware, Data Exfiltration, Data Breach |
| 138 | Weak security controls | critical | 10.0 | 4 | Ransomware, ransomware, Data Breach |
| 139 | Point-of-Sale System | critical | 10.0 | 4 | Data Breach |
| 140 | Inadequate employee training | critical | 10.0 | 4 | phishing, Data Breach, Data Leakage |
| 141 | Unauthorized access to employee email account | critical | 10.0 | 4 | Data Breach |
| 142 | Reused Passwords | critical | 10.0 | 4 | data breach (unverified), Data Breach, Account Compromise |
| 143 | Coding Error | critical | 8.5 | 4 | Data Breach |
| 144 | Unsecured Server | critical | 8.5 | 4 | Data Breach, Data Leak |
| 145 | Compromised login credentials | critical | 8.5 | 4 | Data Breach |
| 146 | MOVEit Transfer vulnerability | critical | 8.5 | 4 | Data Breach |
| 147 | Unauthorized Access by Former Employee | critical | 8.5 | 4 | Data Breach |
| 148 | Third-party vendor vulnerability | critical | 8.5 | 4 | Data Breach |
| 149 | Lack of two-factor authentication | critical | 8.5 | 4 | Data Breach, Cyber Attack |
| 150 | Publicly Accessible Database | critical | 8.5 | 4 | Data Exposure, Data Breach, Data Leak |
| 151 | SQL Injection Flaws | critical | 10.0 | 3 | Data Breach |
| 152 | CVE-2024-55591 | critical | 10.0 | 3 | Ransomware, Cyber-Attack |
| 153 | Supply chain vulnerabilities | critical | 10.0 | 3 | Ransomware, Data Breach |
| 154 | CVE-2017-11882 | critical | 10.0 | 3 | Cyber Espionage, cyber espionage |
| 155 | Lack of Role-Based Access Control (RBAC) | critical | 10.0 | 3 | Data Breach, Data Breach Risk |
| 156 | CVE-2026-23760 | critical | 10.0 | 3 | Ransomware, Ransomware Attack, Remote Code Execution (RCE) |
| 157 | CVE-2024-40766 | critical | 10.0 | 3 | Ransomware |
| 158 | Weak credentials | critical | 10.0 | 3 | AI Model Escape, Botnet, Credential Theft |
| 159 | Weak Authentication System | critical | 10.0 | 3 | Data Breach |
| 160 | CVE-2025-5777 (Citrix Bleed 2) | critical | 10.0 | 3 | Ransomware |
| 161 | Microsoft Exchange Server | critical | 10.0 | 3 | Ransomware, Cyber Espionage, Security Breach |
| 162 | Stolen Employee Credentials | critical | 10.0 | 3 | Data Breach |
| 163 | Weak Password Security | critical | 10.0 | 3 | Data Breach |
| 164 | CVE-2025-53521 | critical | 10.0 | 3 | Vulnerability Exploitation, Remote Code Execution (RCE) |
| 165 | CVE-2026-21509 | critical | 10.0 | 3 | Zero-Day Vulnerability, Zero-day exploitation |
| 166 | React2Shell vulnerability | critical | 10.0 | 3 | Ransomware, Data Breach |
| 167 | CVE-2024-1709 (ConnectWise ScreenConnect) | critical | 10.0 | 3 | Ransomware, ransomware |
| 168 | Weak/Stolen Credentials | critical | 10.0 | 3 | Data Breach |
| 169 | CVE-2026-63520 | critical | 10.0 | 3 | Authentication Bypass, Remote Code Execution (RCE) |
| 170 | Unauthorized Access to Sensitive Data | critical | 10.0 | 3 | Data Breach, Extortion |
| 171 | CVE-2026-20963 | critical | 10.0 | 3 | Vulnerability Exploitation, Cyberespionage, Remote Code Execution (RCE) |
| 172 | CVE-2021-36942 (PetitPotam) | critical | 10.0 | 3 | Cyber Espionage |
| 173 | Zero-day vulnerability in Oracle’s E-Business Suite | critical | 10.0 | 3 | Ransomware, Data Breach |
| 174 | CVE-2025-5777 | critical | 10.0 | 3 | Ransomware, ransomware, Vulnerability Exploitation |
| 175 | CVE-2024-7029 | critical | 10.0 | 3 | Malware, Botnet |
| 176 | AI models or applications | critical | 10.0 | 3 | Data Breach, AI-enabled breach |
| 177 | SonicWall vulnerabilities | critical | 10.0 | 3 | Ransomware, Cybercrime, Vulnerability Exploitation |
| 178 | Weak or Reused Credentials | critical | 10.0 | 3 | Unauthorized Access, Data Breach |
| 179 | CVE-2025-55182 | critical | 10.0 | 3 | Supply Chain Attack, Botnet, DDoS, IoT Exploitation, Remote Code Execution (RCE) |
| 180 | null | critical | 10.0 | 3 | Data Breach, DDoS, Data Breach and Ransomware |
| 181 | Lack of Data Encryption | critical | 10.0 | 3 | Data Breach |
| 182 | CVE-2017-17215 | critical | 10.0 | 3 | Malware, Botnet, Botnet, DDoS, IoT Exploitation |
| 183 | CVE-2023-27351 (PaperCut) | critical | 10.0 | 3 | Ransomware, ransomware |
| 184 | CVE-2025-53771 | critical | 10.0 | 3 | Ransomware, Ransomware Attack |
| 185 | External System Breach | critical | 10.0 | 3 | Data Breach |
| 186 | outdated systems | critical | 10.0 | 3 | Ransomware, ransomware, data breach |
| 187 | credential harvesting | critical | 10.0 | 3 | ransomware, Phishing-as-a-Service (PhaaS), wire fraud |
| 188 | Lack of Multifactor Authentication | critical | 10.0 | 3 | Fraud, Awareness Campaign, Supply Chain Breach |
| 189 | Compromised Employee Credentials | critical | 10.0 | 3 | Data Breach |
| 190 | Sandbox escape | critical | 10.0 | 3 | Espionage, Exploit Kit, Exploit Kit / Cyber Espionage |
| 191 | MFA bypass | critical | 10.0 | 3 | ransomware, Espionage, Phishing-as-a-Service (PhaaS) |
| 192 | Outdated infrastructure | critical | 10.0 | 3 | Ransomware, ransomware, GPS spoofing |
| 193 | Lack of phishing-resistant MFA | critical | 10.0 | 3 | Phishing, Data Breach, Extortion |
| 194 | weak endpoint security | critical | 10.0 | 3 | ransomware, Data Breach, data breach |
| 195 | Third-Party Integration Risks | critical | 10.0 | 3 | Data Breach, third-party breach, Supply Chain Attack |
| 196 | credential theft | critical | 10.0 | 3 | Data Breach, Malware |
| 197 | lack of cybersecurity expertise | critical | 10.0 | 3 | ransomware, Data Breach |
| 198 | Poor Network Segmentation | critical | 10.0 | 3 | Ransomware, cyber attack |
| 199 | Misconfigured Amazon S3 bucket | critical | 9.0 | 3 | Data Breach |
| 200 | Information Disclosure | critical | 8.5 | 3 | Data Breach, Data Leak, Vulnerability Exploitation |
| 201 | CVE-2025-66376 | critical | 8.5 | 3 | AI Security Breach, Cyberespionage, Phishing, Espionage |
| 202 | Security Vulnerability | critical | 8.5 | 3 | Data Breach |
| 203 | MOVEit Transfer solution | critical | 8.5 | 3 | Data Breach |
| 204 | Physical Theft | critical | 8.5 | 3 | Data Breach |
| 205 | CVE-2026-43502 (ZcopyReaper) | critical | 8.5 | 3 | Local Privilege Escalation, Privilege Escalation |
| 206 | Insufficient security measures | critical | 8.5 | 3 | Data Breach |
| 207 | Point of Sale Systems | critical | 8.5 | 3 | Data Breach |
| 208 | MOVEit Transfer server | critical | 8.5 | 3 | Data Breach |
| 209 | human trust (social engineering) | critical | 8.5 | 3 | phishing, Malware, cyber theft |
| 210 | Oracle E-Business Suite (EBS) vulnerability | critical | 8.5 | 3 | Data Breach |
| 211 | Server Misconfiguration | critical | 8.5 | 3 | Data Breach, Botnet |
| 212 | MOVEit file transfer application | critical | 8.5 | 3 | Data Breach |
| 213 | Third-party service provider | critical | 8.5 | 3 | Data Breach |
| 214 | Payment Processing System | critical | 8.5 | 3 | Data Breach |
| 215 | Email Misconfiguration | high | 6.0 | 3 | Data Breach |
| 216 | Unauthorized Data Access | high | 6.0 | 3 | Data Exfiltration, Data Breach |
| 217 | Weak or Stolen Password | high | 6.0 | 3 | Authentication Security Improvement, Data Breach, Data Breach (Unauthorized Access) |
| 218 | Insider Access | low | 0.0 | 3 | Data Breach, Insider Threat |
| 219 | Zero-day vulnerability in Oracle PeopleSoft | critical | 10.0 | 2 | Data Breach, Extortion, Data Breach |
| 220 | Internal Account Compromise | critical | 10.0 | 2 | Data Breach |
| 221 | Unattended Devices | critical | 10.0 | 2 | Insider Threat, Awareness Campaign |
| 222 | CVE-2026-23760 (SmarterMail) | critical | 10.0 | 2 | Ransomware, ransomware |
| 223 | Non-password protected database | critical | 10.0 | 2 | Data Breach |
| 224 | API vulnerabilities | critical | 10.0 | 2 | Data Breach, Quantum Computing Threat |
| 225 | CVE-2023-4966 | critical | 10.0 | 2 | Ransomware, Vulnerability Exploitation |
| 226 | Known vulnerability not patched in time | critical | 10.0 | 2 | Ransomware, Data Breach |
| 227 | CVE-2025-29927 | critical | 10.0 | 2 | Cyberattack, worm-driven campaign |
| 228 | Cisco IOS vulnerabilities | critical | 10.0 | 2 | Data Breach, Vulnerability Exploitation |
| 229 | Lack of Multi-Factor Authentication (MFA) (implied) | critical | 10.0 | 2 | Phishing, Ransomware Attack |
| 230 | Improper security configuration | critical | 10.0 | 2 | Data Breach |
| 231 | CVE-2026-24291 (RegPwn) | critical | 10.0 | 2 | Privilege Escalation |
| 232 | Scoped Storage limitations (Android 10+) | critical | 10.0 | 2 | ransomware |
| 233 | CVE-2025-43529 | critical | 10.0 | 2 | Exploit Kit, Supply Chain Attack |
| 234 | Citrix vulnerabilities | critical | 10.0 | 2 | Ransomware, Cybercrime |
| 235 | Known vulnerability that had not been patched | critical | 10.0 | 2 | Ransomware, Data Breach |
| 236 | MOVEit Transfer software zero-day vulnerability | critical | 10.0 | 2 | Data Breach |
| 237 | CVE-2025-3248 | critical | 10.0 | 2 | Remote Code Execution, Vulnerability Exploitation |
| 238 | inadequate network segmentation | critical | 10.0 | 2 | ransomware |
| 239 | Lack of Encryption (Data at Rest/In Transit) | critical | 10.0 | 2 | Data Breach (General Discussion), Data Breach |
| 240 | CVE-2025-20362 | critical | 10.0 | 2 | Vulnerability Exploitation, Data Breach, Persistent Malware, Unauthorized Access |
| 241 | CVE-2025-31277 | critical | 10.0 | 2 | Exploit Kit, Supply Chain Attack |
| 242 | CVE-2026-63030 | critical | 10.0 | 2 | Zero-day exploit, SQL Injection, Remote Code Execution (RCE) |
| 243 | CVE-2026-58231 | critical | 10.0 | 2 | Memory Corruption, Remote Code Execution (RCE) |
| 244 | CVE-2025-4322 | critical | 10.0 | 2 | Privilege Escalation |
| 245 | CVE-2026-0768 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 246 | Human vulnerability through impersonation | critical | 10.0 | 2 | Data Breach, Social Engineering Attack |
| 247 | CVE-2025-8110 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 248 | Human (Help Desk Personnel) | critical | 10.0 | 2 | Ransomware and Data Theft, Ransomware and Data Breach |
| 249 | Leaked credentials | critical | 10.0 | 2 | Phishing, Cloud Misconfiguration Exploitation |
| 250 | CVE-2026-41089 | critical | 10.0 | 2 | Ransomware, Remote Code Execution (RCE) |
| 251 | Insufficient Monitoring | critical | 10.0 | 2 | Data Breach |
| 252 | CVE-2025-8088 | critical | 10.0 | 2 | Zero-day exploitation, Phishing, Malware installation, Cyberespionage |
| 253 | CVE-2026-47301 | critical | 10.0 | 2 | Privilege Escalation, Remote Code Execution (RCE) |
| 254 | CVE-2026-3055 (Citrix NetScaler) | critical | 10.0 | 2 | AI-driven cyberattack, data_breach |
| 255 | CVE-2026-60004 (Gitea) | critical | 10.0 | 2 | Data Breach, Zero-day Exploit |
| 256 | CVE-2026-20131 (Cisco Secure Firewall Management Center) | critical | 10.0 | 2 | Ransomware, ransomware |
| 257 | Oracle eBusiness Suite vulnerability | critical | 10.0 | 2 | Data Breach |
| 258 | CVE-2026-4480 | critical | 10.0 | 2 | Vulnerability Exploitation, Remote Code Execution (RCE) |
| 259 | Unpatched IoT Devices | critical | 10.0 | 2 | Data Breach, Distributed Denial-of-Service (DDoS) Attack |
| 260 | Cleo file transfer software | critical | 10.0 | 2 | Ransomware |
| 261 | Citrix Vulnerability | critical | 10.0 | 2 | Cyberattack |
| 262 | SonicWall firewall | critical | 10.0 | 2 | Data Breach, Ransomware Attack |
| 263 | human vulnerability (social engineering) | critical | 10.0 | 2 | phishing, data breach |
| 264 | CVE-2025-48828 | critical | 10.0 | 2 | Vulnerability Exploitation, Remote Code Execution |
| 265 | CVE-2024-36401 | critical | 10.0 | 2 | Exploitation of Vulnerability, Malware Distribution and Data Exfiltration |
| 266 | Code Vulnerability | critical | 10.0 | 2 | Data Breach |
| 267 | CVE-2018-0171 | critical | 10.0 | 2 | Ransomware, Vulnerability Exploitation |
| 268 | CVE-2024-55956 | critical | 10.0 | 2 | Ransomware, Data Breach |
| 269 | Oracle E-Business Suite | critical | 10.0 | 2 | Ransomware |
| 270 | Email System Vulnerability | critical | 10.0 | 2 | Data Breach |
| 271 | CVE-2024-21887 | critical | 10.0 | 2 | Ransomware, Zero-Day Exploit |
| 272 | CVE-2025-7775 (Citrix NetScaler) | critical | 10.0 | 2 | Ransomware |
| 273 | CVE-2025-49113 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 274 | CVE-2026-16232 | critical | 10.0 | 2 | AI Security Breach, Authentication Bypass |
| 275 | Email System | critical | 10.0 | 2 | Data Breach |
| 276 | CVE-2023-27350 (PaperCut) | critical | 10.0 | 2 | Ransomware, ransomware |
| 277 | Old vulnerabilities | critical | 10.0 | 2 | Data Theft, Spyware |
| 278 | CVE-2008-4128 | critical | 10.0 | 2 | Ransomware, Cross-Site Request Forgery (CSRF) |
| 279 | CVE-2026-60137 | critical | 10.0 | 2 | Zero-day exploit, SQL Injection, Remote Code Execution (RCE) |
| 280 | CVE-2026-0920 | critical | 10.0 | 2 | Backdoor |
| 281 | Weak SSH credentials | critical | 10.0 | 2 | DDoS Attack, DDoS |
| 282 | CVE-2024-XXXX | critical | 10.0 | 2 | Authentication Bypass, Vulnerability Exploitation |
| 283 | CI/CD pipeline compromise | critical | 10.0 | 2 | supply chain attack, Supply Chain Attack |
| 284 | CVE-2025-54309 | critical | 10.0 | 2 | Zero-Day Exploitation, Zero-Day Vulnerability |
| 285 | CVE-2024-1709 (ScreenConnect) | critical | 10.0 | 2 | Ransomware |
| 286 | WordPress vulnerabilities | critical | 10.0 | 2 | Botnet, Website Defacement |
| 287 | Microsoft IIS | critical | 10.0 | 2 | ransomware, Supply Chain Attack |
| 288 | CVE-2025-59528 | critical | 10.0 | 2 | Remote Code Execution (RCE), Code Injection |
| 289 | Oracle eBusiness Suite security flaw | critical | 10.0 | 2 | Data Breach |
| 290 | Phished login credentials | critical | 10.0 | 2 | Hack, Cyber Attack |
| 291 | CVE-2026-44756 (OVERPASS) | critical | 10.0 | 2 | Memory Corruption, AI-driven attack |
| 292 | CVE-2025-33073 | critical | 10.0 | 2 | Ransomware, Privilege Escalation |
| 293 | VPN vulnerabilities | critical | 10.0 | 2 | ransomware |
| 294 | CVE-2026-22678 | critical | 10.0 | 2 | Stored Cross-Site Scripting (XSS), XSS |
| 295 | Oracle EBS vulnerability | critical | 10.0 | 2 | Data Breach |
| 296 | known vulnerabilities | critical | 10.0 | 2 | ransomware |
| 297 | Remote code execution | critical | 10.0 | 2 | Espionage, Data Privacy and Cybersecurity Advisory |
| 298 | Human vulnerability through phishing | critical | 10.0 | 2 | Ransomware, Phishing |
| 299 | Network infrastructure | critical | 10.0 | 2 | Data Breach, Cyber Sabotage |
| 300 | CVE-2025-33053 | critical | 10.0 | 2 | Remote Code Execution, Advanced Persistent Threat (APT) |
| 301 | Lack of Employee Awareness | critical | 10.0 | 2 | Human Error, Data Breach |
| 302 | Known software vulnerabilities | critical | 10.0 | 2 | Cyber Espionage, Sabotage, Vulnerability Exploitation |
| 303 | CVE-2021-44026 | critical | 10.0 | 2 | Data Breach, Cyberespionage |
| 304 | CVE-2026-42271 | critical | 10.0 | 2 | Command Injection, Remote Code Execution (RCE) |
| 305 | CVE-2025-48827 | critical | 10.0 | 2 | Vulnerability Exploitation, Remote Code Execution |
| 306 | CVE-2026-20253 | critical | 10.0 | 2 | Data Breach, Vulnerability Exploitation |
| 307 | lack of user awareness | critical | 10.0 | 2 | phishing, social engineering |
| 308 | CVE-2017-0199 | critical | 10.0 | 2 | Cyber Espionage, cyber espionage |
| 309 | Arbitrary Code Execution | critical | 10.0 | 2 | Vulnerability Exploitation, Misconfiguration |
| 310 | Weak OAuth Token Management | critical | 10.0 | 2 | Data Breach |
| 311 | CVE-2024-9680 | critical | 10.0 | 2 | Cyber Espionage, Zero-Day Exploit |
| 312 | CVE-2024-49039 | critical | 10.0 | 2 | Cyber Espionage, Zero-Day Exploit |
| 313 | CVE-2024-27198 (JetBrains TeamCity) | critical | 10.0 | 2 | Ransomware, ransomware |
| 314 | CVE-2026-66066 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 315 | CVE-2024-1708 (ConnectWise ScreenConnect) | critical | 10.0 | 2 | Ransomware, ransomware |
| 316 | CVE-2026-15409 | critical | 10.0 | 2 | Ransomware, Zero-Day Exploitation |
| 317 | CVE-2026-34990 | critical | 10.0 | 2 | Zero-Day Vulnerability, Vulnerability Exploitation |
| 318 | Default or Weak Credentials | critical | 10.0 | 2 | Cyberattack, Cloud Security Breach |
| 319 | Cross-Site Scripting (XSS) | critical | 10.0 | 2 | Vulnerability |
| 320 | Weak Password Management | critical | 10.0 | 2 | Malware Infection, Data Breach |
| 321 | Unencrypted, non-password-protected database | critical | 10.0 | 2 | Data Leak |
| 322 | EternalBlue | critical | 10.0 | 2 | Ransomware |
| 323 | CVE-2019-1068 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 324 | CVE-2026-34980 | critical | 10.0 | 2 | Zero-Day Vulnerability, Vulnerability Exploitation |
| 325 | CVE-2024-1086 | critical | 10.0 | 2 | vulnerability exploitation, Privilege Escalation |
| 326 | Poor Data Governance | critical | 10.0 | 2 | Data Breach |
| 327 | Microsoft Exchange Server vulnerabilities (HAFNIUM campaign) | critical | 10.0 | 2 | Cyber Espionage |
| 328 | CVE-2026-46817 | critical | 10.0 | 2 | Phishing, Vulnerability Exploitation |
| 329 | CVE-2026-60004 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 330 | Unauthorized access to an employee’s email account | critical | 10.0 | 2 | Data Breach |
| 331 | CVE-2024-50623 | critical | 10.0 | 2 | Ransomware, Data Breach |
| 332 | CVE-2023-21529 (Microsoft Exchange) | critical | 10.0 | 2 | Ransomware, ransomware |
| 333 | CVE-2023-48788 (Fortinet FortiClient EMS) | critical | 10.0 | 2 | Ransomware |
| 334 | CVE-unknown (MOVEit Transfer zero-day) | critical | 10.0 | 2 | ransomware, Data Breach |
| 335 | CVE-2026-20349 | critical | 10.0 | 2 | Data Breach, Denial-of-Service (DoS) |
| 336 | CVE-2026-15410 | critical | 10.0 | 2 | Ransomware, Zero-Day Exploitation |
| 337 | Improper Credential Management | critical | 10.0 | 2 | Credential Exposure, Supply Chain Attack |
| 338 | CVE-2025-53770 (ToolShell) | critical | 10.0 | 2 | Cyber Espionage |
| 339 | CVE-2025-6543 | critical | 10.0 | 2 | Cyber Attack, Zero-day exploitation |
| 340 | CVE-2025-1268 | critical | 10.0 | 2 | Vulnerability and Potential Breach, Vulnerability |
| 341 | MOVEit Transfer zero-day vulnerability | critical | 10.0 | 2 | Data Breach |
| 342 | Infostealer Malware | critical | 10.0 | 2 | Data Breach |
| 343 | CVE-2026-48710 | critical | 10.0 | 2 | Command Injection, Remote Code Execution (RCE) |
| 344 | Signature-Based Detection Gaps | critical | 10.0 | 2 | Operational Risk, Supply Chain Attack |
| 345 | CVE-2023-3519 (Citrix NetScaler) | critical | 10.0 | 2 | Ransomware, cyberespionage |
| 346 | CVE-2024-21412 | critical | 10.0 | 2 | Ransomware, Cyberattack |
| 347 | Misconfigured system | critical | 10.0 | 2 | Data Breach, Alleged Data Breach |
| 348 | Weak Authentication Mechanisms | critical | 10.0 | 2 | cybercrime, Data Breach |
| 349 | Cloud Storage Service Vulnerability | critical | 10.0 | 2 | Data Breach |
| 350 | Misconfigured Access Controls | critical | 10.0 | 2 | Data Breach, Data Privacy and Cybersecurity Advisory |
| 351 | Human error (social engineering susceptibility) | critical | 10.0 | 2 | Ransomware, Data Breach |
| 352 | Remote code execution vulnerability | critical | 10.0 | 2 | Remote Code Execution, Remote Code Execution (RCE) |
| 353 | Misconfigured cloud storage | critical | 10.0 | 2 | Data Breach |
| 354 | ATM Network Processing | critical | 10.0 | 2 | Data Breach |
| 355 | Citrix Netscaler ADC/Gateway vulnerabilities | critical | 10.0 | 2 | Ransomware, Vulnerability Exploitation |
| 356 | Misconfigured deployments | critical | 10.0 | 2 | Ransomware, Misconfiguration |
| 357 | Phishing Email | critical | 10.0 | 2 | Data Breach |
| 358 | weak identity management | critical | 10.0 | 2 | Data Breach, identity-related breach |
| 359 | Zero-Day Vulnerability in SonicWall SSL VPN | critical | 10.0 | 2 | Ransomware |
| 360 | poor password hygiene | critical | 10.0 | 2 | ransomware, Human Error |
| 361 | Legacy infrastructure | critical | 10.0 | 2 | Ransomware, AI-Powered Cyberattack |
| 362 | public-facing application vulnerabilities | critical | 10.0 | 2 | ransomware, Data Breach |
| 363 | Misconfigured cloud environments | critical | 10.0 | 2 | AI-driven cyber attack, ransomware |
| 364 | Online Payment System Vulnerability | critical | 10.0 | 2 | Data Breach |
| 365 | poor security practices | critical | 10.0 | 2 | espionage, Data Breach |
| 366 | Privilege Escalation | critical | 10.0 | 2 | Ransomware, Vulnerability Exploitation |
| 367 | Outdated operating systems | critical | 10.0 | 2 | Cyberattack, data breach |
| 368 | Compromised vendor credentials | critical | 10.0 | 2 | Data Breach, Phishing, Malware Distribution |
| 369 | Lack of Employee Training | critical | 10.0 | 2 | Ransomware, phishing |
| 370 | Remote access vulnerabilities | critical | 10.0 | 2 | Ransomware, ransomware |
| 371 | lack_of_MFA | critical | 10.0 | 2 | ransomware, data_breach |
| 372 | unknown security gap | critical | 10.0 | 2 | ransomware |
| 373 | Microsoft SharePoint vulnerabilities | critical | 10.0 | 2 | Data Breach, cyberattack |
| 374 | network vulnerabilities | critical | 10.0 | 2 | Ransomware, ransomware |
| 375 | CVE-2025-61884 (Oracle E-Business Suite Zero-Day) | critical | 10.0 | 2 | Data Breach, data breach |
| 376 | Legacy IT systems | critical | 10.0 | 2 | Ransomware Attack, Cyber Attack |
| 377 | Delayed patch management | critical | 10.0 | 2 | Ransomware, Data Breach |
| 378 | Social Engineering / Phishing | critical | 10.0 | 2 | Business Email Compromise (BEC), Spear Phishing |
| 379 | lack of signal authentication | critical | 10.0 | 2 | Data Interception, spoofing |
| 380 | Lack of Package Integrity Verification | critical | 10.0 | 2 | supply-chain attack, Supply Chain Attack |
| 381 | Vulnerable IoT Devices | critical | 10.0 | 2 | Botnet Disruption, State-Sponsored Cyber Espionage |
| 382 | User Trust in App Store | critical | 10.0 | 2 | Malware |
| 383 | weak MFA | critical | 10.0 | 2 | Data Breach, data_breach |
| 384 | Industrial Control Systems (ICS) | critical | 10.0 | 2 | ransomware, Cyberattack |
| 385 | System Misconfiguration | critical | 10.0 | 2 | Data Breach, AI-driven cyberattack |
| 386 | Exposed API key | critical | 10.0 | 2 | Cloud Security Breach, Zero-day exploitation |
| 387 | Lack of IP restrictions | critical | 10.0 | 2 | Data Breach |
| 388 | Brute force attacks | critical | 10.0 | 2 | Extortion / Data Leak Threat, Authentication Security Improvement |
| 389 | Exposed credentials | critical | 10.0 | 2 | phishing, AI-driven cyberattack |
| 390 | Misconfigured MongoDB Database | critical | 10.0 | 2 | Data Exposure, Data Breach |
| 391 | Hardcoded credentials | critical | 10.0 | 2 | Misconfiguration, Cyber Attack |
| 392 | Known vulnerability | critical | 10.0 | 2 | Ransomware Attack, Data Leak |
| 393 | Cloud Storage Misconfiguration | critical | 10.0 | 2 | Data Breach, Misconfiguration |
| 394 | Third-party vulnerabilities | critical | 10.0 | 2 | Data Breach |
| 395 | Microsoft Exchange server vulnerabilities | critical | 10.0 | 2 | Ransomware, Vulnerability Exploitation |
| 396 | SQL injection vulnerability in MOVEit Transfer | critical | 10.0 | 2 | Ransomware |
| 397 | Authentication Bypass | critical | 8.5 | 2 | Authentication Bypass, Malware Distribution |
| 398 | CVE-2026-22219 | critical | 8.5 | 2 | Data Breach, Vulnerability Exploitation |
| 399 | Accessibility Service Abuse | critical | 8.5 | 2 | Banking Malware, Malware (Banking Trojan) |
| 400 | Third-party system vulnerability | critical | 8.5 | 2 | Data Breach |
| 401 | Overprivileged Access | critical | 8.5 | 2 | Data Breach |
| 402 | Compromised employee account | critical | 8.5 | 2 | Data Breach |
| 403 | Progress Software's MOVEit Transfer software | critical | 8.5 | 2 | Data Breach |
| 404 | HTML rendering race condition | critical | 8.5 | 2 | Data Exfiltration, Vulnerability Exploitation |
| 405 | Android Accessibility Services | critical | 8.5 | 2 | Malware-as-a-Service (MaaS), Malware (Banking Trojan) |
| 406 | CVE-2025-47813 | critical | 8.5 | 2 | Information Disclosure, Remote Code Execution, Vulnerability Exploitation |
| 407 | inadequate vendor oversight | critical | 8.5 | 2 | ransomware, data breach |
| 408 | Unprotected Server | critical | 8.5 | 2 | Data Breach |
| 409 | Access Control | critical | 8.5 | 2 | Data Breach |
| 410 | CVE-2026-39808 | critical | 8.5 | 2 | Data Breach, OS command injection |
| 411 | UAC bypass | critical | 8.5 | 2 | ransomware, Malware (RAT) |
| 412 | SSRF | critical | 8.5 | 2 | SSRF Vulnerability, Malware Distribution |
| 413 | Human Error (Falling for Phishing Scam) | critical | 8.5 | 2 | Data Breach (Phishing), Data Breach |
| 414 | Insufficient Multi-Factor Authentication (MFA) | critical | 8.5 | 2 | Data Breach |
| 415 | CVE-2026-9547 | critical | 8.5 | 2 | Vulnerability Disclosure, Vulnerability Exploitation |
| 416 | Software Coding Issue | critical | 8.5 | 2 | Data Breach |
| 417 | Broken Access Control | critical | 8.5 | 2 | API Vulnerability, Vulnerability Exploitation |
| 418 | CVE-2026-39987 | critical | 8.5 | 2 | Remote Code Execution (RCE) |
| 419 | Critical security flaw in License Express system | critical | 8.5 | 2 | Data Breach, Data Security Failure |
| 420 | CVE-2026-21510 | critical | 8.5 | 2 | Zero-Day Vulnerability |
| 421 | CVE-2026-20262 | critical | 8.5 | 2 | Data Breach, Zero-Day Exploitation |
| 422 | Incorrect privacy settings on a public mapping website | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 423 | missing authentication | critical | 8.5 | 2 | data breach |
| 424 | CVE-2026-23795 | critical | 8.5 | 2 | XXE (XML External Entity) Vulnerability, Supply Chain Attack |
| 425 | API vulnerability | critical | 8.5 | 2 | Data Breach |
| 426 | CVE-2026-3910 | critical | 8.5 | 2 | Zero-Day Vulnerability Exploitation, Zero-day Exploitation |
| 427 | Lack of Identity Verification | critical | 8.5 | 2 | Fraud, Data Breach |
| 428 | CVE-2026-26110 (Type Confusion - CWE-843) | critical | 8.5 | 2 | Vulnerability, Remote Code Execution (RCE) |
| 429 | Compromised User Account | critical | 8.5 | 2 | Data Breach |
| 430 | CVE-2026-39813 | critical | 8.5 | 2 | Data Breach, OS command injection |
| 431 | MOVEit web transfer application vulnerability | critical | 8.5 | 2 | Data Breach |
| 432 | Compromised email account credentials | critical | 8.5 | 2 | Phishing, Phishing Attack |
| 433 | CVE-2026-12958 | critical | 8.5 | 2 | Arbitrary Code Execution, Supply Chain Attack |
| 434 | Misconfigured Elasticsearch Database | critical | 8.5 | 2 | Data Exposure, Data Leak |
| 435 | Insecure Data Storage | critical | 8.5 | 2 | Data Collection, Data Breach |
| 436 | Social Engineering, Trust Exploitation | critical | 8.5 | 2 | Phishing |
| 437 | Leaked Passwords | critical | 8.5 | 2 | Data Breach, Account Hijacking, Data Theft, Sextortion |
| 438 | Weak email account security | critical | 8.5 | 2 | Data Breach |
| 439 | Inadequate Vendor Vetting | critical | 8.5 | 2 | Data Breach |
| 440 | CVE-2026-2413 | critical | 8.5 | 2 | SQL Injection |
| 441 | CVE-2026-12957 | critical | 8.5 | 2 | Arbitrary Code Execution, Supply Chain Attack |
| 442 | CVE-2026-3909 | critical | 8.5 | 2 | Zero-Day Vulnerability Exploitation, Zero-day Exploitation |
| 443 | Okta SSO Credentials | critical | 8.5 | 2 | Data Breach |
| 444 | CVE-2025-41244 | critical | 8.5 | 2 | Privilege Escalation |
| 445 | Poor data visibility settings | critical | 8.5 | 2 | Data Exposure |
| 446 | CVE-2025-54309 (CrushFTP) | critical | 8.5 | 2 | Ransomware, Exploit Trends |
| 447 | CVE-2026-34621 (Adobe Acrobat Reader) | critical | 8.5 | 2 | Data Breach, Vulnerability Exploitation |
| 448 | CVE-2026-22218 | critical | 8.5 | 2 | Data Breach, Vulnerability Exploitation |
| 449 | CVE-2026-8925 | critical | 8.5 | 2 | Vulnerability Disclosure, Vulnerability Exploitation |
| 450 | Insufficient access controls and monitoring | critical | 8.5 | 2 | Data Breach, Insider Threat |
| 451 | Oracle E-Business Suite software vulnerability | critical | 8.5 | 2 | Data Breach |
| 452 | CVE-2025-55177 (WhatsApp incomplete authorization) | critical | 8.5 | 2 | Zero-day exploit, Zero-day vulnerability |
| 453 | Unsecured MongoDB Database | critical | 8.5 | 2 | Data Breach |
| 454 | Code Injection | critical | 8.5 | 2 | Data Breach |
| 455 | Inadvertent Disclosure | critical | 8.5 | 2 | Data Breach |
| 456 | Oracle PeopleSoft vulnerability | critical | 8.5 | 2 | Ransomware, Data Breach |
| 457 | System Configuration Error | critical | 8.5 | 2 | Data Breach |
| 458 | CVE-2026-32201 (Improper Input Validation - CWE-20) | critical | 8.5 | 2 | Zero-Day Exploitation, Zero-Day Vulnerability |
| 459 | Unpatched network devices | critical | 8.5 | 2 | DDoS, Malware |
| 460 | MOVEit Transfer (CVE-2023-34362 or related) | critical | 8.5 | 2 | Data Breach |
| 461 | Misconfigured Rsync Server | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 462 | Improper Access Controls (Publicly Accessible Database) | critical | 8.5 | 2 | Data Leak, data breach |
| 463 | Long-lived tokens | critical | 8.5 | 2 | Data Breach |
| 464 | Access Credentials | critical | 8.5 | 2 | Data Breach |
| 465 | Misconfigured Elasticsearch Instance | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 466 | Unsecured MongoDB Instance | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 467 | Parameter-to-Prompt (P2P) Injection | critical | 8.5 | 2 | Data Exfiltration, Vulnerability Exploitation |
| 468 | Unsecured ElasticSearch cluster | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 469 | Unsecured Amazon S3 Bucket | critical | 8.5 | 2 | Data Breach |
| 470 | Improper access controls on Amazon S3 bucket | critical | 8.5 | 2 | Data Breach |
| 471 | CVE-2025-21043 (Out-of-Bounds Write in libimagecodec.quram.so) | critical | 8.5 | 2 | Vulnerability Exploitation |
| 472 | unencrypted sensitive data | critical | 8.5 | 2 | data breach, Quantum Computing Threat |
| 473 | weak email security controls | critical | 8.5 | 2 | Data Breach, data breach |
| 474 | Publicly available data | critical | 8.5 | 2 | Data Breach |
| 475 | Salesforce Misconfiguration | critical | 8.5 | 2 | Data Breach |
| 476 | Unsecured Flash Drive | critical | 8.5 | 2 | Data Breach |
| 477 | Unauthorized access by authorized user | critical | 8.5 | 2 | Data Breach, Insider Data Theft |
| 478 | lack of awareness | critical | 8.5 | 2 | data breach, Awareness Campaign |
| 479 | Unsecured APIs | critical | 8.5 | 2 | ransomware, Data Leak |
| 480 | Lack of Physical Security for Sensitive Device | critical | 8.5 | 2 | Data Breach (Physical Theft) |
| 481 | Unauthorized code injection | critical | 8.5 | 2 | Data Breach |
| 482 | Inadequate Data Security Measures | critical | 8.5 | 2 | Data Breach |
| 483 | Missing access controls | critical | 8.5 | 2 | Unauthorized Access, Data Exposure |
| 484 | GoAnywhere Zero-Day Vulnerability | critical | 8.5 | 2 | Ransomware, Data Breach, Ransomware |
| 485 | Technical Glitch | critical | 8.0 | 2 | Data Breach |
| 486 | Identity Theft | critical | 8.0 | 2 | Identity Theft, Data Breach |
| 487 | Unauthorized Data Sharing | critical | 8.0 | 2 | Data Breach |
| 488 | Improper Disposal of Sensitive Information | critical | 8.0 | 2 | Data Breach |
| 489 | Inadequate Physical Security | high | 7.5 | 2 | physical cyber convergence, Data Breach |
| 490 | MOVEit Transfer service | high | 6.0 | 2 | Data Breach |
| 491 | Corporate Email Account | high | 6.0 | 2 | Data Breach |
| 492 | Compromised Account Credentials | high | 6.0 | 2 | Data Breach, Unauthorized Access, DNS Manipulation |
| 493 | Human Error/Insider Threat | high | 6.0 | 2 | Data Breach |
| 494 | Unencrypted Payment Card Information | high | 6.0 | 2 | Data Breach |
| 495 | Inadvertent Email | high | 6.0 | 2 | Data Breach |
| 496 | Loss of Physical Media | high | 6.0 | 2 | Data Breach |
| 497 | Website Misconfiguration | high | 6.0 | 2 | Data Exposure, Data Breach |
| 498 | CVE-2018-3952 | high | 6.0 | 2 | Vulnerability Exploitation, Vulnerability Exploit |
| 499 | ATM Security | high | 6.0 | 2 | Data Breach, ATM Skimming/Shimming |
| 500 | Clipboard Hijacking | high | 6.0 | 2 | Cryptocurrency Theft, Malware (Browser Extension) |
| 501 | Lack of Multi-Factor Authentication (MFA) on Slack | high | 6.0 | 2 | Data Breach, data breach |
| 502 | Compromised Microsoft Office 365 account | high | 6.0 | 2 | Data Breach, Business Email Compromise (BEC) |
| 503 | Point-of-Sale Device | high | 6.0 | 2 | Data Breach |
| 504 | Improper Disposal | medium | 5.0 | 2 | Data Breach |
| 505 | MOVEit Transfer software vulnerabilities | medium | 5.0 | 2 | Data Breach |
| 506 | Tax Filing Software | medium | 5.0 | 2 | Data Breach |
| 507 | Reused credentials | medium | 5.0 | 2 | Data Breach |
| 508 | HTML Injection | medium | 5.0 | 2 | Prompt Injection, Vulnerability Exploitation |
| 509 | CVE-2026-1504 | low | 2.5 | 2 | Vulnerability |
| 510 | Unsecured Physical Records | low | 2.5 | 2 | Data Breach |
| 511 | CVE-2026-0049 | low | 2.5 | 2 | Vulnerability |
| 512 | CVE-2024-7399 | low | 2.5 | 2 | Vulnerability Exploitation, Botnet Infection |
| 513 | Citrix Bleed | critical | 10.0 | 1 | Ransomware Attack |
| 514 | Unencrypted POS devices | critical | 10.0 | 1 | Data Breach |
| 515 | Compromised Polyfill.io service | critical | 10.0 | 1 | Supply Chain Attack |
| 516 | Web application stack | critical | 10.0 | 1 | Data Breach |
| 517 | CVE-2025-49144 | critical | 10.0 | 1 | Privilege Escalation |
| 518 | CVE-2017-17215 (TP-Link Routers) | critical | 10.0 | 1 | Botnet / DDoS Campaign |
| 519 | Lack of oversight in outsourcing, contractual violations | critical | 10.0 | 1 | Data Breach |
| 520 | Unauthorized access to departmental server | critical | 10.0 | 1 | Espionage |
| 521 | CVE-2024-1182 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 522 | BitLocker bypass bug | critical | 10.0 | 1 | Zero-day exploit |
| 523 | Unchecked nesting-stack write | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 524 | Programmable logic controllers (PLCs) | critical | 10.0 | 1 | Cyberattack |
| 525 | Volume Shadow Copy Service | critical | 10.0 | 1 | Ransomware |
| 526 | Insecure remote access, weak passwords, lack of network segmentation | critical | 10.0 | 1 | Cyberattack |
| 527 | Memory corruption in Zoom’s annotation processing | critical | 10.0 | 1 | Zero-Click Exploit |
| 528 | SharePoint vulnerabilities | critical | 10.0 | 1 | cyber espionage |
| 529 | CVE-2023-49105 (ownCloud) | critical | 10.0 | 1 | Data Breach |
| 530 | CVE-2026-86218 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 531 | Lack of Business Continuity Plans | critical | 10.0 | 1 | Ransomware |
| 532 | Trojanized Software Supply Chain | critical | 10.0 | 1 | Targeted Attack |
| 533 | Weak supply-chain security | critical | 10.0 | 1 | Data Breach |
| 534 | Legacy Authentication Protocols (e.g., SAMLjacking) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 535 | Lack of Visibility into Privileged Account Usage | critical | 10.0 | 1 | Data Breach |
| 536 | Remote Work Security Blind Spots | critical | 10.0 | 1 | Cybercrime |
| 537 | Zero-day exploits (up to a week before public disclosure) | critical | 10.0 | 1 | Ransomware |
| 538 | Internet-facing OT devices, project files in PLCs | critical | 10.0 | 1 | Cyberattack |
| 539 | unauthorized remote access | critical | 10.0 | 1 | cyber-physical attack |
| 540 | Remote Code Execution (RCE) zero-day in Oracle E-Business Suite (versions 12.2.3-12.2.14) | critical | 10.0 | 1 | ransomware |
| 541 | XAML deserialization | critical | 10.0 | 1 | Cyber Espionage |
| 542 | CVE-2026-8711 (Heap Buffer Overflow in NGINX JavaScript) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 543 | CVE-2024-55591 (FortiOS/FortiProxy authentication bypass) | critical | 10.0 | 1 | Ransomware |
| 544 | Login bypass vulnerability, improper access controls | critical | 10.0 | 1 | Data Leak, Unauthorized Access, Remote Exploitation |
| 545 | Blind Spots in Monitoring | critical | 10.0 | 1 | Ransomware |
| 546 | Vulnerability in Ivanti's security products | critical | 10.0 | 1 | Malware |
| 547 | Unsecured RDP | critical | 10.0 | 1 | Ransomware |
| 548 | Undocumented Warbird framework | critical | 10.0 | 1 | Supply Chain Attack |
| 549 | Understaffed Security Operations Center (SOC) | critical | 10.0 | 1 | Data Breach |
| 550 | Oracle E-Business Suite vulnerability (patched post-incident) | critical | 10.0 | 1 | Ransomware |
| 551 | Open-source LD_PRELOAD rootkit (Medusa) repurposed for malicious use | critical | 10.0 | 1 | Rootkit |
| 552 | Shallow Depth of Baltic Sea (Ease of Anchor Damage) | critical | 10.0 | 1 | Physical Sabotage |
| 553 | Unspecified Adobe ColdFusion Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 554 | Spear-phishing campaigns | critical | 10.0 | 1 | Data Breach |
| 555 | Zero-day exploit in a widely used government software | critical | 10.0 | 1 | Cyberattack |
| 556 | weak RDP credentials | critical | 10.0 | 1 | ransomware |
| 557 | npm package hijacking | critical | 10.0 | 1 | supply chain attack |
| 558 | Lack of physical security for sensitive data display | critical | 10.0 | 1 | Data Breach |
| 559 | Unsalted Password Hashes (pre-remediation) | critical | 10.0 | 1 | Data Breach |
| 560 | RC4 encryption (obsolete since 1980s) | critical | 10.0 | 1 | ransomware |
| 561 | Dependence on unencrypted GPS signals for navigation and communication | critical | 10.0 | 1 | GPS jamming |
| 562 | CVE-2019-9569 (Delta Controls enteliBUS - RCE via crafted BACnet traffic) | critical | 10.0 | 1 | Vulnerability Exposure |
| 563 | File transfer software vulnerability | critical | 10.0 | 1 | Data Breach |
| 564 | OWASSRF | critical | 10.0 | 1 | Ransomware Attack |
| 565 | Unauthenticated APIs | critical | 10.0 | 1 | Cyber Espionage |
| 566 | Technical error (premature website publication) | critical | 10.0 | 1 | Data Leak / Unauthorized Disclosure |
| 567 | Cloud provider vulnerabilities | critical | 10.0 | 1 | Data Theft and Extortion |
| 568 | CVE-2025-52691 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 569 | Human Vulnerability (Phishing/Social Engineering Susceptibility) | critical | 10.0 | 1 | Account Compromise |
| 570 | over-reliance on technological defenses | critical | 10.0 | 1 | phishing |
| 571 | Backdoor in M.E.Doc software updates (Intellect Service) | critical | 10.0 | 1 | Cyber Attack |
| 572 | Follina | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 573 | Unpatched legacy systems | critical | 10.0 | 1 | Ransomware |
| 574 | Latent firmware flaw in Coldcard hardware wallets | critical | 10.0 | 1 | Data Breach, Theft |
| 575 | Unauthenticated File Read | critical | 10.0 | 1 | Vulnerability Exploitation |
| 576 | Unauthorized access via compromised civil servant credentials | critical | 10.0 | 1 | Data Breach |
| 577 | Insufficient Physical Security for Fiber-Optic Cables | critical | 10.0 | 1 | Cyber Espionage |
| 578 | CVE-2026-25177 | critical | 10.0 | 1 | Privilege Escalation |
| 579 | Unsafe dynamic code generation in `Type.generateConstructor` (CVE not assigned, GHSA-xq3m-2v4x-88gg) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 580 | GreenPlasma (Windows zero-day) | critical | 10.0 | 1 | Zero-day Exploit |
| 581 | Security Incident During Server Setup | critical | 10.0 | 1 | Ransomware |
| 582 | delayed patching | critical | 10.0 | 1 | phishing |
| 583 | Lack of anti-jamming protection for GPS systems | critical | 10.0 | 1 | GPS jamming |
| 584 | Previously unknown vulnerability in email system | critical | 10.0 | 1 | Ransomware |
| 585 | CVE-2026-4368 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 586 | Unsecured remote access tools | critical | 10.0 | 1 | Cyber Espionage |
| 587 | CVE-2025-1727 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 588 | VMware | critical | 10.0 | 1 | ransomware |
| 589 | AI Training Data Exposure | critical | 10.0 | 1 | Cyber Espionage |
| 590 | Malicious code injection in legitimate packages | critical | 10.0 | 1 | Supply Chain Attack |
| 591 | Lack of OIDC verification, unmatched GitHub commits | critical | 10.0 | 1 | Supply Chain Attack |
| 592 | Open Academic Networks in Universities | critical | 10.0 | 1 | Data Breach |
| 593 | Understaffed security operations | critical | 10.0 | 1 | Data Breach |
| 594 | Resident portal credentials harvested over time and leaked in stealer logs | critical | 10.0 | 1 | Ransomware |
| 595 | Fragmented security standards across subcontractors | critical | 10.0 | 1 | Ransomware |
| 596 | GitLab Server Misconfiguration (Red Hat) | critical | 10.0 | 1 | Data Breach |
| 597 | Lack of cybersecurity investment | critical | 10.0 | 1 | Cyberattack |
| 598 | Limited Supply Chain Visibility (beyond first-tier vendors) | critical | 10.0 | 1 | Ransomware |
| 599 | Unpatched Self-Managed GitLab Community Edition | critical | 10.0 | 1 | Data Breach |
| 600 | Zero-day RCE in Artifactory | critical | 10.0 | 1 | Zero-day exploitation |
| 601 | CV_2025_03_1 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 602 | CVE-2024-12912 | critical | 10.0 | 1 | botnet |
| 603 | Weak Detection/Response Capabilities (SMEs) | critical | 10.0 | 1 | Ransomware |
| 604 | Vulnerabilities in RaaS administrative panels | critical | 10.0 | 1 | Ransomware |
| 605 | Partial Logging of Data Access | critical | 10.0 | 1 | Insider Threat |
| 606 | System Migration Bug | critical | 10.0 | 1 | Data Breach |
| 607 | Oracle zero-day (Clop gang) | critical | 10.0 | 1 | ransomware |
| 608 | Abuse of Device Admin and Accessibility Services permissions | critical | 10.0 | 1 | Ransomware |
| 609 | Third-party Salesforce CRM integration | critical | 10.0 | 1 | Data Breach |
| 610 | Improper validation of profile image uploads (SVG files with embedded JavaScript) | critical | 10.0 | 1 | Stored Cross-Site Scripting (XSS) |
| 611 | Vulnerabilities in voting machines and ballot-counting systems | critical | 10.0 | 1 | Data Breach, Election Interference |
| 612 | Unauthenticated file upload vulnerability (Grav CMS) | critical | 10.0 | 1 | Defacement, Data Breach, Extortion |
| 613 | CVE-2012-4701 (Tridium NiagaraAX 3.x - Directory traversal and RCE) | critical | 10.0 | 1 | Vulnerability Exposure |
| 614 | Stale IAM Accounts in AI Environments | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 615 | Lack of Data Handling Training | critical | 10.0 | 1 | Data Breach |
| 616 | cloud migration risks | critical | 10.0 | 1 | ransomware |
| 617 | CVE-2026-10520 | critical | 10.0 | 1 | OS Command Injection |
| 618 | Unauthenticated Redis instances | critical | 10.0 | 1 | Botnet |
| 619 | Implicit trust in supply chains | critical | 10.0 | 1 | Supply Chain Attack, Extortion Campaign |
| 620 | Kickidler employee monitoring tool | critical | 10.0 | 1 | Ransomware |
| 621 | Third-Party Customer Service Provider (Discord) | critical | 10.0 | 1 | Data Breach |
| 622 | CVE-2025-24893 (Critical RCE in XWiki) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 623 | Vulnerabilities in municipal utilities' operational technology (OT) systems | critical | 10.0 | 1 | Cyberattack |
| 624 | Accellion sharing software | critical | 10.0 | 1 | Ransomware |
| 625 | Hikvision vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 626 | Siemens S7 industrial controllers vulnerabilities | critical | 10.0 | 1 | AI-enabled cyberattack |
| 627 | CVE-2021-Log4j (Remote Code Execution) | critical | 10.0 | 1 | Ransomware |
| 628 | CVE-2025-1449 | critical | 10.0 | 1 | Vulnerability Exploit |
| 629 | Potential lack of redundant navigation systems | critical | 10.0 | 1 | GPS spoofing (disputed) |
| 630 | Potential vulnerability in screen monitoring software | critical | 10.0 | 1 | Ransomware |
| 631 | CVE-2026-20131 (Insecure Deserialization - CWE-502) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 632 | CVE-2025-59689 (Command injection in Libraesva ESG) | critical | 10.0 | 1 | Zero-day exploitation |
| 633 | CVE-2025-61882 (CVSS 9.8) - Oracle E-Business Suite Concurrent Processing Component | critical | 10.0 | 1 | Data Breach |
| 634 | Known vulnerabilities dating back to 2018 | critical | 10.0 | 1 | Espionage |
| 635 | Maintenance errors | critical | 10.0 | 1 | Physical Incident |
| 636 | Infrastructure weaknesses | critical | 10.0 | 1 | AI-enabled attack |
| 637 | Default password on PLC, unsecured operational technology (OT) | critical | 10.0 | 1 | Cyberattack |
| 638 | budget reductions | critical | 10.0 | 1 | data breach |
| 639 | Human Weakness | critical | 10.0 | 1 | Data Breach |
| 640 | understaffed municipal services | critical | 10.0 | 1 | physical security breach |
| 641 | Data encryption software vulnerability | critical | 10.0 | 1 | Data Breach |
| 642 | Remote Code Execution in Imunify360 AV deobfuscation logic (versions before v32.7.4.0) | critical | 10.0 | 1 | Vulnerability |
| 643 | CNAME DNS record | critical | 10.0 | 1 | Data Breach |
| 644 | Absence of two-factor authentication | critical | 10.0 | 1 | Ransomware |
| 645 | Vulnerability in data exchange platform | critical | 10.0 | 1 | Data Breach |
| 646 | CVE-2022-22948 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 647 | Operational Security | critical | 10.0 | 1 | Operational Security Breach |
| 648 | CVE-2024-20399 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 649 | Weak internal security segmentation | critical | 10.0 | 1 | Data Breach |
| 650 | VPN weaknesses | critical | 10.0 | 1 | ransomware |
| 651 | Cryptographic flaw in ChaCha20-IETF cipher implementation (nonce overwriting) | critical | 10.0 | 1 | Ransomware (Data Wiper) |
| 652 | DFSCoerce | critical | 10.0 | 1 | Ransomware |
| 653 | Previously unidentified vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 654 | CVE-2026-4681 (CWE-94) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 655 | visibility gap in EDR/SIEM logs | critical | 10.0 | 1 | ransomware |
| 656 | Weakness in `url_safe` feature (Bing.com tracking link evasion) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 657 | Inadequate Cybersecurity Defenses | critical | 10.0 | 1 | Data Breach |
| 658 | Zero-day vulnerabilities in cloud infrastructure/SaaS platforms | critical | 10.0 | 1 | Cybercriminal Alliance Formation |
| 659 | Weak procedures, inadequate staff training, poor data protection practices | critical | 10.0 | 1 | Data Breach |
| 660 | CVE-2026-33825 (CVSS 7.8, High) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 661 | CVE-2023-22527 | critical | 10.0 | 1 | Cryptomining Campaign |
| 662 | Unsecured directory with unrestricted access | critical | 10.0 | 1 | Data Leak |
| 663 | CVE-2025-2857 | critical | 10.0 | 1 | Zero-day Vulnerability |
| 664 | failures in basic cyber hygiene | critical | 10.0 | 1 | ransomware |
| 665 | Legitimate cloud administrative tools | critical | 10.0 | 1 | Data Exfiltration |
| 666 | CVE-2026-8711 (Heap-based buffer overflow in ngx_http_js_module) | critical | 10.0 | 1 | Vulnerability |
| 667 | Spoofable Workflow Notifications | critical | 10.0 | 1 | Social Engineering |
| 668 | Critical vulnerabilities (CVSS 9+) | critical | 10.0 | 1 | Ransomware |
| 669 | CVE-2024-36401 (Critical RCE in GeoServer) | critical | 10.0 | 1 | Cyber Espionage |
| 670 | inadequate administrative/physical/technical safeguards (HIPAA) | critical | 10.0 | 1 | data breach |
| 671 | custom network architectures in CERs | critical | 10.0 | 1 | supply chain attack |
| 672 | CVE-2025-20393 | critical | 10.0 | 1 | Cyberattack |
| 673 | Unauthorized Access by Employee | critical | 10.0 | 1 | Data Breach |
| 674 | Weak Employee Credentials | critical | 10.0 | 1 | Cyberattack Surge |
| 675 | lack of continuous verification | critical | 10.0 | 1 | phishing |
| 676 | Unknown vulnerability in file transfer software | critical | 10.0 | 1 | Ransomware |
| 677 | GreenPlasma (Local privilege escalation) | critical | 10.0 | 1 | Zero-day vulnerability |
| 678 | CVE-2026-82329 | critical | 10.0 | 1 | Authentication Bypass |
| 679 | CVE-2025-55241 (Token Validation Failure in Microsoft Entra ID / Azure AD Graph API) | critical | 10.0 | 1 | Privilege Escalation |
| 680 | CVE-2023-41345 | critical | 10.0 | 1 | botnet |
| 681 | missing security patches | critical | 10.0 | 1 | data breach |
| 682 | Phishing Domains | critical | 10.0 | 1 | Cryptocurrency Scam |
| 683 | CVE-2026-88765 | critical | 10.0 | 1 | Data Breach |
| 684 | unpatched Windows SMB flaw (WannaCry) | critical | 10.0 | 1 | ransomware |
| 685 | Unmanaged OAuth App Permissions (Salesforce, Other SaaS) | critical | 10.0 | 1 | Browser-Based Attack |
| 686 | zero-day vulnerability in Oracle EBusiness Suite | critical | 10.0 | 1 | data breach |
| 687 | Legacy Authentication Methods (Password-Only Logins) | critical | 10.0 | 1 | Browser-Based Attack |
| 688 | CVE-2017-11882 (Microsoft Office) | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 689 | Limited incident response capabilities in SMEs | critical | 10.0 | 1 | Extortion |
| 690 | Kaseya VSA platform | critical | 10.0 | 1 | Ransomware Attack |
| 691 | CVE-2025-22224 | critical | 10.0 | 1 | Ransomware |
| 692 | Indirect prompt injection | critical | 10.0 | 1 | Data Privacy and Cybersecurity Advisory |
| 693 | Disabled authentication in VNC servers | critical | 10.0 | 1 | Exposed Servers |
| 694 | Human psychology | critical | 10.0 | 1 | AI-driven cyberattack |
| 695 | Supply chain vulnerabilities in financial transaction software | critical | 10.0 | 1 | Ransomware |
| 696 | Microsoft Hyper-V virtualization | critical | 10.0 | 1 | Cyber Espionage |
| 697 | CVE-2019-0708 (BlueKeep) | critical | 10.0 | 1 | Cyber Espionage |
| 698 | Unmonitored AI Data Flows | critical | 10.0 | 1 | Data Breach |
| 699 | Misconfigured cloud databases | critical | 10.0 | 1 | Ransomware |
| 700 | Human factor (credentials theft) | critical | 10.0 | 1 | Phishing |
| 701 | CVE-2026-32202 (Windows Shell Spoofing) | critical | 10.0 | 1 | Data Breach |
| 702 | CVE-2026-43284 | critical | 10.0 | 1 | Privilege Escalation |
| 703 | Microsoft SharePoint Server Vulnerabilities (On-Premises) | critical | 10.0 | 1 | Data Breach |
| 704 | Claude Code Model Safeguard Bypass | critical | 10.0 | 1 | Espionage |
| 705 | CVE-2025-34067 (Hikvision - remote code execution) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 706 | Misaligned agent workflows | critical | 10.0 | 1 | AI-driven breach |
| 707 | PackageGate Vulnerabilities | critical | 10.0 | 1 | Supply Chain Attack |
| 708 | Container escape vulnerabilities (e.g., CVE-2025-23266) | critical | 10.0 | 1 | Malware Framework |
| 709 | CVE-2024-7587 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 710 | Unmonitored Privileged Accounts | critical | 10.0 | 1 | Data Breach |
| 711 | Unpatched Cisco ASA device (last patched in 2024) | critical | 10.0 | 1 | Cyberwarfare |
| 712 | MOVEit software | critical | 10.0 | 1 | Data Breach |
| 713 | Default credentials on WAGO PFC200 PLC | critical | 10.0 | 1 | OT Breach |
| 714 | CVE-2024-56325 | critical | 10.0 | 1 | Vulnerability Exploit |
| 715 | SonicWall SSL VPN Misconfiguration | critical | 10.0 | 1 | Unauthorized Access |
| 716 | Poor access controls and credential management for third-party code repositories | critical | 10.0 | 1 | Data Breach |
| 717 | Long-lived AWS IAM credentials with AdministratorAccess privileges | critical | 10.0 | 1 | Cloud Credential Abuse |
| 718 | Unmonitored API Traffic | critical | 10.0 | 1 | Data Breach |
| 719 | Legitimate Administrative Tools (ScreenConnect, AnyDesk, RMM Platforms) | critical | 10.0 | 1 | Social Engineering |
| 720 | Inadequate cybersecurity training for non-IT staff | critical | 10.0 | 1 | Ransomware |
| 721 | insufficient physical security for network devices | critical | 10.0 | 1 | cyber-espionage |
| 722 | misconfigured AWS S3 bucket permissions | critical | 10.0 | 1 | ransomware |
| 723 | unencrypted storage of sensitive data in an internet-accessible environment | critical | 10.0 | 1 | ransomware |
| 724 | CVE-2026-41940 (cPanel Authentication Bypass) | critical | 10.0 | 1 | Data Breach |
| 725 | OpenClaw WebSocket-based AI agent framework vulnerability | critical | 10.0 | 1 | Zero-Click Exploit |
| 726 | CVE-2025-68947 (NsecSoft NSecKrnl driver) | critical | 10.0 | 1 | Ransomware |
| 727 | JIT compiler hijacking, .NET Reactor obfuscation, static constructor execution | critical | 10.0 | 1 | Supply Chain Attack |
| 728 | Code block display bug (hiding malicious instructions) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 729 | Weak default passwords, unpatched vulnerabilities | critical | 10.0 | 1 | Cyberattack |
| 730 | Endpoint Detection Gaps (EDR Limitations) | critical | 10.0 | 1 | Social Engineering |
| 731 | CVE-2024-40766 (SonicWall SSL VPN) | critical | 10.0 | 1 | Ransomware |
| 732 | Automated build execution in Rust (build.rs), Cargo’s safety features manipulation | critical | 10.0 | 1 | Supply Chain Attack |
| 733 | Potential CVE-2023-29357 (SharePoint RCE, linked to summer 2023 exploits) | critical | 10.0 | 1 | Data Breach |
| 734 | CVE-2026-32746 (Buffer Overflow in GNU InetUtils telnetd) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 735 | CVE-2026-50160 (GHSA-j542-4rch-8hwf) | critical | 10.0 | 1 | Mass Assignment Vulnerability |
| 736 | IT-OT convergence risks | critical | 10.0 | 1 | Ransomware |
| 737 | Encrypted master key printed in plain, unencrypted digital language | critical | 10.0 | 1 | Data Breach |
| 738 | CVE-2026-1492 | critical | 10.0 | 1 | Privilege Escalation |
| 739 | CVE-2025-10035 | critical | 10.0 | 1 | Ransomware Attack |
| 740 | unpatched VPN appliances | critical | 10.0 | 1 | ransomware |
| 741 | Insufficient anti-jam technology | critical | 10.0 | 1 | GPS spoofing |
| 742 | Deteriorating cyber defenses | critical | 10.0 | 1 | Cyberattack |
| 743 | Publicly exposed servers and computers | critical | 10.0 | 1 | Cyberattack |
| 744 | Unsecured IoT/Peripheral Devices | critical | 10.0 | 1 | Ransomware |
| 745 | usbliter8 (BootROM misconfiguration in Synopsys DesignWare USB2 controller) | critical | 10.0 | 1 | Hardware Vulnerability |
| 746 | Default or Weak ESXi Authentication Mechanisms | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 747 | Microsoft Word 2010 vulnerability | critical | 10.0 | 1 | Cyber Espionage |
| 748 | Mapped Network Drives | critical | 10.0 | 1 | Data Theft Extortion |
| 749 | Flaws in Access Controls | critical | 10.0 | 1 | Data Breach |
| 750 | CVE-2026-76461 (Insufficient input sanitization in Cisco AsyncOS Software leading to command injection) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 751 | over_permissive_cloud_settings | critical | 10.0 | 1 | ransomware |
| 752 | CVE-2025-3835 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 753 | React2Shell (CVE-2025-29927) | critical | 10.0 | 1 | Cloud Exploitation Campaign |
| 754 | CVE-2024-XXXX (CVSS 10.0), exposed Model Context Protocol (MCP) bridge | critical | 10.0 | 1 | Vulnerability Exploitation |
| 755 | CVE-2025-23334 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 756 | Notepad++ Zip Slip path traversal | critical | 10.0 | 1 | Zero-day exploit |
| 757 | CVE-2025-27507 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 758 | Lack of proper security policies post-migration due to human error (single employee responsible for manual compilation without second-layer checks) | critical | 10.0 | 1 | data breach |
| 759 | Lack of BCC usage in group emails | critical | 10.0 | 1 | Data Breach |
| 760 | Insecure helpdesk protocols | critical | 10.0 | 1 | AI-driven vulnerability exploitation |
| 761 | Human Trust Vulnerability | critical | 10.0 | 1 | Data Breach |
| 762 | Insufficient Asset Discovery (IIoT Device Proliferation) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 763 | GDPR compliance leverage (ransom coercion) | critical | 10.0 | 1 | ransomware |
| 764 | Excessive user permissions | critical | 10.0 | 1 | Ransomware |
| 765 | Over-Reliance on Reactive Detection (EDR/XDR) | critical | 10.0 | 1 | EDR/XDR Evasion |
| 766 | CVE-2025-70994 | critical | 10.0 | 1 | Firmware Vulnerability |
| 767 | OpenSSL memory allocation flaw (CVE not assigned, silently patched) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 768 | Use-After-Free (UAF) | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 769 | Vulnerabilities in aviation’s digital infrastructure | critical | 10.0 | 1 | Cyberattack |
| 770 | Shared-Service Model Vulnerabilities | critical | 10.0 | 1 | Cyberattack |
| 771 | Progress Software MOVEit Transfer SQL Injection Vulnerability (CVE-2023-34362) | critical | 10.0 | 1 | Data Breach |
| 772 | Data blind spots | critical | 10.0 | 1 | Ransomware Prediction |
| 773 | Salesforce Instance Misconfiguration | critical | 10.0 | 1 | Data Breach |
| 774 | Compromised APIs | critical | 10.0 | 1 | AI-driven cyber attack |
| 775 | CVE-2025-21042 (CVSS 8.8) - Out-of-Bounds Write in libimagecodec.quram.so | critical | 10.0 | 1 | Espionage |
| 776 | Zero-day vulnerability in enterprise software | critical | 10.0 | 1 | Data Breach, Ransomware |
| 777 | Use-after-free in SCTP Dynamic Address Reconfiguration (ASCONF chunks) | critical | 10.0 | 1 | Privilege Escalation, Container Escape |
| 778 | CVE-2026-17106 (CopyEscape) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 779 | limited financial resources for cybersecurity investments | critical | 10.0 | 1 | ransomware |
| 780 | User Data Misuse | critical | 10.0 | 1 | Data Breach |
| 781 | cross-border supplier networks | critical | 10.0 | 1 | ransomware |
| 782 | Exposed Secrets in GitHub Repository | critical | 10.0 | 1 | Data Breach |
| 783 | NDJSON injection in `inventory_sync` subsystem (CWE-74, CWE-93, CWE-863) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 784 | network vulnerabilities (unspecified) | critical | 10.0 | 1 | ransomware |
| 785 | Rewards system manipulation | critical | 10.0 | 1 | Cryptocurrency Heist |
| 786 | Adreno GPU Driver Vulnerabilities | critical | 10.0 | 1 | Vulnerability |
| 787 | Vulnerable software | critical | 10.0 | 1 | Cyber Intrusion |
| 788 | CVE-2026-84393 (FortiOS/FortiProxy Agentless ZTNA certificate validation flaw) | critical | 10.0 | 1 | Zero-day exploitation |
| 789 | Weak Caller Verification Processes | critical | 10.0 | 1 | Social Engineering |
| 790 | Classified information mishandling | critical | 10.0 | 1 | Cyber Attack, Data Leak |
| 791 | identity governance gaps | critical | 10.0 | 1 | ransomware |
| 792 | Inadequate security controls in femtocell management system, disabled end-to-end encryption | critical | 10.0 | 1 | Malware |
| 793 | Third-party applications (Salesforce and Snowflake instances) | critical | 10.0 | 1 | Data Breach |
| 794 | Coding error in liquidity pools | critical | 10.0 | 1 | Cryptocurrency Heist |
| 795 | AI's inability to recognize malicious intent in fragmented tasks | critical | 10.0 | 1 | cyberespionage |
| 796 | lack of network segmentation (allowed lateral movement) | critical | 10.0 | 1 | ransomware |
| 797 | poor staff training | critical | 10.0 | 1 | data breach |
| 798 | CVE-2025-5309 | critical | 10.0 | 1 | Remote Code Execution |
| 799 | Exposed long-term IAM user credentials, Lambda function code injection | critical | 10.0 | 1 | Cloud Breach |
| 800 | CVE-2023-50224 | critical | 10.0 | 1 | Credential Harvesting |
| 801 | Critical CVSS-rated vulnerabilities in legacy and new ICS devices | critical | 10.0 | 1 | Exposure of Critical Infrastructure |
| 802 | Misconfigured MongoDB instances lacking authentication, typically listening on port 27017 | critical | 10.0 | 1 | Ransomware |
| 803 | jailbreaking techniques | critical | 10.0 | 1 | ransomware |
| 804 | CVE-2026-62911 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 805 | Compromised private key controlling minting approvals | critical | 10.0 | 1 | Stablecoin Exploit |
| 806 | weak/default credentials | critical | 10.0 | 1 | cyberattack |
| 807 | Excessive Access Privileges | critical | 10.0 | 1 | Insider Threat |
| 808 | Endpoint Detection and Response (EDR) and antivirus process termination | critical | 10.0 | 1 | Malware, Ransomware |
| 809 | Excessive Browser Extension Permissions | critical | 10.0 | 1 | Espionage |
| 810 | CVE-2026-48172 (CWE-266: Improper Privilege Management) | critical | 10.0 | 1 | Privilege Escalation |
| 811 | Unsecured Public Wi-Fi | critical | 10.0 | 1 | Awareness Campaign |
| 812 | Unpatched Systems (Software/Hardware) | critical | 10.0 | 1 | Data Breach |
| 813 | CVE-2026-1490 (Authorization Bypass via Reverse DNS Spoofing) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 814 | CVE-2023-6895 (Hikvision - OS command injection) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 815 | Outdated Ethernet systems | critical | 10.0 | 1 | Ransomware |
| 816 | Unpatched ICS/OT Systems | critical | 10.0 | 1 | Ransomware |
| 817 | Prompt Injection (indirect) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 818 | CosmosEscape (improper .NET reflection restriction in Gremlin API) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 819 | CVE-2026-40369 | critical | 10.0 | 1 | Privilege Escalation |
| 820 | IIS vulnerabilities | critical | 10.0 | 1 | cyber espionage |
| 821 | Insufficient access controls, lack of root account protection | critical | 10.0 | 1 | Data Destruction |
| 822 | Stolen API keys | critical | 10.0 | 1 | AI Token Jacking |
| 823 | lack of package cooldown periods | critical | 10.0 | 1 | supply chain attack |
| 824 | No Backup Strategy | critical | 10.0 | 1 | Ransomware |
| 825 | OpenSSL flaws | critical | 10.0 | 1 | Ransomware |
| 826 | flat network architectures | critical | 10.0 | 1 | ransomware |
| 827 | CVE-2026-67401 | critical | 10.0 | 1 | SQL Injection |
| 828 | Design Flaw in 'SAVE' Feature | critical | 10.0 | 1 | Data Leak |
| 829 | CVE-2025-9491 (Windows Shortcut (LNK) file user interface misinterpretation) | critical | 10.0 | 1 | Remote Code Execution |
| 830 | CVE-2026-85706 | critical | 10.0 | 1 | Data Breach |
| 831 | NPM package integrity weakness | critical | 10.0 | 1 | supply chain attack |
| 832 | Abuse of legitimate browser permissions (File System Access API) | critical | 10.0 | 1 | Ransomware |
| 833 | Unpatched Software (50% of CVEs in last 5 years) | critical | 10.0 | 1 | Ransomware |
| 834 | Human vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 835 | Stolen Passwords | critical | 10.0 | 1 | Data Breach |
| 836 | Apache Log4j vulnerability | critical | 10.0 | 1 | Cyberattack (Reconnaissance Campaign) |
| 837 | Outdated RTU firmware | critical | 10.0 | 1 | Cyberattack (Wiper Malware, Firmware Tampering) |
| 838 | Hardcoded secrets in APKs | critical | 10.0 | 1 | AI-driven cyberattack |
| 839 | discrepancies in document classification | critical | 10.0 | 1 | spearphishing |
| 840 | human error (accidental download of malware-laced system administration tool) | critical | 10.0 | 1 | ransomware |
| 841 | CVE-2024-21410 | critical | 10.0 | 1 | Zero-Day Exploit |
| 842 | Lack of Cybersecurity Protocols | critical | 10.0 | 1 | Cybercrime |
| 843 | CVE-2026-6644 | critical | 10.0 | 1 | Zero-Day Exploit |
| 844 | Browser Sandbox Exploitation (Clipboard Access) | critical | 10.0 | 1 | Social Engineering |
| 845 | Router vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 846 | Critical jailbreak vulnerability in *Fable 5* and *Mythos 5* AI models | critical | 10.0 | 1 | AI Model Vulnerability / Regulatory Intervention |
| 847 | Insufficient Access Management | critical | 10.0 | 1 | Data Breach |
| 848 | Weak Password in Remote-Control System | critical | 10.0 | 1 | Cyberattack |
| 849 | CVE-2026-58240 (S4GET) | critical | 10.0 | 1 | Memory Corruption |
| 850 | lack of up-to-date incident response plans | critical | 10.0 | 1 | cyber attack |
| 851 | Unpatched flaw in Kaseya VSA | critical | 10.0 | 1 | Ransomware |
| 852 | Zero-Day in Oracle E-Business Suite | critical | 10.0 | 1 | Data Breach |
| 853 | Oracle E-Business Suite vulnerability | critical | 10.0 | 1 | Ransomware |
| 854 | Malicious form injection | critical | 10.0 | 1 | Data Breach |
| 855 | inadequate endpoint protection (Symantec Endpoint Protection failed to fully remediate backdoor) | critical | 10.0 | 1 | ransomware |
| 856 | Poor Access Controls (Lack of Tiered Admin Account Model) | critical | 10.0 | 1 | Data Breach |
| 857 | Spring4Shell | critical | 10.0 | 1 | Vulnerability Exploitation |
| 858 | CVE-2026-28289 (bypass of CVE-2026-27636) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 859 | CVE-2026-3502 (Download of Code Without Integrity Check - CWE-494) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 860 | Compromised Apple ID logins and LinkedIn data | critical | 10.0 | 1 | Data Breach |
| 861 | Lack of IT/OT Security Maturity (65% misalignment with NIST CSF 2.0) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 862 | Weak or Compromised RDP Credentials | critical | 10.0 | 1 | Malware |
| 863 | Publicly disclosed vulnerabilities | critical | 10.0 | 1 | Cyberattack |
| 864 | Alteration of system IP address | critical | 10.0 | 1 | Cyberattack |
| 865 | Potential zero-day in F5 products | critical | 10.0 | 1 | Data Breach |
| 866 | CVE-2024-12345 | critical | 10.0 | 1 | Cyber Espionage |
| 867 | Weak DNS Security Extensions (DNSSEC) Implementation | critical | 10.0 | 1 | Domain Hijacking |
| 868 | CVE-2026-55116 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 869 | aging infrastructure | critical | 10.0 | 1 | ransomware |
| 870 | Lack of MFA Enforcement | critical | 10.0 | 1 | Social Engineering |
| 871 | Plaintext Credential Storage | critical | 10.0 | 1 | Vulnerability Exploitation |
| 872 | Design Flaws | critical | 10.0 | 1 | Data Breach |
| 873 | CVE-2026-33017 | critical | 10.0 | 1 | Code Injection |
| 874 | Microsoft Exchange Server flaw | critical | 10.0 | 1 | Zero-day Exploit |
| 875 | zero-day vulnerabilities in PDF readers | critical | 10.0 | 1 | ransomware |
| 876 | Delayed Breach Detection (avg. 276 days per IBM 2025 report) | critical | 10.0 | 1 | Supply Chain Attack |
| 877 | Microsoft Outlook vulnerability | critical | 10.0 | 1 | Data Breach |
| 878 | CVE-2025-32711 (EchoLeak) | critical | 10.0 | 1 | Data Exposure |
| 879 | Undisclosed (stolen vulnerability data) | critical | 10.0 | 1 | Data Breach |
| 880 | Citrix NetScaler Gateway Appliance (unspecified CVE) | critical | 10.0 | 1 | Cyber Espionage |
| 881 | Backup compromise | critical | 10.0 | 1 | Ransomware |
| 882 | CVE-2025-14894 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 883 | CVE-2024-4885 | critical | 10.0 | 1 | Ransomware |
| 884 | Insecure webcam | critical | 10.0 | 1 | Ransomware |
| 885 | CVE-2023-28252 (Cisco) | critical | 10.0 | 1 | ransomware |
| 886 | Poorly configured firewalls | critical | 10.0 | 1 | Ransomware |
| 887 | Inadequate access controls for sensitive spreadsheets | critical | 10.0 | 1 | Data Breach |
| 888 | SharePoint server vulnerabilities | critical | 10.0 | 1 | ransomware |
| 889 | Exposed credentials, trust relationships, transitive authority, branch protection bypass attempts | critical | 10.0 | 1 | Ransomware |
| 890 | Poor Credential Hygiene (GitHub Repository) | critical | 10.0 | 1 | Data Breach |
| 891 | lack of managed GenAI tools | critical | 10.0 | 1 | ransomware |
| 892 | Exploitation of Android’s Accessibility Service, Google Play Protect bypass techniques | critical | 10.0 | 1 | Malware (Remote Access Trojan - RAT) |
| 893 | Microsoft Defender Race Condition | critical | 10.0 | 1 | AI Cybersecurity Risk |
| 894 | Cross-Site Scripting (XSS) in Free-for-Teacher environment | critical | 10.0 | 1 | Data Breach, Extortion |
| 895 | FTP Misconfiguration | critical | 10.0 | 1 | Data Breach |
| 896 | Over-Permissive API/OAuth Token Access | critical | 10.0 | 1 | Data Breach |
| 897 | Lack of HIPAA-compliant risk analysis | critical | 10.0 | 1 | Ransomware |
| 898 | CVE-2026-42210 / CVE-2026-56022 | critical | 10.0 | 1 | XSS |
| 899 | CVE-2026-42934 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 900 | Employee Theft | critical | 10.0 | 1 | Data Breach |
| 901 | vulnerable computer systems | critical | 10.0 | 1 | data breach |
| 902 | Lateral Movement from Contractor to MoD Systems | critical | 10.0 | 1 | Data Breach |
| 903 | CVE-2026-55200 (Integer overflow leading to buffer overflow in libssh2) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 904 | AI Model Vulnerabilities | critical | 10.0 | 1 | State-Backed Surveillance & Hacking |
| 905 | unchanged default passwords in VSAT terminals | critical | 10.0 | 1 | cyberattack |
| 906 | CVE-2024-42057 | critical | 10.0 | 1 | Ransomware Attack |
| 907 | Unsecured MSSQL Database | critical | 10.0 | 1 | Data Breach |
| 908 | unsecured programmable logic controllers (PLCs), weak passwords, lack of firewalls | critical | 10.0 | 1 | cyberattack |
| 909 | Predictable bucket naming in Google Cloud Vertex AI, lack of bucket ownership verification, unsafe Python pickle deserialization | critical | 10.0 | 1 | Vulnerability Exploitation |
| 910 | Caching Error | critical | 10.0 | 1 | Data Breach |
| 911 | Infected Barcode Scanners | critical | 10.0 | 1 | Data Breach |
| 912 | CVE-2025-25249 (FortiOS/FortiSwitchManager CAPWAP heap overflow) | critical | 10.0 | 1 | Zero-day exploitation |
| 913 | Unsecured Infrastructure Controls | critical | 10.0 | 1 | Cyber Attack |
| 914 | inadequate third-party access controls | critical | 10.0 | 1 | data breach |
| 915 | CVE-2025-47950 | critical | 10.0 | 1 | Vulnerability |
| 916 | CVE-2025-64111 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 917 | CNVD-2020-26585 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 918 | CVE-2025-52562 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 919 | Insufficient permission checks | critical | 10.0 | 1 | DeFi Exploit |
| 920 | third-party cybersecurity dependencies | critical | 10.0 | 1 | cyberattack |
| 921 | Security Oversight | critical | 10.0 | 1 | Data Breach |
| 922 | CVE-2026-60137 (SQL injection) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 923 | 17-year-old undisclosed vulnerability | critical | 10.0 | 1 | AI-enabled cyberattack |
| 924 | Inadequate Data Redaction Procedures | critical | 10.0 | 1 | Data Breach |
| 925 | Insecure Internet-facing operational technology (OT), weak passwords, lack of multifactor authentication | critical | 10.0 | 1 | Cyberattack |
| 926 | exposed SaaS endpoints | critical | 10.0 | 1 | AI-driven cyberattack |
| 927 | flat networks | critical | 10.0 | 1 | Ransomware |
| 928 | Potential Weak Authentication (if credentials were shared) | critical | 10.0 | 1 | Insider Threat |
| 929 | Mobile Device Management (MDM) system | critical | 10.0 | 1 | Espionage, Data Breach |
| 930 | CVE-2026-66066 (Rails Active Storage) | critical | 10.0 | 1 | Zero-day Exploit |
| 931 | CVE-2026-22719 (CWE-77 - Command Injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 932 | Lack of adequate detection and response capabilities for drone threats | critical | 10.0 | 1 | Physical Security Threat |
| 933 | Abuse of trusted domain (bubble.io) to bypass email security filters | critical | 10.0 | 1 | Phishing |
| 934 | Lack of authentication/logging in OT systems | critical | 10.0 | 1 | Ransomware, Cyber Espionage, Industrial Sabotage |
| 935 | Weak governance mechanisms | critical | 10.0 | 1 | DeFi Exploit |
| 936 | CVE-2018-5999 | critical | 10.0 | 1 | Botnet Exploitation |
| 937 | Disabled HMAC Authentication | critical | 10.0 | 1 | Vulnerability Disclosure |
| 938 | CVE-2024-51324 (Baidu Antivirus driver) | critical | 10.0 | 1 | Ransomware |
| 939 | Trojanized update | critical | 10.0 | 1 | Supply Chain Attack |
| 940 | Delegated Administrative Privileges (DAP) in Microsoft cloud solutions | critical | 10.0 | 1 | cyberespionage |
| 941 | Optional MFA (to be phased out) | critical | 10.0 | 1 | Predictive Analysis |
| 942 | Cloud storage platform | critical | 10.0 | 1 | Data Breach |
| 943 | Unsecured GitHub Personal Access Tokens (PATs) | critical | 10.0 | 1 | Supply-Chain Attack |
| 944 | CVE-2025-55182 (CVSS 9.8) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 945 | CVE-2026-25049 (insufficient input sanitization in expression evaluation mechanism) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 946 | hijacked_maintainer_account | critical | 10.0 | 1 | ransomware |
| 947 | Lack of MFA on FortiGate VPN devices | critical | 10.0 | 1 | Destructive Cyberattack |
| 948 | Fortinet VPN vulnerabilities | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 949 | Weak authentication, default credentials, lack of network segmentation | critical | 10.0 | 1 | Exposure of Critical Infrastructure |
| 950 | CVE-2025-53690 (ViewState Deserialization in Sitecore XM/XP/XC/Managed Cloud) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 951 | 181 Firefox exploits | critical | 10.0 | 1 | AI-driven cyber attack |
| 952 | User Registration & Membership WordPress plugin vulnerability | critical | 10.0 | 1 | Authentication Bypass |
| 953 | CVE-2026-73570 (OS command injection in SNMP monitoring functionality) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 954 | Accidental transmission of private key information | critical | 10.0 | 1 | Data Breach |
| 955 | Exposed VPN concentrators | critical | 10.0 | 1 | Destructive Cyberattack |
| 956 | Critical vulnerability in SAP NetWeaver Visual Composer development server | critical | 10.0 | 1 | Zero-day attack |
| 957 | Outdated software in critical sectors (hospitals, governments) | critical | 10.0 | 1 | Extortion |
| 958 | tasks.json file execution | critical | 10.0 | 1 | Financial Theft |
| 959 | Misconfigured replication rights (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All) | critical | 10.0 | 1 | Credential Theft |
| 960 | Command execution flaws | critical | 10.0 | 1 | Cyber Attack |
| 961 | Untrusted App Sources | critical | 10.0 | 1 | Awareness Campaign |
| 962 | CitrixBleed (CVE-2023-4966) - CVSS 9.3 in Netscaler ADC and Gateway (Session Token Theft, MFA Bypass) | critical | 10.0 | 1 | Data Breach |
| 963 | Oracle’s E-Business Suite flaw | critical | 10.0 | 1 | Ransomware Attack |
| 964 | PhantomRPC (CVE not specified) | critical | 10.0 | 1 | Privilege Escalation |
| 965 | No rate-limiting or access restrictions on user data | critical | 10.0 | 1 | Data Breach |
| 966 | Data Sharing with Third-Party | critical | 10.0 | 1 | Data Breach |
| 967 | CVE-2025-53771 (Path Traversal) | critical | 10.0 | 1 | Cyber Espionage |
| 968 | CVE-2025-25012 | critical | 10.0 | 1 | Vulnerability Exploit |
| 969 | Inadequate Redaction | critical | 10.0 | 1 | Data Breach |
| 970 | SAP software vulnerability | critical | 10.0 | 1 | Cyberattack |
| 971 | third-party ecosystem dependencies | critical | 10.0 | 1 | ransomware |
| 972 | Over-permissioning | critical | 10.0 | 1 | AI-driven breach |
| 973 | Lack of encryption or authentication in GPS signals | critical | 10.0 | 1 | GPS spoofing |
| 974 | Outdated Cryptographic Protocols | critical | 10.0 | 1 | Data Breach |
| 975 | CVE-2021-36260 (Hikvision - command injection) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 976 | Exposed SMB ports with weak or compromised credentials | critical | 10.0 | 1 | Ransomware |
| 977 | CVE-2026-62832 (Windows User Profile Service - LegacyHive) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 978 | urgency/authority manipulation | critical | 10.0 | 1 | social engineering |
| 979 | CVE-2026-46242 (Use-after-free and race condition in epoll subsystem) | critical | 10.0 | 1 | Privilege Escalation |
| 980 | Heap Metadata Corruption | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 981 | Secure Boot Bypass via vulnerable UEFI shim bootloaders (versions 0.9 and older) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 982 | Exposed AI and automation services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) | critical | 10.0 | 1 | Botnet |
| 983 | Salesloft’s Drift AI Chat Integration (OAuth Token Theft) | critical | 10.0 | 1 | Data Breach |
| 984 | Lack of browser-layer visibility | critical | 10.0 | 1 | Session Hijacking |
| 985 | Zero-day flaw in MOVEit Transfer (Progress Software) | critical | 10.0 | 1 | Ransomware |
| 986 | Single-point-of-failure in 1/1 validation setup, lack of redundant verifiers | critical | 10.0 | 1 | Exploit |
| 987 | SVG animate elements in HTML sanitizer | critical | 10.0 | 1 | SQL Injection |
| 988 | CVE-2025-55125 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 989 | embedded secrets in Android APKs | critical | 10.0 | 1 | AI-driven cyberattack |
| 990 | Data susceptible to interception or misuse during cloud processing | critical | 10.0 | 1 | Privacy Breach |
| 991 | Remote Work Vulnerabilities | critical | 10.0 | 1 | Insider Threat |
| 992 | unique implementation flaws | critical | 10.0 | 1 | supply chain attack |
| 993 | CVE-2026-1354 | critical | 10.0 | 1 | Firmware Vulnerability |
| 994 | Satellite Communication Systems | critical | 10.0 | 1 | Cyber Attack |
| 995 | CVE-2017-9805 (Apache Struts) | critical | 10.0 | 1 | cyberespionage |
| 996 | Vulnerability in Cleo's file transfer products | critical | 10.0 | 1 | Ransomware |
| 997 | CVE-2026-9256 (nginx-poolslip) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 998 | Notepad++ PowerShell command injection | critical | 10.0 | 1 | Zero-day exploit |
| 999 | Unauthorized access to video lessons | critical | 10.0 | 1 | Data Breach |
| 1000 | IoT Device Vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 1001 | Publicly Indexed 'Recent Links' Pages | critical | 10.0 | 1 | Data Leak |
| 1002 | NPM package dependency trust model | critical | 10.0 | 1 | supply chain attack |
| 1003 | Known vulnerabilities in backbone routers | critical | 10.0 | 1 | Cyber Espionage |
| 1004 | CVE-2026-33112 (SharePoint XmlValidator bypass via external XSD schemas) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1005 | File System Access API in Chrome/Chromium-based browsers | critical | 10.0 | 1 | Ransomware |
| 1006 | Known vulnerability in Unitronics programmable logic controllers (PLCs) | critical | 10.0 | 1 | Cyberattack |
| 1007 | Firewall rule exposing RDP on a management server | critical | 10.0 | 1 | Ransomware |
| 1008 | Lack of MFA on Personal/Social Media Accounts | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1009 | CVE-2025-8088 (WinRAR vulnerability) | critical | 10.0 | 1 | Cyber Espionage, Data Theft |
| 1010 | Trusted partner relationships, fake Okta login pages, clipboard data theft | critical | 10.0 | 1 | Data Theft Extortion |
| 1011 | Insufficient client-side runtime monitoring | critical | 10.0 | 1 | Data Breach |
| 1012 | Insufficient Privileged Access Controls (e.g., standing admin roles) | critical | 10.0 | 1 | Social Engineering |
| 1013 | DLL sideloading | critical | 10.0 | 1 | Supply Chain Attack |
| 1014 | CVE-2025-14733 (Out-of-bounds write in iked process) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1015 | Over-the-Air Broadcast Without Protection | critical | 10.0 | 1 | Data Interception |
| 1016 | Kernel-level hooks in EDR products (28+ vendors targeted) | critical | 10.0 | 1 | Ransomware |
| 1017 | Log4Shell vulnerability | critical | 10.0 | 1 | Cyber Attack |
| 1018 | Legitimate account compromise | critical | 10.0 | 1 | Ransomware |
| 1019 | LLM Susceptibility to Prompt Injection | critical | 10.0 | 1 | Prompt Injection |
| 1020 | SimpleHelp | critical | 10.0 | 1 | Ransomware |
| 1021 | lack_of_verified_security_controls | critical | 10.0 | 1 | data_at_risk |
| 1022 | CVE-2026-5194 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1023 | Manual SOC inefficiencies | critical | 10.0 | 1 | Data Breach |
| 1024 | Critical API security vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 1025 | Lack of Secure Boot/Trust Anchor in ASA 5500-X Series | critical | 10.0 | 1 | Zero-day exploitation |
| 1026 | Lack of Compliance Oversight | critical | 10.0 | 1 | Data Breach |
| 1027 | Lax network security | critical | 10.0 | 1 | Data Breach |
| 1028 | Windows IKE VPN vulnerabilities | critical | 10.0 | 1 | AI-driven cyberattack |
| 1029 | shared webmail platform misconfiguration | critical | 10.0 | 1 | cyber espionage |
| 1030 | Cisco Smart Install feature vulnerabilities | critical | 10.0 | 1 | Cyber Espionage, Critical Infrastructure Attack |
| 1031 | CVE-2026-1207 | critical | 10.0 | 1 | SQL Injection |
| 1032 | CVE-2025-30401 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1033 | CVE-2026-49102 | critical | 10.0 | 1 | XSS |
| 1034 | Diversité des systèmes OT rendant difficile une protection standardisée | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1035 | poor segmentation of payment systems | critical | 10.0 | 1 | ransomware |
| 1036 | OS auto-enumeration of mice on Windows 11 and macOS Sonoma, lack of HID trust models | critical | 10.0 | 1 | Hardware-based Attack |
| 1037 | AI supply chain threats (e.g., LangFlow RCE) | critical | 10.0 | 1 | Malware Framework |
| 1038 | Authentication Bypass in Python.org’s release management API | critical | 10.0 | 1 | Authentication Bypass |
| 1039 | Trust in .gov/.police Domain Emails (Bypassing Technical Filters) | critical | 10.0 | 1 | Account Compromise |
| 1040 | Ineffective DMARC Protection | critical | 10.0 | 1 | Data Breach |
| 1041 | outdated cybersecurity protocols | critical | 10.0 | 1 | cyber attack |
| 1042 | Plaintext access to JSON payloads in AI agent tool calls, lack of cryptographic verification for tool-call integrity | critical | 10.0 | 1 | Supply Chain Attack |
| 1043 | Insufficient Anomaly Detection | critical | 10.0 | 1 | Data Breach |
| 1044 | Orion Software Vulnerability | critical | 10.0 | 1 | Software Exploitation |
| 1045 | unrestricted PowerShell usage | critical | 10.0 | 1 | ransomware |
| 1046 | Compromised Microsoft Entra account | critical | 10.0 | 1 | Data Breach |
| 1047 | remote-code execution in dataset processing | critical | 10.0 | 1 | AI-driven cyber attack |
| 1048 | CVE-2025-5777 (Citrix NetScaler ADC/Gateway) | critical | 10.0 | 1 | Ransomware |
| 1049 | WordPress race condition | critical | 10.0 | 1 | AI-driven cyberattack |
| 1050 | BeyondTrust | critical | 10.0 | 1 | Ransomware |
| 1051 | Lack of Standardized Controls | critical | 10.0 | 1 | Collaborative Initiative |
| 1052 | Improper Pointer Nullification | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 1053 | GraphQL interfaces | critical | 10.0 | 1 | Data Breach |
| 1054 | Insufficient Network Segmentation (implied) | critical | 10.0 | 1 | Ransomware Attack |
| 1055 | SonicWall VPN RCE | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 1056 | CVE-2026-34908 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1057 | Legacy systems, architectural weaknesses in industrial security, IT-OT convergence | critical | 10.0 | 1 | Cyberattack on Operational Technology (OT) |
| 1058 | Overprivileged service accounts | critical | 10.0 | 1 | Ransomware |
| 1059 | Weak Cybersecurity Safeguards in Government Systems | critical | 10.0 | 1 | Data Privacy Violation |
| 1060 | Unsecured Elasticsearch Server | critical | 10.0 | 1 | Data Breach |
| 1061 | CVE-2025-3935 | critical | 10.0 | 1 | Cyberattack |
| 1062 | CVE-2026-42945 (Heap Buffer Overflow in ngx_http_rewrite_module) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1063 | Weak Authentication (e.g., VPN Passwords) | critical | 10.0 | 1 | Cyber Espionage |
| 1064 | package registries | critical | 10.0 | 1 | ransomware |
| 1065 | overlooked software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1066 | Vulnerabilities in AI development platforms | critical | 10.0 | 1 | AI-driven cyber threats |
| 1067 | Over-Permissive Tool Access (e.g., Password Crackers, Network Scanners) | critical | 10.0 | 1 | Espionage |
| 1068 | Authenticated Local File Inclusion | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1069 | Legacy System Exploits | critical | 10.0 | 1 | Ransomware |
| 1070 | CVE-2025-21042 (Samsung Android image processing library) | critical | 10.0 | 1 | spyware |
| 1071 | Log4Shell (CVE-2021-44228) | critical | 10.0 | 1 | Ransomware Attack |
| 1072 | Limited Budget/Resources | critical | 10.0 | 1 | Collaborative Initiative |
| 1073 | CVE-2021-36942 (PetitPotam - Windows LSA Spoofing) | critical | 10.0 | 1 | Cyber Espionage |
| 1074 | CVE-2025-69258 (LoadLibraryEX vulnerability in MsgReceiver.exe) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1075 | Social engineering, ClickFix-style prompts, PowerShell exploitation, Windows Defender exclusion manipulation | critical | 10.0 | 1 | Malware Deployment, Social Engineering, Data Exfiltration |
| 1076 | Funnel Builder vulnerability | critical | 10.0 | 1 | Zero-day Exploit |
| 1077 | Poor Vendor/Third-Party Risk Management | critical | 10.0 | 1 | Ransomware |
| 1078 | Unpinned GitHub Actions dependencies | critical | 10.0 | 1 | Supply Chain Attack |
| 1079 | CVE-2026-68820 (Windows Ancillary Function Driver for WinSock) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1080 | unsecured GenAI prompts | critical | 10.0 | 1 | ransomware |
| 1081 | CVE-2026-20127 (CVSS 10.0) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1082 | Exposed API endpoints returning call metadata/recordings without authentication | critical | 10.0 | 1 | Data Breach |
| 1083 | CVE-2025-53521 (F5 BIG-IP APM) | critical | 10.0 | 1 | ransomware |
| 1084 | CVE-2026-20965 | critical | 10.0 | 1 | Unauthorized Access |
| 1085 | AI Chatbot Feature | critical | 10.0 | 1 | Copyright Infringement |
| 1086 | WeWorm (WeChat VoIP zero-click exploit) | critical | 10.0 | 1 | Zero-day exploitation |
| 1087 | Failure to revoke former employee access, Lack of blind signing protection, Inadequate monitoring of software updates | critical | 10.0 | 1 | Data Breach, Phishing, Supply Chain Attack, Fraud |
| 1088 | Potential vulnerability in Citrix NetScaler | critical | 10.0 | 1 | Cyberattack |
| 1089 | Compromised open-source development tools | critical | 10.0 | 1 | Ransomware |
| 1090 | Progress Software's MOVEit Transfer vulnerability | critical | 10.0 | 1 | ransomware |
| 1091 | Legacy Authentication Protocols | critical | 10.0 | 1 | Social Engineering |
| 1092 | Lack of Vendor Oversight | critical | 10.0 | 1 | Data Breach |
| 1093 | Legacy System Risks | critical | 10.0 | 1 | Data Breach |
| 1094 | Undocumented WordPress Installation | critical | 10.0 | 1 | Data Breach |
| 1095 | CVE-2023-41347 | critical | 10.0 | 1 | botnet |
| 1096 | CVE-2025-59468 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1097 | Windchill login servlet weakness enabling RCE | critical | 10.0 | 1 | Ransomware, Data Theft |
| 1098 | myCare Integrity EMR system | critical | 10.0 | 1 | Data Breach |
| 1099 | Human Error (lack of skepticism toward unsolicited interactions) | critical | 10.0 | 1 | Cyber Theft |
| 1100 | Insufficient Vetting of Remote IT Workers | critical | 10.0 | 1 | Cyber Theft |
| 1101 | CVE-2026-33634 (CWE-506) | critical | 10.0 | 1 | Supply Chain Attack |
| 1102 | CVE-2026-0229 | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 1103 | Unsecured Database Accessible Without Authentication | critical | 10.0 | 1 | Data Breach |
| 1104 | Outdated legacy systems | critical | 10.0 | 1 | Cyberattack |
| 1105 | Fortinet systems | critical | 10.0 | 1 | Ransomware |
| 1106 | Disguised Malicious Commands as Benign Requests | critical | 10.0 | 1 | Espionage |
| 1107 | Known exploited vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1108 | Exploit Kit | critical | 10.0 | 1 | Malvertising |
| 1109 | excessive email/mailbox permissions (shared read access) | critical | 10.0 | 1 | cyberespionage |
| 1110 | Vulnerability in Canvas’s 'Free for Teacher' accounts | critical | 10.0 | 1 | Data Breach, Ransomware |
| 1111 | Four-Faith industrial routers | critical | 10.0 | 1 | DDoS Attack |
| 1112 | Potential Salesforce Misconfigurations | critical | 10.0 | 1 | Data Breach |
| 1113 | Stolen credentials from vendor’s environment | critical | 10.0 | 1 | Data Breach |
| 1114 | Exposed Credentials in Repositories | critical | 10.0 | 1 | Data Breach |
| 1115 | CVE-2025-48595 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1116 | Vehicle Tracking Systems (VTS), Immobilizer systems, Security systems | critical | 10.0 | 1 | Cyber Attack, Satellite Interference, Vehicle Immobilization |
| 1117 | Lack of multi-factor authentication (MFA) on a critical server | critical | 10.0 | 1 | ransomware |
| 1118 | Internal mechanism for helping password-forgetting users reclaim their accounts | critical | 10.0 | 1 | Data Privacy Breach |
| 1119 | Overwhelming a server or website with excessive fake traffic | critical | 10.0 | 1 | DDoS Attack |
| 1120 | Memory Leak | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1121 | Human error (opening infected email attachment) | critical | 10.0 | 1 | cyber espionage |
| 1122 | User Trust in App Store and Social Media Ads | critical | 10.0 | 1 | Data Breach |
| 1123 | weak/recycled passwords | critical | 10.0 | 1 | general cybersecurity awareness |
| 1124 | Inadequate Training | critical | 10.0 | 1 | Data Breach |
| 1125 | Inadequate Incident Response Plans | critical | 10.0 | 1 | Ransomware |
| 1126 | Disconnected IAM Systems | critical | 10.0 | 1 | Predictive Analysis |
| 1127 | insufficient incident response plans | critical | 10.0 | 1 | phishing |
| 1128 | CVE-2026-22844 (Command Injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1129 | Inadequate Sandboxing for AI/ML Environments | critical | 10.0 | 1 | Supply Chain Attack |
| 1130 | Unpatched Microsoft SharePoint Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1131 | Software Development and Distribution Processes | critical | 10.0 | 1 | Supply Chain Attack |
| 1132 | Improper access control in WDS (CVE-2026-0386) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1133 | CVE-2026-42946 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1134 | CVE-2026-54420 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1135 | Redis/Memcache session poisoning for arbitrary file deletion | critical | 10.0 | 1 | SQL Injection |
| 1136 | Systemic design weaknesses in agentic red-team tools, including weak isolation, shared volumes, unauthenticated APIs, and excessive container privileges | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1137 | Poor Endpoint Security | critical | 10.0 | 1 | Data Breach (General Discussion) |
| 1138 | Full Disk Access Exploitation | critical | 10.0 | 1 | AI Cybersecurity Risk |
| 1139 | CVE-2026-24747 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1140 | Credential Stuffing / Account Takeover | critical | 10.0 | 1 | Data Breach |
| 1141 | trusted communications impersonation | critical | 10.0 | 1 | phishing |
| 1142 | End-of-support (EoS) devices (ASA 5500-X Series) | critical | 10.0 | 1 | Zero-day exploitation |
| 1143 | PCI DSS 4.0.1 compliance gaps in client-side data protection | critical | 10.0 | 1 | Data Breach |
| 1144 | insecure use of pull_request_target in GitHub Actions | critical | 10.0 | 1 | supply chain attack |
| 1145 | Static Zero Trust Policies (Lack of Dynamic Guardrails) | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 1146 | CVE-2025-8110 (Path traversal in PutContents API via symbolic links) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1147 | CVE-2024-21182 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1148 | CVE-2025-1055 | critical | 10.0 | 1 | Ransomware |
| 1149 | compromised backup configurations (SonicWall cloud breach) | critical | 10.0 | 1 | ransomware |
| 1150 | CVE-2026-27689 (DoS in SAP Supply Chain Management) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1151 | Lack of backup systems | critical | 10.0 | 1 | Ransomware |
| 1152 | Windows OS vulnerability (unspecified programming bug) | critical | 10.0 | 1 | malware |
| 1153 | Check Point Vulnerabilities | critical | 10.0 | 1 | Ransomware Attack |
| 1154 | Unsafe library loading | critical | 10.0 | 1 | Data Breach |
| 1155 | CVE-2026-61511 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1156 | Stolen credentials, lateral movement | critical | 10.0 | 1 | Data Breach |
| 1157 | lack_of_immutable_backups | critical | 10.0 | 1 | data_breach |
| 1158 | CVE-2025-7027 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1159 | Improper Whitelisting of Microsoft CDB | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 1160 | CVE-2026-1731 (OS command injection, CWE-78) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1161 | Improper access controls in Capital One's cloud-based firewall (AWS S3 bucket misconfiguration) | critical | 10.0 | 1 | Data Breach |
| 1162 | Windows minifilter drivers | critical | 10.0 | 1 | Ransomware |
| 1163 | AppArmor vulnerabilities (no CVE assigned yet) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1164 | Outdated or unpatched consumer and small office devices | critical | 10.0 | 1 | Cyber Espionage |
| 1165 | static credential storage | critical | 10.0 | 1 | fraud |
| 1166 | Improper input sanitization in virtuser_query plugin (preg_replace backslash escape bypass) | critical | 10.0 | 1 | SQL Injection |
| 1167 | Crafted local address URLs for SSRF bypass | critical | 10.0 | 1 | SQL Injection |
| 1168 | SimpleHelp RMM flaws | critical | 10.0 | 1 | Ransomware |
| 1169 | Database Injection | critical | 10.0 | 1 | Website Defacement |
| 1170 | CVE-2023-35082 | critical | 10.0 | 1 | Ransomware |
| 1171 | Accessibility Services abuse | critical | 10.0 | 1 | ransomware |
| 1172 | Unvetted Browser Extensions (Cyberhaven Hack, 35+ Extensions in 2024) | critical | 10.0 | 1 | Browser-Based Attack |
| 1173 | Unknown vulnerability in Microsoft SharePoint servers | critical | 10.0 | 1 | Cyber Espionage |
| 1174 | Weak credentials (e.g., built-in *sa* account) | critical | 10.0 | 1 | Ransomware |
| 1175 | CVE-2026-48558 | critical | 10.0 | 1 | Authentication Bypass |
| 1176 | Microsoft Office Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1177 | Unpatched Web Browser/Plugin Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1178 | Poor detection of abnormal system activity | critical | 10.0 | 1 | Data Breach |
| 1179 | Known Exploited Vulnerabilities (KEV) | critical | 10.0 | 1 | Ransomware |
| 1180 | SAP vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 1181 | Valid Login Information | critical | 10.0 | 1 | Data Breach |
| 1182 | Weak Endpoint Detection | critical | 10.0 | 1 | Targeted Cyberattack |
| 1183 | Security gap in MOVEit Transfer | critical | 10.0 | 1 | Data Breach |
| 1184 | outdated web forms | critical | 10.0 | 1 | ransomware |
| 1185 | Package Impersonation | critical | 10.0 | 1 | Supply Chain Attack |
| 1186 | Overcollection of Personal Data | critical | 10.0 | 1 | Data Privacy Violation |
| 1187 | Outsourced Business Process Provider Vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 1188 | CVE-2023-22515 (Atlassian Confluence) | critical | 10.0 | 1 | Ransomware |
| 1189 | Lack of Multi-Factor Authentication (2FA) Enforcement | critical | 10.0 | 1 | Data Breach |
| 1190 | Insecure ICS Protocols (Plaintext Traffic) | critical | 10.0 | 1 | Exposure of Vulnerable Systems |
| 1191 | CVE-2026-25611 | critical | 10.0 | 1 | Denial of Service (DoS) |
| 1192 | BlueKeep | critical | 10.0 | 1 | Ransomware |
| 1193 | Insecure Data Storage Practices | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1194 | Single Point of Failure in Critical Workflows | critical | 10.0 | 1 | Supply Chain Attack |
| 1195 | Inadequate Data Encryption | critical | 10.0 | 1 | Ransomware |
| 1196 | Weak Token Management in Drift Integration | critical | 10.0 | 1 | Supply Chain Attack |
| 1197 | CVE-2026-9862 (OS Command Injection - CWE-78) | critical | 10.0 | 1 | Command Injection |
| 1198 | Citrix NetScaler Vulnerabilities | critical | 10.0 | 1 | Ransomware Attack |
| 1199 | Unpatched Firmware/Software in Network Perimeter Devices | critical | 10.0 | 1 | Cyber Espionage |
| 1200 | Embedded Credentials in BIG-IP | critical | 10.0 | 1 | Supply Chain Attack |
| 1201 | Vect Ransomware Bug | critical | 10.0 | 1 | Data Breach |
| 1202 | CVE-2026-46316 (ITScape) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1203 | Supply chain compromise | critical | 10.0 | 1 | Supply Chain Attack |
| 1204 | insufficient AI governance | critical | 10.0 | 1 | ransomware |
| 1205 | CVE-2025-2502 | critical | 10.0 | 1 | Outage and Vulnerability |
| 1206 | Insufficient sanitization in serialize and compileMDX functions (CVE-2026-0969) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1207 | Student cybersecurity illiteracy | critical | 10.0 | 1 | Data Breach |
| 1208 | Authentication Mechanisms | critical | 10.0 | 1 | Data Breach |
| 1209 | VIB Acceptance Level Tampering | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 1210 | Veeam Backup & Replication (VBR) servers | critical | 10.0 | 1 | Ransomware |
| 1211 | CAN bus vulnerabilities in Tesla Model S | critical | 10.0 | 1 | Remote Code Execution |
| 1212 | Insecure systems | critical | 10.0 | 1 | Ransomware Attack |
| 1213 | Government mismanagement, lack of security protocols | critical | 10.0 | 1 | Data Breach |
| 1214 | lack of backups | critical | 10.0 | 1 | data breach |
| 1215 | Shadow AI, IdentityMesh, Infostealers | critical | 10.0 | 1 | Data Breach |
| 1216 | Publicly Exposed MCP Servers | critical | 10.0 | 1 | Data Exposure |
| 1217 | Insufficient security controls, governance gaps, vendor-related risks | critical | 10.0 | 1 | Ransomware Attack |
| 1218 | Unsegmented Networks | critical | 10.0 | 1 | Data Breach |
| 1219 | Flawed ChaCha20-IETF encryption routine (discarding nonces) | critical | 10.0 | 1 | Ransomware (Data Wiper) |
| 1220 | Sophos vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 1221 | CVE-2025-47962 (Windows SDK EoP) | critical | 10.0 | 1 | Patch Release |
| 1222 | Oracle software vulnerability (identified in September 2023 by NCSC) | critical | 10.0 | 1 | Data Breach, Ransomware |
| 1223 | CVE-2024-45347 | critical | 10.0 | 1 | Authentication Bypass Vulnerability |
| 1224 | Lack of Access Controls During Layoffs | critical | 10.0 | 1 | Data Breach |
| 1225 | CVE-2024-12297 (Frontend Authorization Logic Disclosure) | critical | 10.0 | 1 | Authentication Bypass |
| 1226 | File transfer tool vulnerability | critical | 10.0 | 1 | Ransomware |
| 1227 | Unsafe `pull_request_target` trigger | critical | 10.0 | 1 | Supply Chain Attack |
| 1228 | Unprotected Fax Server | critical | 10.0 | 1 | Data Breach |
| 1229 | CVE-2023-41346 | critical | 10.0 | 1 | botnet |
| 1230 | lack of unified secure document collaboration platform | critical | 10.0 | 1 | spearphishing |
| 1231 | Improperly exposed backend function (Convex framework's `downloads: increment` configured as public mutation) | critical | 10.0 | 1 | Supply-Chain Attack |
| 1232 | weak Wi-Fi security | critical | 10.0 | 1 | cyber-espionage |
| 1233 | zero-day vulnerabilities in SaaS provider cloud environments | critical | 10.0 | 1 | cyberespionage |
| 1234 | SQL Injection Vulnerability | critical | 10.0 | 1 | Data Breach |
| 1235 | unpatched or misconfigured endpoints | critical | 10.0 | 1 | ransomware |
| 1236 | Weak vendor security controls | critical | 10.0 | 1 | Ransomware |
| 1237 | Previously unknown vulnerability in the payment processing system | critical | 10.0 | 1 | Data Breach |
| 1238 | SaaS supply chain blind spots | critical | 10.0 | 1 | Ransomware |
| 1239 | CVE-2026-24512 (Improper handling of `rules.http.paths.path` field in Ingress resources) | critical | 10.0 | 1 | Code Execution Vulnerability |
| 1240 | Lack of rate limiting and CAPTCHA controls | critical | 10.0 | 1 | Data Breach |
| 1241 | Unmanaged BYOD Devices | critical | 10.0 | 1 | Social Engineering |
| 1242 | CVE-2024-12686 | critical | 10.0 | 1 | Breach |
| 1243 | Human Error (Compliance with Fraudulent Requests) | critical | 10.0 | 1 | Data Breach |
| 1244 | unpatched software (suspected) | critical | 10.0 | 1 | data breach |
| 1245 | CVE-2025-7028 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1246 | CVE-2026-9082 | critical | 10.0 | 1 | SQL Injection |
| 1247 | Self-propagating payload in NPM packages | critical | 10.0 | 1 | Supply Chain Attack |
| 1248 | Typosquatted Zoom links | critical | 10.0 | 1 | Phishing |
| 1249 | weak intranet security | critical | 10.0 | 1 | data breach |
| 1250 | lack of physical security for copper wiring | critical | 10.0 | 1 | physical security breach |
| 1251 | CVE-2025-6000 | critical | 10.0 | 1 | Vulnerability |
| 1252 | Server Crash | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1253 | AI-Generated Deepfakes | critical | 10.0 | 1 | Data Breach |
| 1254 | F5 vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 1255 | CVE-2025-15576 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1256 | Improper oversight and mismanagement of data protection protocols | critical | 10.0 | 1 | Data Breach |
| 1257 | CVE-2025-32432 (CWE-94: Improper Control of Code Generation) | critical | 10.0 | 1 | Code Injection |
| 1258 | inadequate monitoring of employee activity | critical | 10.0 | 1 | data breach |
| 1259 | Generative AI applications | critical | 10.0 | 1 | ransomware |
| 1260 | Defective Secure Boot shims signed by Microsoft (CVE not specified) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1261 | Unmanaged Credentials | critical | 10.0 | 1 | Data Breach |
| 1262 | Shor's Algorithm (theoretical) | critical | 10.0 | 1 | Emerging Threat |
| 1263 | Lack of two-factor authentication (2FA) | critical | 10.0 | 1 | Supply Chain Attack |
| 1264 | Unsecured ElasticSearch Database | critical | 10.0 | 1 | Data Exposure |
| 1265 | Weaknesses in satellite-ground station security | critical | 10.0 | 1 | Cyber-Physical Threat |
| 1266 | Cryptographic Protocols | critical | 10.0 | 1 | Cryptographic Risk |
| 1267 | ProxyLogon (Microsoft Exchange) | critical | 10.0 | 1 | cyberespionage |
| 1268 | Potential vulnerabilities in NSCC’s infrastructure, outdated 2020 admin manual for HPC3 supercomputer cluster | critical | 10.0 | 1 | Data Breach |
| 1269 | Outdated IT Systems | critical | 10.0 | 1 | Cybercrime |
| 1270 | Lack of Granular Network Segmentation | critical | 10.0 | 1 | EDR/XDR Evasion |
| 1271 | Malicious Word documents | critical | 10.0 | 1 | Security Breach |
| 1272 | Over-Permissive Guest/External User Access | critical | 10.0 | 1 | Social Engineering |
| 1273 | Coding vulnerability in the 'DNA Relatives' feature | critical | 10.0 | 1 | Data Breach |
| 1274 | File System Access API (user-granted permissions) | critical | 10.0 | 1 | Ransomware |
| 1275 | Poor Vendor Security Practices | critical | 10.0 | 1 | Third-Party Breach |
| 1276 | PeopleSoft | critical | 10.0 | 1 | Ransomware |
| 1277 | Weak IoT Device Security (e.g., default credentials, unpatched firmware) | critical | 10.0 | 1 | Distributed Denial of Service (DDoS) |
| 1278 | automated package update mechanisms | critical | 10.0 | 1 | supply chain attack |
| 1279 | Stolen Private Key | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1280 | remote access security | critical | 10.0 | 1 | Ransomware |
| 1281 | AI Model Jailbreak (Disguised Malicious Tasks as Benign) | critical | 10.0 | 1 | Espionage |
| 1282 | Exposed Firewall Configuration Backups (Encrypted but Sensitive) | critical | 10.0 | 1 | Unauthorized Access |
| 1283 | CVE-2025-20333 (Cisco ASA/Firepower - RCE) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1284 | Insufficient Workforce Training (phishing/social engineering) | critical | 10.0 | 1 | Ransomware |
| 1285 | CVE (Oj gem vulnerabilities) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1286 | CVE-2026-33824 (Double-free memory corruption in IKE protocol) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1287 | Unmonitored Devices | critical | 10.0 | 1 | Domain Hijacking |
| 1288 | Delayed Response to Security Alerts | critical | 10.0 | 1 | Data Breach |
| 1289 | Inadequate backup testing policy | critical | 10.0 | 1 | Policy Deficiency |
| 1290 | CVE-2019-7192 | critical | 10.0 | 1 | Cyber Intrusion |
| 1291 | Unique validation node | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1292 | Privacy Regulation Non-Compliance | critical | 10.0 | 1 | Ransomware |
| 1293 | CVE-2023-MoveIt (Critical File Transfer Vulnerability) | critical | 10.0 | 1 | Ransomware |
| 1294 | Misconfigured Elasticsearch Cluster | critical | 10.0 | 1 | Data Breach |
| 1295 | Legacy Operational Technology (OT) systems with known vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1296 | CVE-2026-20223 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1297 | CVE-2026-3300 (CVSS 9.8) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1298 | CVE-2025-10035 (GoAnywhere MFT) | critical | 10.0 | 1 | ransomware |
| 1299 | Human Error (Phishing Susceptibility) & Weak Remote Access Controls | critical | 10.0 | 1 | Data Breach (Phishing & Unauthorized Access) |
| 1300 | VMware vSphere vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1301 | Microsoft Entra ID Self-Service Password Reset Process | critical | 10.0 | 1 | Cloud Data Theft |
| 1302 | CVE-2026-34909 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1303 | inconsistent security standards across geographies | critical | 10.0 | 1 | supply chain attack |
| 1304 | Misconfigured or unmonitored edge devices | critical | 10.0 | 1 | Ransomware |
| 1305 | 7-Zip archive flaw | critical | 10.0 | 1 | Zero-day exploit |
| 1306 | CVE-2024-37079 (CWE-787 - Out-of-bounds Write) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1307 | Lack of regular security reviews | critical | 10.0 | 1 | Data Breach |
| 1308 | blind spots in network visibility | critical | 10.0 | 1 | ransomware |
| 1309 | Misconfigured RDP ports | critical | 10.0 | 1 | Espionage |
| 1310 | UnDefend | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1311 | Internal system vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 1312 | Supply-chain compromise via open-source software | critical | 10.0 | 1 | Supply-Chain Attack |
| 1313 | CVE-2026-33660 (Improper input validation, CWE-94: Code Injection) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1314 | Poor IT-OT segmentation | critical | 10.0 | 1 | Ransomware, Cyber Espionage, Industrial Sabotage |
| 1315 | Zimbra Server vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1316 | Trust in AI Model Updates | critical | 10.0 | 1 | Malware |
| 1317 | VMware virtual machines | critical | 10.0 | 1 | Cyberespionage |
| 1318 | CVE-2024-0132, Docker DoS flaw on Linux | critical | 10.0 | 1 | Vulnerability Exploitation, DoS Attack |
| 1319 | CVE-2026-59310 | critical | 10.0 | 1 | APT Attack |
| 1320 | Time-Triggered Ethernet (TTEthernet) vulnerabilities | critical | 10.0 | 1 | Time Synchronization Attack |
| 1321 | Unsecured Kibana Dashboard | critical | 10.0 | 1 | Data Leak |
| 1322 | 20 security vulnerabilities identified by Claude LLM | critical | 10.0 | 1 | Data Breach, Cyber Espionage |
| 1323 | CVE-2026-3502 (CVSS 7.8) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1324 | CVE-2026-33784 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1325 | Microsoft Silverlight plugin flaw | critical | 10.0 | 1 | Ransomware |
| 1326 | Zero-day flaw in outdated OAuth implementation | critical | 10.0 | 1 | Data Breach |
| 1327 | Phishing, Malicious Software Deployment | critical | 10.0 | 1 | Data Breach, Ransomware |
| 1328 | Unencrypted Linux Partition in Dual-Boot Configuration | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1329 | Remote Code Execution (RCE) in AhsayCBS backup system | critical | 10.0 | 1 | Remote Code Execution |
| 1330 | AI integrations with applications (e.g., Google Calendar, Zoom) | critical | 10.0 | 1 | AI Exploitation |
| 1331 | AI infrastructure misconfigurations | critical | 10.0 | 1 | AI-driven cyberattack |
| 1332 | Social Engineering, Impersonation | critical | 10.0 | 1 | Phishing, Cyber Espionage |
| 1333 | Weaknesses in detection-focused security tools like EDR/XDR | critical | 10.0 | 1 | Ransomware |
| 1334 | Flaw in SecondFi’s native Cardano web wallet generation software | critical | 10.0 | 1 | Exploit |
| 1335 | Ghost Logins (Unmonitored Active Sessions) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1336 | Outdated technology and internet-connected systems | critical | 10.0 | 1 | Cyberattack |
| 1337 | Roundcube and SquirrelMail webmail vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1338 | Lack of Behavioral Analytics for Insider Threat Detection | critical | 10.0 | 1 | Insider Threat (Attempted) |
| 1339 | lack of cyber-physical resilience in maritime navigation systems | critical | 10.0 | 1 | cyber deception |
| 1340 | Manipulation of AmountWithBonus variable | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1341 | Insufficient Log Retention/Preservation | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 1342 | npm auto-update mechanisms, lifecycle hooks in package installation | critical | 10.0 | 1 | Supply Chain Attack |
| 1343 | Customer misconfigurations (not AWS vulnerabilities) | critical | 10.0 | 1 | Cyber Espionage, Lateral Movement, Credential Harvesting |
| 1344 | Cybersecurity Staffing Shortages | critical | 10.0 | 1 | Collaborative Initiative |
| 1345 | CVE-2024-7694 | critical | 10.0 | 1 | Supply Chain Attack |
| 1346 | CVE-2026-19489 (Citrix NetScaler memory overflow) | critical | 10.0 | 1 | ransomware |
| 1347 | CVE-2023-46805 (Ivanti Connect Secure/Policy Secure) | critical | 10.0 | 1 | Ransomware |
| 1348 | Misconfiguration or compromise in Okta SSO and Salesforce Marketing Cloud | critical | 10.0 | 1 | Phishing / Scam |
| 1349 | CVE-2022-29499 | critical | 10.0 | 1 | Ransomware |
| 1350 | Unsanitized Metadata | critical | 10.0 | 1 | Data Leak |
| 1351 | CVE-2025-10035 (Critical, CVSS 10.0) - Deserialization in License Servlet of GoAnywhere MFT | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1352 | CVE-2017-12637 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1353 | 27-year-old OpenBSD flaw | critical | 10.0 | 1 | AI-driven cyber attack |
| 1354 | Fraudulently obtained digital certificates, Lack of Azure tenant credential security | critical | 10.0 | 1 | Malware Distribution / Ransomware Enablement |
| 1355 | Lack of Timely Detection (6-month delay) | critical | 10.0 | 1 | Supply Chain Attack |
| 1356 | CVE-2026-20316 (Cisco Firepower Management Center) | critical | 10.0 | 1 | Zero-day Exploit |
| 1357 | CVE-2026-59309 | critical | 10.0 | 1 | APT Attack |
| 1358 | Incorrect configuration | critical | 10.0 | 1 | Data Breach |
| 1359 | Legacy system vulnerabilities (some dating back to 2013) | critical | 10.0 | 1 | Ransomware |
| 1360 | Default/weak passwords | critical | 10.0 | 1 | Cyber Espionage |
| 1361 | Lack of Cybersecurity Preparedness | critical | 10.0 | 1 | Ransomware Attack |
| 1362 | underfunded IT security | critical | 10.0 | 1 | ransomware |
| 1363 | CVE-2026-0826 (Stack-based buffer overflow in SDP attribute parsing) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1364 | SynologyPhotos application on BeeStation and DiskStation systems | critical | 10.0 | 1 | Zero-Click Vulnerability |
| 1365 | Critical SharePoint Vulnerabilities (July 2025) | critical | 10.0 | 1 | Ransomware Attack |
| 1366 | Compromised Deloitte employee credentials | critical | 10.0 | 1 | data breach |
| 1367 | Inter-Agency Data Governance Weaknesses | critical | 10.0 | 1 | Data Breach |
| 1368 | Inadequate Data Anonymization in AI Features (e.g., Grok AI) | critical | 10.0 | 1 | Data Breach |
| 1369 | Improper Handling of Sensitive Material | critical | 10.0 | 1 | Data Breach |
| 1370 | CISA Known Exploited Vulnerabilities (unspecified) | critical | 10.0 | 1 | Cyber Espionage, Critical Infrastructure Attack |
| 1371 | Default Pre-Shared Keys | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1372 | MongoBleed | critical | 10.0 | 1 | Data Breach |
| 1373 | Lack of access controls (broad permissions) | critical | 10.0 | 1 | Ransomware |
| 1374 | Outdated versions of Windows | critical | 10.0 | 1 | Data Breach, Ransomware |
| 1375 | MFA bypass techniques | critical | 10.0 | 1 | phishing |
| 1376 | Pool initialization bypass | critical | 10.0 | 1 | Exploit |
| 1377 | upstream services | critical | 10.0 | 1 | ransomware |
| 1378 | CVE-2026-50748 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1379 | Unsecured RDP access, absence of MFA | critical | 10.0 | 1 | Ransomware |
| 1380 | Unsafe code evaluation in LDAP autovalues option | critical | 10.0 | 1 | SQL Injection |
| 1381 | Human vulnerabilities (compromised adviser accounts) | critical | 10.0 | 1 | Data Breach |
| 1382 | Stolen personal data (Social Security numbers, birthdates, account credentials) | critical | 10.0 | 1 | Data Breach, Identity Fraud, Account Takeover |
| 1383 | Human Error (Credential Sharing/System Access Granted via Deception) | critical | 10.0 | 1 | Data Breach |
| 1384 | CVE-2021-26828 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1385 | Unauthenticated SQL injection in Lilli’s API, publicly exposed endpoints | critical | 10.0 | 1 | AI-driven cyberattack |
| 1386 | Windows Safe Mode vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1387 | Volume Shadow Copy Service (VSS) for backup manipulation and credential access | critical | 10.0 | 1 | ransomware |
| 1388 | CVE-2025-31324 (SAP NetWeaver) | critical | 10.0 | 1 | Ransomware |
| 1389 | CVE-2025-22225 | critical | 10.0 | 1 | Ransomware |
| 1390 | Opportunistic TLS | critical | 10.0 | 1 | Cross-protocol Application Layer Desynchronization |
| 1391 | Poisoned machine-learning models | critical | 10.0 | 1 | Malware Framework |
| 1392 | developer mistyped dependency installation | critical | 10.0 | 1 | supply chain attack |
| 1393 | Unpatched system (not disclosed) | critical | 10.0 | 1 | Ransomware |
| 1394 | CVE-2024-3400 (Palo Alto GlobalProtect VPN) | critical | 10.0 | 1 | Ransomware Attack |
| 1395 | Trust in Employee | critical | 10.0 | 1 | Insider Threat |
| 1396 | Custom IoT malware, IOCONTROL | critical | 10.0 | 1 | Cyberattack |
| 1397 | CVE-2026-0310 (PAN-OS XML processing buffer overflow) | critical | 10.0 | 1 | Zero-day exploitation |
| 1398 | Insufficient regex anchoring in AWS CodeBuild webhook filters | critical | 10.0 | 1 | Supply Chain Attack |
| 1399 | Historic file server | critical | 10.0 | 1 | Data Breach |
| 1400 | cloud security misconfigurations | critical | 10.0 | 1 | cyber espionage |
| 1401 | Unpatched vulnerability in appointment system software | critical | 10.0 | 1 | Data Breach |
| 1402 | Citrix VPN vulnerabilities | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 1403 | Stale service accounts | critical | 10.0 | 1 | Ransomware |
| 1404 | Unaddressed software vulnerabilities in CM/ECF system (identified in 2019 after a prior 2020 breach) | critical | 10.0 | 1 | Data Breach |
| 1405 | uneven cybersecurity maturity | critical | 10.0 | 1 | data breach |
| 1406 | Avast Anti-Rootkit driver | critical | 10.0 | 1 | Malware Campaign |
| 1407 | Impersonation of trusted contact (reporter) | critical | 10.0 | 1 | Cyber Espionage |
| 1408 | Exposed credentials and access tokens | critical | 10.0 | 1 | Ransomware |
| 1409 | CVE-2025-20363 (Cisco ASA VPN) | critical | 10.0 | 1 | Ransomware |
| 1410 | lack of multi-factor authentication for downloads | critical | 10.0 | 1 | ransomware |
| 1411 | CrushFTP | critical | 10.0 | 1 | Ransomware |
| 1412 | lack of formal AI-use/data privacy policies | critical | 10.0 | 1 | ransomware |
| 1413 | CVE-2024-8525 (Carrier WebCTRL 7.0 - Unauthenticated RCE, CVSS 10.0) | critical | 10.0 | 1 | Vulnerability Exposure |
| 1414 | Stolen Employee Tokens | critical | 10.0 | 1 | Data Breach |
| 1415 | CVE-2025-37164 | critical | 10.0 | 1 | Botnet Campaign |
| 1416 | CVE-2026-50747 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1417 | Fortinet software | critical | 10.0 | 1 | Cyber Attack |
| 1418 | vBulletin vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 1419 | unencrypted data transmission | critical | 10.0 | 1 | ransomware |
| 1420 | Human-Machine Interfaces (HMIs) | critical | 10.0 | 1 | Cyber Sabotage |
| 1421 | CVE-2026-1492 (Privilege Management Flaw in User Registration & Membership Plugin) | critical | 10.0 | 1 | Privilege Escalation |
| 1422 | Third-party software application used to manage client services | critical | 10.0 | 1 | Data Breach |
| 1423 | Lack of Regular Penetration Testing | critical | 10.0 | 1 | Data Breach |
| 1424 | CVE-2026-29000 | critical | 10.0 | 1 | Authentication Bypass |
| 1425 | CVE-2025-33053 (WebDAV External Control of File Name or Path) | critical | 10.0 | 1 | Patch Release |
| 1426 | CVE-2026-55115 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1427 | Inadequate Access Controls for PowerSource Portal | critical | 10.0 | 1 | Data Breach |
| 1428 | Lack of Operational Resilience | critical | 10.0 | 1 | Data Breach |
| 1429 | Well-known attack vector (unspecified) | critical | 10.0 | 1 | Data Breach |
| 1430 | Accessibility Services Permission, Device Admin Permission | critical | 10.0 | 1 | Malware (Ransomware-like) |
| 1431 | Lack of a business associate agreement | critical | 10.0 | 1 | Ransomware Attack |
| 1432 | Unpatched Software Vulnerabilities | critical | 10.0 | 1 | Malware |
| 1433 | compromised authentication credentials | critical | 10.0 | 1 | ransomware |
| 1434 | Vulnerability allowing linkage of email addresses and phone numbers to Twitter accounts | critical | 10.0 | 1 | Data Breach |
| 1435 | CVE-2024-20359 (Privilege Escalation: Admin → Root) | critical | 10.0 | 1 | Cyberattack |
| 1436 | Lack of Access Controls for Sensitive Data Aggregation | critical | 10.0 | 1 | Data Breach |
| 1437 | CVE-2025-68613 (n8n, CVSS 9.9) | critical | 10.0 | 1 | AI-Powered Cyber Attack |
| 1438 | Browser-Based Credential Storage (Syncing Across Devices) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1439 | Fake Job Offers | critical | 10.0 | 1 | Cryptocurrency Scam |
| 1440 | Misconfigured Security Controls | critical | 10.0 | 1 | Malware |
| 1441 | CVE-2025-20333 (Cisco ASA VPN) | critical | 10.0 | 1 | Ransomware |
| 1442 | Malicious code injection | critical | 10.0 | 1 | Data Breach |
| 1443 | Internet-exposed PLCs | critical | 10.0 | 1 | Cyberattack on Operational Technology (OT) |
| 1444 | Unguarded Museum | critical | 10.0 | 1 | Theft |
| 1445 | Remote Terminal Units (RTUs) | critical | 10.0 | 1 | Cyber Sabotage |
| 1446 | user trust in search engine ads | critical | 10.0 | 1 | ransomware |
| 1447 | Third-party systems (Famly platform and one other unnamed system) | critical | 10.0 | 1 | data breach |
| 1448 | outsourcing risks | critical | 10.0 | 1 | data breach |
| 1449 | Corporate Virtual Desktop Infrastructure (VDI) | critical | 10.0 | 1 | Data Theft Extortion |
| 1450 | Roundcube webmail XSS vulnerability, twofactorgauthenticator plugin misconfiguration | critical | 10.0 | 1 | Cyberespionage |
| 1451 | Weak Authentication in Third-Party Platforms | critical | 10.0 | 1 | Data Breach |
| 1452 | Telnyx SDK | critical | 10.0 | 1 | Ransomware |
| 1453 | Insecure data storage and handling | critical | 10.0 | 1 | Data Breach |
| 1454 | Legitimate Cybersecurity Testing Impersonation | critical | 10.0 | 1 | Espionage |
| 1455 | potential prior SharePoint vulnerabilities (historical context for Storm-2603) | critical | 10.0 | 1 | ransomware |
| 1456 | SharePoint Permissions Issue | critical | 10.0 | 1 | Data Breach |
| 1457 | unmanaged devices | critical | 10.0 | 1 | ransomware |
| 1458 | misuse of scientific research cover | critical | 10.0 | 1 | espionage |
| 1459 | Insecure Build Process | critical | 10.0 | 1 | Supply Chain Attack |
| 1460 | Insufficient Identity Security Policies for AI Agents | critical | 10.0 | 1 | Identity Security Crisis |
| 1461 | Mutable version tags | critical | 10.0 | 1 | Supply Chain Attack, Extortion Campaign |
| 1462 | Vulnerabilities in decentralized energy infrastructure and OT/ICS systems | critical | 10.0 | 1 | Cyberattack on Critical Infrastructure |
| 1463 | Legacy infrastructure risks | critical | 10.0 | 1 | Ransomware |
| 1464 | Unauthorized access to security credentials | critical | 10.0 | 1 | Financial Fraud, Insider Threat |
| 1465 | Java Vulnerability | critical | 10.0 | 1 | Data Breach |
| 1466 | Weak Access Controls (e.g., AWS Misconfigurations) | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 1467 | Public-Key Cryptography (e.g., RSA, ECC) | critical | 10.0 | 1 | Emerging Threat |
| 1468 | Alert Fatigue and False Positives | critical | 10.0 | 1 | EDR/XDR Evasion |
| 1469 | ATM Skimming Devices | critical | 10.0 | 1 | ATM Skimming |
| 1470 | Security flaw in SonicWall’s systems | critical | 10.0 | 1 | Ransomware |
| 1471 | CVE-2024-3721 (TBK DVRs) | critical | 10.0 | 1 | Botnet / DDoS Campaign |
| 1472 | Flaw in smart contract calls | critical | 10.0 | 1 | DeFi Exploit |
| 1473 | CVE-2026-5757 (Out-of-bounds memory vulnerability in model quantization engine) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1474 | User Trust in Fake App | critical | 10.0 | 1 | Malware Attack |
| 1475 | Apache Log4j2 | critical | 10.0 | 1 | Reconnaissance |
| 1476 | undersea cable physical exposure | critical | 10.0 | 1 | sabotage |
| 1477 | Fake suspicious activity notifications | critical | 10.0 | 1 | Phishing |
| 1478 | Human Trust in Browser Update Prompts | critical | 10.0 | 1 | Malware Infection |
| 1479 | Weak multi-factor authentication (MFA) | critical | 10.0 | 1 | AI-driven vulnerability exploitation |
| 1480 | Lack of two-factor authentication (2FA), persistent access to Aeroflot’s infrastructure | critical | 10.0 | 1 | Supply-Chain Attack |
| 1481 | CVE-2025-30333 | critical | 10.0 | 1 | Data Breach, Persistent Malware, Unauthorized Access |
| 1482 | CVE-2024-40766 (SonicWall SSLVPN improper access control) | critical | 10.0 | 1 | ransomware |
| 1483 | SolarWinds Orion Software | critical | 10.0 | 1 | Supply Chain Attack |
| 1484 | GPS signal susceptibility to jamming | critical | 10.0 | 1 | GPS jamming |
| 1485 | unrestricted access to GitHub Actions environment variables | critical | 10.0 | 1 | supply chain attack |
| 1486 | Limited control over shipping and air cargo spaces | critical | 10.0 | 1 | Economic Vulnerability |
| 1487 | Disabled Logging | critical | 10.0 | 1 | Data Exposure |
| 1488 | outdated business continuity plans | critical | 10.0 | 1 | ransomware |
| 1489 | virtualized environment exploits | critical | 10.0 | 1 | ransomware |
| 1490 | Default credentials, weak cybersecurity oversight, legacy systems | critical | 10.0 | 1 | Cyber Espionage, Supply Chain Attack |
| 1491 | Unauthorized physical access to sensitive data | critical | 10.0 | 1 | Data Theft |
| 1492 | CVE-2025-26319 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1493 | Misconfigured firewalls | critical | 10.0 | 1 | APT Attack |
| 1494 | Lack of Multi-Factor Authentication (MFA) for Vendor Logins | critical | 10.0 | 1 | Cyberattack |
| 1495 | LiteLLM | critical | 10.0 | 1 | Ransomware |
| 1496 | weak encryption key management practices | critical | 10.0 | 1 | ransomware |
| 1497 | CVE-2025-27915 (Stored XSS in Zimbra Classic Web Client via ICS files) | critical | 10.0 | 1 | Cyber Espionage |
| 1498 | HTML/CSS injection in draft restore dialog’s subject field | critical | 10.0 | 1 | SQL Injection |
| 1499 | Separate vulnerability in login pages | critical | 10.0 | 1 | Ransomware |
| 1500 | CVE-2025-32713 (Windows Common Log File System Driver EoP) | critical | 10.0 | 1 | Patch Release |
| 1501 | Unsupervised automation | critical | 10.0 | 1 | AI-driven breach |
| 1502 | inadequate security of payment systems | critical | 10.0 | 1 | data breach |
| 1503 | Unpatched IoT/OT Systems | critical | 10.0 | 1 | EDR/XDR Evasion |
| 1504 | CVE-2025-23319 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1505 | QR Code Vulnerability | critical | 10.0 | 1 | Espionage |
| 1506 | Mismanagement of sensitive data, lack of secure cloud storage | critical | 10.0 | 1 | Data Breach |
| 1507 | Automatic execution of malicious code during package installation or project builds | critical | 10.0 | 1 | Supply Chain Attack |
| 1508 | gaps in patching | critical | 10.0 | 1 | Ransomware |
| 1509 | Canvas Free for Teacher service vulnerability | critical | 10.0 | 1 | Data Breach |
| 1510 | CVE-2024-50603 | critical | 10.0 | 1 | Cryptojacking and Backdoor Exploitation |
| 1511 | Enterprise hardware vulnerabilities (Fortinet, SonicWall, Cisco) | critical | 10.0 | 1 | Ransomware |
| 1512 | interconnected manufacturing systems | critical | 10.0 | 1 | cyberattack |
| 1513 | CVE-2026-21509 (RTF parsing flaw) | critical | 10.0 | 1 | Cyber Espionage |
| 1514 | GPS signal manipulation | critical | 10.0 | 1 | cyber deception |
| 1515 | Linux Kernel bug (Fragnesia) | critical | 10.0 | 1 | Zero-day Exploit |
| 1516 | CVE-2026-6875 | critical | 10.0 | 1 | Sandbox Escape |
| 1517 | Absence de formation des employés en cybersécurité | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1518 | Stored Credentials in Veeam Backup Infrastructure | critical | 10.0 | 1 | Social Engineering |
| 1519 | Misconfigured cloud infrastructure | critical | 10.0 | 1 | Cloud Exploitation Campaign |
| 1520 | Unsecured PLCs exposed to the internet | critical | 10.0 | 1 | Cyber Attack |
| 1521 | XSS vulnerability in StealC control panel | critical | 10.0 | 1 | malware |
| 1522 | network security issues | critical | 10.0 | 1 | third-party breach |
| 1523 | emotional manipulation | critical | 10.0 | 1 | phishing |
| 1524 | CVE-2025-59287 (Windows Server Update Services - WSUS) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1525 | PROMISQROUTE (Prompt-based Router Open-Mode Manipulation Induced via SSRF-like Queries, Reconfiguring Operations Using Trust Evasion) | critical | 10.0 | 1 | AI System Vulnerability |
| 1526 | Unsecured Data Storage | critical | 10.0 | 1 | Data Breach |
| 1527 | weak account/access controls (reactivation of default accounts, new privileged users) | critical | 10.0 | 1 | ransomware |
| 1528 | Legitimate SaaS platforms for command-and-control | critical | 10.0 | 1 | Data Theft |
| 1529 | Legacy OT systems, lack of OT security prioritization, IT-OT convergence | critical | 10.0 | 1 | Ransomware |
| 1530 | Critical RCE vulnerability in widely used VPN | critical | 10.0 | 1 | RCE (Remote Code Execution) |
| 1531 | 2,000 previously unknown vulnerabilities across major operating systems | critical | 10.0 | 1 | AI-Driven Vulnerability Discovery and Exploitation |
| 1532 | Microsoft SharePoint ToolShell vulnerabilities (zero-day, patched post-exploitation) | critical | 10.0 | 1 | Ransomware |
| 1533 | CVE-2023-52271 | critical | 10.0 | 1 | Ransomware |
| 1534 | CVE-2025-6218 | critical | 10.0 | 1 | Cyberespionage |
| 1535 | Legacy protocols misconfigurations | critical | 10.0 | 1 | Exposed Servers |
| 1536 | Employee Use of Unvetted AI Tools | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 1537 | CWE-22: Path Traversal in Docker build context configuration (smithery.yaml) | critical | 10.0 | 1 | Supply Chain Attack |
| 1538 | Digitized supply chains | critical | 10.0 | 1 | Cyberattack |
| 1539 | CVE-2025-3052 | critical | 10.0 | 1 | Secure Boot Bypass |
| 1540 | Dual-use technology misuse | critical | 10.0 | 1 | Policy Violation and Dual-Use Technology Misuse |
| 1541 | Insufficient insider threat controls | critical | 10.0 | 1 | Data Breach |
| 1542 | Lack of strict removable media controls, insufficient monitoring of privileged users | critical | 10.0 | 1 | Insider Threat, Data Exfiltration |
| 1543 | CVE-2025-20362 (Memory corruption in Cisco ASA Software) | critical | 10.0 | 1 | Zero-day exploitation |
| 1544 | third-party compromises (35.5% of breaches in 2024) | critical | 10.0 | 1 | ransomware |
| 1545 | CVE-2023-20269 (Cisco) | critical | 10.0 | 1 | ransomware |
| 1546 | Known vulnerability in data storage systems | critical | 10.0 | 1 | Ransomware Attack |
| 1547 | Unprotected 'Recent Links' feature with predictable URL format, enabling unauthorized data scraping via crawlers | critical | 10.0 | 1 | Data Exposure |
| 1548 | Inadequate Contractual Security Provisions | critical | 10.0 | 1 | Data Breach |
| 1549 | Lack of multi-factor authentication (MFA) on an outsourced partner’s administrator account | critical | 10.0 | 1 | Ransomware |
| 1550 | Buffer underflow in Synopsys DWC2 USB controller (BootROM) | critical | 10.0 | 1 | Hardware Vulnerability |
| 1551 | CVE-2026-65094 (CWE-123 write-what-where condition) | critical | 10.0 | 1 | Vulnerability |
| 1552 | CVE-2024-9852 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 1553 | Critical vulnerabilities within the ESXi platform | critical | 10.0 | 1 | Ransomware |
| 1554 | Apache Log4j flaws | critical | 10.0 | 1 | Ransomware |
| 1555 | Exposed programmable logic controllers (PLCs), lack of network segmentation, default credentials | critical | 10.0 | 1 | Cyberattack |
| 1556 | default LDAP group configurations | critical | 10.0 | 1 | ransomware |
| 1557 | CVE-2025-61882 (Oracle E-Business Suite Zero-Day) | critical | 10.0 | 1 | Data Breach |
| 1558 | CVE-2026-34976 (Missing authorization check in restoreTenant command) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1559 | Misconfigured or stolen OAuth tokens, insufficient monitoring of API access logs | critical | 10.0 | 1 | Supply Chain Attack |
| 1560 | YellowKey (Windows zero-day) | critical | 10.0 | 1 | Zero-day Exploit |
| 1561 | Saved Credentials in Browsers/Email Clients | critical | 10.0 | 1 | Account Compromise |
| 1562 | Fortinet firewalls and VPNs | critical | 10.0 | 1 | ransomware |
| 1563 | insufficient user education on phishing/social engineering | critical | 10.0 | 1 | cyber espionage |
| 1564 | Inadequate penetration testing | critical | 10.0 | 1 | Data Breach |
| 1565 | Microsoft Exchange | critical | 10.0 | 1 | ransomware |
| 1566 | Social Media Account Compromise | critical | 10.0 | 1 | Phishing, Social Engineering |
| 1567 | LLMNR/NBT-NS | critical | 10.0 | 1 | Ransomware |
| 1568 | improper cloud storage configuration | critical | 10.0 | 1 | ransomware |
| 1569 | Six vulnerabilities | critical | 10.0 | 1 | Exploit Kit / Cyber Espionage |
| 1570 | Unspecified (32% of attacks involved exploited vulnerabilities) | critical | 10.0 | 1 | ransomware |
| 1571 | Unmonitored third-party script dependencies | critical | 10.0 | 1 | Data Breach |
| 1572 | Legitimate Tools Abuse (Bitsadmin, PowerShell, curl) | critical | 10.0 | 1 | Targeted Cyberattack |
| 1573 | Fortinet SSL VPN vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1574 | GPS signal weakness | critical | 10.0 | 1 | spoofing |
| 1575 | Vulnerabilities in Synology Network-Attached Storage (NAS) devices | critical | 10.0 | 1 | Ransomware |
| 1576 | CVE-2026-7482 (Memory Overread in GGUF Model File Processing) | critical | 10.0 | 1 | Data Breach |
| 1577 | CVE-2026-21858 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1578 | Unpatched or zero-day flaws in technology platforms | critical | 10.0 | 1 | Ransomware |
| 1579 | CVE-2025-0282 (Ivanti Pulse Connect VPN) | critical | 10.0 | 1 | cyberespionage |
| 1580 | CVE-2026-73570 (OS command injection in SNMP monitoring path) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1581 | mismanaged certificates | critical | 10.0 | 1 | third-party breach |
| 1582 | lack of tamper-proof audit trails | critical | 10.0 | 1 | ransomware |
| 1583 | CVE-2022-41328 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 1584 | Outdated Industrial Control Systems (ICS) | critical | 10.0 | 1 | Cyber Espionage |
| 1585 | FortiOS (unspecified CVEs) | critical | 10.0 | 1 | ransomware |
| 1586 | CVE-2026-0755 (ZDI-26-021, ZDI-CAN-27783) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1587 | CVE-2025-20333 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1588 | SCADA-IT Data Convergence | critical | 10.0 | 1 | Cyber Espionage |
| 1589 | Unmonitored ESXCLI Command Usage | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 1590 | CVE-2016-10033 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1591 | React2Shell (CVE not specified) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1592 | Vulnerability in the virtual private network | critical | 10.0 | 1 | Ransomware |
| 1593 | Weak or Missing End-to-End Encryption | critical | 10.0 | 1 | Data Breach |
| 1594 | CVE-2023-3596 | critical | 10.0 | 1 | Cyber Espionage |
| 1595 | Absence of Memoranda of Agreement (MOAs) with LGUs | critical | 10.0 | 1 | Data Privacy Violation |
| 1596 | Actively exploited CVEs | critical | 10.0 | 1 | Ransomware |
| 1597 | CVE-2025-49157 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1598 | Poorly Secured ICS | critical | 10.0 | 1 | Cyberattack |
| 1599 | Bypassed consent protocols, vulnerabilities in offshored data-management tools | critical | 10.0 | 1 | Data Breach |
| 1600 | Oracle WebLogic (unidentified flaw) | critical | 10.0 | 1 | Ransomware Attack |
| 1601 | EternalBlue (WannaCry, 2017) | critical | 10.0 | 1 | ransomware |
| 1602 | Legacy Protocols (NTLM Enabled for Backward Compatibility) | critical | 10.0 | 1 | Data Breach |
| 1603 | Stolen Credentials (Infostealer Malware) | critical | 10.0 | 1 | Supply Chain Attack |
| 1604 | Unmanaged machine identities | critical | 10.0 | 1 | Ransomware |
| 1605 | Hidden preinstall scripts | critical | 10.0 | 1 | Supply Chain Attack |
| 1606 | Open USB ports | critical | 10.0 | 1 | APT Attack |
| 1607 | Over-Permissioned IAM Roles | critical | 10.0 | 1 | Predictive Analysis |
| 1608 | CVE-2026-3055 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1609 | Weakness in GPS navigation systems (susceptibility to spoofing) | critical | 10.0 | 1 | GPS spoofing |
| 1610 | Client-side file type restrictions without server-side validation | critical | 10.0 | 1 | Cloud Account Takeover |
| 1611 | Account-specific vulnerability | critical | 10.0 | 1 | Data Breach |
| 1612 | GenAI Prompt Leakage | critical | 10.0 | 1 | Cyber-Attack |
| 1613 | Public-facing file-sharing folder | critical | 10.0 | 1 | Ransomware |
| 1614 | Default passwords, Outdated software, Lack of manual updates | critical | 10.0 | 1 | Data Breach, Voyeurism, Illegal Content Distribution |
| 1615 | Lack of Email Filtering | critical | 10.0 | 1 | Targeted Cyberattack |
| 1616 | CVE-2025-34291 (Origin Validation Error - CWE-346) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1617 | Absence of Privacy-Enhancing Technologies (PETs) | critical | 10.0 | 1 | Data Breach |
| 1618 | Unpatched Kentico CMS (v12.0.0) with known vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 1619 | Interception and editing of RF signals | critical | 10.0 | 1 | Vulnerability |
| 1620 | cloud security weaknesses | critical | 10.0 | 1 | ransomware |
| 1621 | CVE-2023-23397 (Microsoft Outlook Elevation of Privilege Vulnerability) | critical | 10.0 | 1 | Cyber Espionage |
| 1622 | Windows User Profile Service exploit (LegacyHive PoC) | critical | 10.0 | 1 | Zero-day exploit |
| 1623 | Third-party AI tool vulnerabilities | critical | 10.0 | 1 | DDoS |
| 1624 | Insufficient Input Validation (CWE-20) | critical | 10.0 | 1 | Unauthorized Access |
| 1625 | Legacy Infrastructure Weaknesses | critical | 10.0 | 1 | Data Breach |
| 1626 | Failure to randomize hostnames in VMmanager, KMS-enabled unlicensed operation | critical | 10.0 | 1 | ransomware |
| 1627 | CVE-2025-2171 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1628 | CVE-2025-24472 | critical | 10.0 | 1 | Ransomware |
| 1629 | delayed maintenance response | critical | 10.0 | 1 | physical security breach |
| 1630 | BlueHammer | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1631 | Unauthorized access to sensitive databases, insecure data handling | critical | 10.0 | 1 | Data Breach |
| 1632 | Legitimate Identity Abuse | critical | 10.0 | 1 | Data Breach |
| 1633 | Insufficient Backup Protocols | critical | 10.0 | 1 | Ransomware |
| 1634 | Poor IAM practices | critical | 10.0 | 1 | Ransomware |
| 1635 | D-Link vulnerabilities | critical | 10.0 | 1 | Botnet |
| 1636 | Systemic vulnerabilities in critical infrastructure | critical | 10.0 | 1 | Data Breach |
| 1637 | CVE-2025-25249 (heap-based buffer-overflow in cw_acd daemon) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1638 | CVE-2022-41082 | critical | 10.0 | 1 | Ransomware |
| 1639 | Compromised WordPress sites, social engineering (fake updates) | critical | 10.0 | 1 | Malware Distribution / Botnet Takedown |
| 1640 | Unrotated Factory-Default Logins | critical | 10.0 | 1 | Cyber Espionage |
| 1641 | Protection insuffisante des terminaux | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1642 | Overly permissive IAM policies | critical | 10.0 | 1 | Supply-Chain Attack |
| 1643 | outdated configurations | critical | 10.0 | 1 | ransomware |
| 1644 | encryption gaps | critical | 10.0 | 1 | AI-enabled breach |
| 1645 | Lapse of CISA 2015 liability protections | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 1646 | CVE-2025-30247 (OS Command Injection in Firmware UI) | critical | 10.0 | 1 | Vulnerability |
| 1647 | CVE-2024-56336 | critical | 10.0 | 1 | Vulnerability |
| 1648 | Compromised third-party vendor credentials | critical | 10.0 | 1 | Data Breach |
| 1649 | Unpatched Software (e.g., Equifax) | critical | 10.0 | 1 | Data Breach |
| 1650 | CVE-2023-41348 | critical | 10.0 | 1 | botnet |
| 1651 | CVE-2025-32433 | critical | 10.0 | 1 | Ransomware |
| 1652 | Single-character coding error | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1653 | Unpatched vulnerability disclosed in December 2024 | critical | 10.0 | 1 | Data Breach |
| 1654 | human error (social engineering via phishing) | critical | 10.0 | 1 | cyberespionage |
| 1655 | arbitrary code execution in CI/CD pipeline | critical | 10.0 | 1 | supply chain attack |
| 1656 | Lax Hiring Processes | critical | 10.0 | 1 | Insider Threat |
| 1657 | Lack of proactive threat detection and centralized incident response | critical | 10.0 | 1 | Cyber Espionage |
| 1658 | Lack of Monitoring for Insider Threats | critical | 10.0 | 1 | SCADA Tampering / Insider Threat |
| 1659 | Over-reliance on single-source supply chain (China) | critical | 10.0 | 1 | Geopolitical Risk |
| 1660 | Unknown vulnerability in the company's network | critical | 10.0 | 1 | Data Breach |
| 1661 | CVE-2025-7742 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1662 | Unspecified Salesforce vulnerability (likely API or authentication flaw) | critical | 10.0 | 1 | Data Breach |
| 1663 | CVE-2020-8515 | critical | 10.0 | 1 | Botnet, DDoS, IoT Exploitation |
| 1664 | Architectural flaws in perimeter defenses, lack of segmentation and monitoring | critical | 10.0 | 1 | Data Breach |
| 1665 | AIS protocol lack of authentication | critical | 10.0 | 1 | spoofing |
| 1666 | CVE-2026-2005 (Heap-based buffer overflow in PGP session key parsing) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1667 | CVE-2026-25108 | critical | 10.0 | 1 | OS Command Injection |
| 1668 | Heap overflow in FFmpeg’s MagicYUV decoder (CVE-2026-8461) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1669 | Ivanti vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1670 | Lack of Security Layers | critical | 10.0 | 1 | Ransomware |
| 1671 | Unknown vulnerability in online platforms | critical | 10.0 | 1 | Data Breach |
| 1672 | CVE-2025-10035 (Critical vulnerability in Fortra's GoAnywhere MFT) | critical | 10.0 | 1 | Ransomware |
| 1673 | Lack of Monitoring for Renamed Binaries | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 1674 | Backup Restoration Failures | critical | 10.0 | 1 | Ransomware |
| 1675 | Cisco-related exploits | critical | 10.0 | 1 | Ransomware |
| 1676 | CVE-2026-2329 (Stack-based buffer overflow in /cgi-bin/api.values.Get endpoint) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1677 | Hidden malicious proxy in AI agents | critical | 10.0 | 1 | Vulnerability Exploit |
| 1678 | Unspecified vulnerability in MOVEit file transfer platform (known to CL0P) | critical | 10.0 | 1 | Data Breach |
| 1679 | UNECE R155 Non-Compliance (Insecure Deployed Software) | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 1680 | CVE-2026-22755 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1681 | Lack of domestic rare earth processing capacity | critical | 10.0 | 1 | Geopolitical Risk |
| 1682 | Uncontrolled AI Tool Integration | critical | 10.0 | 1 | Data Breach Risk |
| 1683 | Weak login credentials | critical | 10.0 | 1 | Data Breach |
| 1684 | Payment processing system vulnerability | critical | 10.0 | 1 | Data Breach |
| 1685 | CVE-2026-20181 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1686 | Exposed web directories | critical | 10.0 | 1 | Cyber Intrusion |
| 1687 | CVE-2026-32191 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1688 | Vulnerabilities in Accellion file transfer platform | critical | 10.0 | 1 | Data Breach |
| 1689 | CVE-2026-23918 (double free memory corruption) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1690 | CVE-2026-0740 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1691 | CVE-2025-28137 (Totolink) | critical | 10.0 | 1 | Botnet |
| 1692 | Absence of Multi-Factor Authentication (MFA) | critical | 10.0 | 1 | Ransomware |
| 1693 | CVE-2024-37085 (Cisco) | critical | 10.0 | 1 | ransomware |
| 1694 | CVE-2025-1316 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1695 | CVE-2026-41096 (Heap-based buffer overflow in DNSAPI.dll) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1696 | Remote Code Execution (RCE) | critical | 10.0 | 1 | Security Vulnerabilities |
| 1697 | Unpatched Third-Party Integrations (Salesloft Drift) | critical | 10.0 | 1 | Data Breach |
| 1698 | User Trust in Popular Repositories | critical | 10.0 | 1 | Malware Distribution and Phishing |
| 1699 | Remote code execution vulnerability in SharePoint’s authentication mechanism | critical | 10.0 | 1 | Cyberattack |
| 1700 | Open Amazon S3 bucket | critical | 10.0 | 1 | Data Breach |
| 1701 | Precision rounding error in swap calculations | critical | 10.0 | 1 | Exploit |
| 1702 | CVE-2026-42533 (Missing save/restore mechanism in NGINX’s script engine for PCRE capture state) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1703 | CVE-2024-XXXX (Unauthenticated Command Injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1704 | Unsecured communication channels (WhatsApp) | critical | 10.0 | 1 | Data Breach |
| 1705 | Unintentional Misconfiguration | critical | 10.0 | 1 | Data Exposure |
| 1706 | delayed AV detection due to obfuscation | critical | 10.0 | 1 | ransomware |
| 1707 | Misconfigured WAF | critical | 10.0 | 1 | Data Breach |
| 1708 | Jira | critical | 10.0 | 1 | Data Leak |
| 1709 | Undetected network access | critical | 10.0 | 1 | Ransomware |
| 1710 | Vulnerable server | critical | 10.0 | 1 | Ransomware |
| 1711 | CVE-2026-65643 (cPanel domain parking functionality) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1712 | token-based publishing model | critical | 10.0 | 1 | supply chain attack |
| 1713 | Vulnerabilities in Change Healthcare’s IT infrastructure | critical | 10.0 | 1 | Ransomware |
| 1714 | Misconfigured or overly permissive domain replication permissions | critical | 10.0 | 1 | Data Breach / Credential Theft / Privilege Escalation |
| 1715 | Lack of real-time threat-sharing incentives | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 1716 | Sonatype Nexus | critical | 10.0 | 1 | Cyberattack (Reconnaissance Campaign) |
| 1717 | Insufficient multi-factor authentication (MFA) protections | critical | 10.0 | 1 | Ransomware |
| 1718 | Improperly secured AJAX action (CVE not specified) | critical | 10.0 | 1 | Privilege Escalation |
| 1719 | Operational Trust | critical | 10.0 | 1 | Data Breach |
| 1720 | Overprivileged identities | critical | 10.0 | 1 | Cloud Infrastructure Compromise |
| 1721 | Improper Access Controls / Platform Misconfiguration | critical | 10.0 | 1 | Data Exposure |
| 1722 | CVE-2025-44179 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1723 | Gaps in GDPR Data Protection for Vehicle-Generated Data | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 1724 | IPMI 2.0 protocol flaw (weak challenge-response mechanism) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1725 | legacy monitoring tools | critical | 10.0 | 1 | data_breach |
| 1726 | Security software vulnerability | critical | 10.0 | 1 | Ransomware |
| 1727 | SHA-1 | critical | 10.0 | 1 | Data Breach |
| 1728 | Misconfigured Cloud Identity and Access Management (IAM) | critical | 10.0 | 1 | Data Breach |
| 1729 | CVE-2024-32114 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1730 | Predictable defense patterns | critical | 10.0 | 1 | AI-driven cyberattack |
| 1731 | cloud security negligence | critical | 10.0 | 1 | cyberattack |
| 1732 | default weak password policies (privileged accounts <14 characters) | critical | 10.0 | 1 | ransomware |
| 1733 | Lack of global standards for D2D services | critical | 10.0 | 1 | Cyber-Physical Threat |
| 1734 | CVE in Tridium’s Niagara Framework (13 vulnerabilities, Nozomi Networks) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 1735 | Microsoft products (17% of exploitations) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1736 | Website Software | critical | 10.0 | 1 | Data Breach |
| 1737 | Trusted dependency chains, Node.js sandbox escape technique | critical | 10.0 | 1 | Supply-Chain Attack |
| 1738 | Exposed Presence/Status Data | critical | 10.0 | 1 | Social Engineering |
| 1739 | Misconfigured OAuth integrations (historical, via Salesloft's Drift) | critical | 10.0 | 1 | Extortion |
| 1740 | FortiGate Vulnerabilities | critical | 10.0 | 1 | Ransomware Attack |
| 1741 | CVE-2026-3497 (OpenSSH GSSAPI Key Exchange) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1742 | CVE-2025-68613 (n8n workflow automation) | critical | 10.0 | 1 | AI-driven cyberattack |
| 1743 | Inadequate monitoring for suspicious activity | critical | 10.0 | 1 | Data Breach |
| 1744 | CVE-2026-2256 (Inadequate input sanitization in MS-Agent's 'Shell tool') | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1745 | CVE-2025-47171 (Windows Netlogon Use of Uninitialized Resources) | critical | 10.0 | 1 | Patch Release |
| 1746 | SmarterMail | critical | 10.0 | 1 | Ransomware |
| 1747 | Zero-Day Vulnerability in Fortra's GoAnywhere MFT | critical | 10.0 | 1 | Data Breach |
| 1748 | Unencrypted AI Training Datasets/Model Checkpoints | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 1749 | Lack of Behavioral Anomaly Detection | critical | 10.0 | 1 | Insider Threat |
| 1750 | Default Authentication Bypasses | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1751 | LOLDrivers (Living Off The Land Drivers) - 'truesight.sys' from RogueKiller AntiRootkit | critical | 10.0 | 1 | ransomware |
| 1752 | CVE-2026-34197 (13-year-old flaw in Apache ActiveMQ Classic) and CVE-2024-32114 (authentication bypass) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1753 | Third-Party Repository Access | critical | 10.0 | 1 | AI Cybersecurity Risk |
| 1754 | Poorly maintained systems | critical | 10.0 | 1 | Ransomware |
| 1755 | CVE-2023-34048 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 1756 | CVE-2026-31431 (Linux Kernel Privilege Escalation) | critical | 10.0 | 1 | Data Breach |
| 1757 | Unpatched vulnerability in HealthNet’s legacy database software | critical | 10.0 | 1 | Data Breach |
| 1758 | CVE-2026-27685 (Insecure deserialization in SAP NetWeaver Enterprise Portal Administration) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1759 | Lack of API Key Monitoring | critical | 10.0 | 1 | Influence Operation |
| 1760 | Protection relays | critical | 10.0 | 1 | Cyber Sabotage |
| 1761 | Memory Injection (persistent threat mechanism) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1762 | CVE-2024-55591 (FortiOS/FortiProxy Race Condition Authentication Bypass) | critical | 10.0 | 1 | Unauthorized Access |
| 1763 | Systemic security weaknesses, undetected breach for over two years | critical | 10.0 | 1 | Data Breach, Fraud, Identity Theft |
| 1764 | Google Play Store Security | critical | 10.0 | 1 | Malware |
| 1765 | CVE-2025-10035 (Critical deserialization flaw in GoAnywhere MFT) | critical | 10.0 | 1 | Zero-day exploitation |
| 1766 | Velociraptor CVE-2025-6264 (privilege escalation to arbitrary command execution) | critical | 10.0 | 1 | Ransomware |
| 1767 | Compromised digital certificate, trusted update infrastructure | critical | 10.0 | 1 | Supply Chain Attack |
| 1768 | Mobile carrier verification processes, SMS-based authentication | critical | 10.0 | 1 | SIM Swap Attack |
| 1769 | Identity Debt | critical | 10.0 | 1 | Data Breach |
| 1770 | Lack of basic security features such as two-factor authentication | critical | 10.0 | 1 | Data Breach |
| 1771 | Incorrect mailing of care management letters | critical | 10.0 | 1 | Data Breach |
| 1772 | Vulnerabilities in interconnected operational systems | critical | 10.0 | 1 | Cyberattack |
| 1773 | LogoFAIL flaws (CVE-2023-40238) | critical | 10.0 | 1 | UEFI Bootkit |
| 1774 | CVE-2025-64175 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1775 | Public Internet Exposure | critical | 10.0 | 1 | Exposure of Vulnerable Systems |
| 1776 | Legitimate signed drivers | critical | 10.0 | 1 | Ransomware |
| 1777 | Azure Key Vault Compromise | critical | 10.0 | 1 | Data Exfiltration |
| 1778 | REST API endpoints | critical | 10.0 | 1 | Data Breach |
| 1779 | Default credentials, unpatched Unitronics PLC software | critical | 10.0 | 1 | Cyberattack |
| 1780 | weak supply chain security | critical | 10.0 | 1 | data breach |
| 1781 | AI system weaknesses | critical | 10.0 | 1 | ransomware |
| 1782 | Direct Internet Exposure | critical | 10.0 | 1 | Cyber-Physical Attack |
| 1783 | CVE-2024-38200 | critical | 10.0 | 1 | Zero-Day Exploit |
| 1784 | Atlassian Confluence | critical | 10.0 | 1 | Cyberattack (Reconnaissance Campaign) |
| 1785 | CVE-2017-0144 (EternalBlue) | critical | 10.0 | 1 | Ransomware |
| 1786 | React Server Components RCE vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1787 | Inadequate Reporting Processes | critical | 10.0 | 1 | Data Breach |
| 1788 | Cisco AnyConnect software vulnerability | critical | 10.0 | 1 | Data Breach |
| 1789 | Cultural Gap Between IT/OT Teams | critical | 10.0 | 1 | Cyber-Physical Attack |
| 1790 | Fragmented Security Posture (On-Premises vs. Cloud Visibility Gaps) | critical | 10.0 | 1 | Data Breach |
| 1791 | CVE-2025-33064 (Windows SMB Improper Access Control) | critical | 10.0 | 1 | Patch Release |
| 1792 | critical and zero-day vulnerabilities in internet-facing network equipment | critical | 10.0 | 1 | ransomware |
| 1793 | Compromised logistics systems and load boards | critical | 10.0 | 1 | Cyber-Enabled Cargo Theft |
| 1794 | CVE-2026-87020 (Heap Out-of-Bounds Write via Integer Overflow in PNG/JPEG Decoding) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1795 | CVE-2025-30232 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1796 | Zero-day SQL injection vulnerability | critical | 10.0 | 1 | Data Breach |
| 1797 | Palo Alto PAN-OS | critical | 10.0 | 1 | Ransomware |
| 1798 | Stolen username and password of a UN employee purchased off the dark web | critical | 10.0 | 1 | Data Breach |
| 1799 | Misconfigurations in operational technology (OT) systems | critical | 10.0 | 1 | Exposure of Critical Infrastructure |
| 1800 | CVE-2026-24789 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1801 | Network | critical | 10.0 | 1 | Data Breach |
| 1802 | Unpatched Systems (Historical) | critical | 10.0 | 1 | Data Breach |
| 1803 | Unsecured Self-Service Password Reset | critical | 10.0 | 1 | Cyber Espionage |
| 1804 | CVE-2025-27821 (Out-of-bounds write in HDFS native client) | critical | 10.0 | 1 | Vulnerability |
| 1805 | unpatched flaw in a popular file-transfer tool | critical | 10.0 | 1 | ransomware |
| 1806 | CVE-2020-12812 | critical | 10.0 | 1 | Ransomware |
| 1807 | third-party vendor compromises | critical | 10.0 | 1 | Data Breach |
| 1808 | CVE-2023-3519 | critical | 10.0 | 1 | Ransomware |
| 1809 | CVE-2019-5786 (Google Chrome FileReader) | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 1810 | CVE-2026-53921 (OpenWrt DHCPv6 Server) | critical | 10.0 | 1 | Zero-day Exploit |
| 1811 | maritime domain awareness gaps | critical | 10.0 | 1 | espionage |
| 1812 | Cross-Site Scripting (XSS) flaws | critical | 10.0 | 1 | Cyber Espionage |
| 1813 | Compromised Passwords | critical | 10.0 | 1 | Data Breach |
| 1814 | Shadow AI (unauthorized generative AI tools) | critical | 10.0 | 1 | Ransomware |
| 1815 | Poorly secured ATG systems | critical | 10.0 | 1 | Cyberattack |
| 1816 | Remote Control Software Vulnerability | critical | 10.0 | 1 | Phishing Attack |
| 1817 | CVE-2026-4372 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1818 | RxRPC Page-Cache Write | critical | 10.0 | 1 | Local Privilege Escalation (LPE) |
| 1819 | Internal Login | critical | 10.0 | 1 | Data Breach |
| 1820 | Microsoft SharePoint zero-day | critical | 10.0 | 1 | ransomware |
| 1821 | Outsourced IT support vendor | critical | 10.0 | 1 | Social Engineering |
| 1822 | Free-for-Teacher Accounts | critical | 10.0 | 1 | Data Breach |
| 1823 | WebLogic deserialization flaws | critical | 10.0 | 1 | Botnet |
| 1824 | Decentralized App Ecosystem (Shadow IT, Unmanaged SaaS) | critical | 10.0 | 1 | Browser-Based Attack |
| 1825 | Undocumented backdoors in the Go1 quadruped | critical | 10.0 | 1 | Privacy Breach |
| 1826 | Over-reliance on server-side WAFs/IDS for client-side threats | critical | 10.0 | 1 | Data Breach |
| 1827 | Known vulnerability in IT infrastructure | critical | 10.0 | 1 | Data Breach |
| 1828 | Misconfigured AWS Bucket | critical | 10.0 | 1 | Data Exposure |
| 1829 | Trusted third-party SDK distribution (websdk.appsflyer.com) | critical | 10.0 | 1 | Supply-Chain Attack |
| 1830 | Human behavior | critical | 10.0 | 1 | Illegal intrusion |
| 1831 | unknown_vulnerabilities_in_OS/browsers | critical | 10.0 | 1 | data_breach |
| 1832 | Path Traversal Flaw (CabSlip) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1833 | FortiGate firewall VPN authentication misconfiguration, older Claude AI model (Sonnet 4.6) with weaker guardrails | critical | 10.0 | 1 | Ransomware |
| 1834 | Misuse of authorized access to medical records under false pretenses | critical | 10.0 | 1 | Data Breach |
| 1835 | CVE-2026-41940 | critical | 10.0 | 1 | Ransomware |
| 1836 | human error (clicking suspicious links) | critical | 10.0 | 1 | general cybersecurity awareness |
| 1837 | Weak Insider Controls | critical | 10.0 | 1 | Data Breach |
| 1838 | Hijacked maintainer accounts and automated dependency updates | critical | 10.0 | 1 | Supply Chain Attack |
| 1839 | Procedural errors by Special Agent Aaron Spivack; unsecured server in child exploitation forensic lab | critical | 10.0 | 1 | Data Breach |
| 1840 | Unpatched edge devices | critical | 10.0 | 1 | Cyber Espionage |
| 1841 | Third-party breaches | critical | 10.0 | 1 | Supply Chain Attack, Extortion Campaign |
| 1842 | CVE-2018-13379 | critical | 10.0 | 1 | Ransomware |
| 1843 | CrushFTP servers | critical | 10.0 | 1 | Supply Chain Attack |
| 1844 | unmonitored vendor access to sensitive data | critical | 10.0 | 1 | supply chain attack |
| 1845 | publicly available data misrepresented as 'secret' (hallucination exploit) | critical | 10.0 | 1 | cyberespionage |
| 1846 | Unsecured internet-facing devices (used by China-affiliated actors) | critical | 10.0 | 1 | Extortion |
| 1847 | SonicWall SSLVPN (Weak MFA/Access Controls) | critical | 10.0 | 1 | Ransomware |
| 1848 | TP-Link camera flaw | critical | 10.0 | 1 | Zero-day exploit |
| 1849 | Confluence Server Webwork OGNL injection | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1850 | Human Trust (Fake CAPTCHA Social Engineering) | critical | 10.0 | 1 | Social Engineering |
| 1851 | Ivanti products | critical | 10.0 | 1 | ransomware |
| 1852 | Poor Data Residency Enforcement | critical | 10.0 | 1 | Data Breach Risk |
| 1853 | AI safeguard bypass | critical | 10.0 | 1 | Cyber Espionage |
| 1854 | Legitimate utilities repurposed for malicious use (e.g., gpscript.exe) | critical | 10.0 | 1 | Ransomware |
| 1855 | Abandoned Vercel-hosted URL takeover | critical | 10.0 | 1 | Phishing |
| 1856 | CVE-2025-7029 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1857 | Enabled dangerous features (xp_cmdshell, CLR, OLE Automation) | critical | 10.0 | 1 | Ransomware |
| 1858 | CVE-2026-21509 (Microsoft Office OLE flaw) | critical | 10.0 | 1 | Cyberespionage |
| 1859 | CVE-2024-38178 | critical | 10.0 | 1 | Cyber Espionage |
| 1860 | Unpatched vulnerabilities in internet-facing applications | critical | 10.0 | 1 | Data Breach |
| 1861 | Abuse of legitimate software (BitDefender, VLC Media Player, Sangfor) | critical | 10.0 | 1 | Cyber Espionage |
| 1862 | Lack of contractual compliance and oversight, unauthorized offshore access | critical | 10.0 | 1 | Data Breach |
| 1863 | Lack of Password or Encryption | critical | 10.0 | 1 | Data Exposure |
| 1864 | CVE-2023-48788 (Fortinet EMS) | critical | 10.0 | 1 | Ransomware |
| 1865 | CVE-2026-59568, CVE-2026-59564, CVE-2026-59567, CVE-2026-59565 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1866 | Lack of Fragment Inspection in Security Tools | critical | 10.0 | 1 | Prompt Injection |
| 1867 | Weak administrator access controls | critical | 10.0 | 1 | Data Breach |
| 1868 | F5 BIG-IP load balancers | critical | 10.0 | 1 | Reconnaissance |
| 1869 | Coding error in 'DNA Relatives' feature | critical | 10.0 | 1 | Data Breach |
| 1870 | Weak/Reused Passwords (88% of breaches per Verizon DBIR) | critical | 10.0 | 1 | Data Breach |
| 1871 | Irregular software patching | critical | 10.0 | 1 | Ransomware |
| 1872 | CVE-2025-2172 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1873 | Minimal/No Authentication | critical | 10.0 | 1 | Exposure of Vulnerable Systems |
| 1874 | Legitimate Windows driver *truesight.sys* (Adlice Software’s RogueKiller) with IOCTL command abuse | critical | 10.0 | 1 | ransomware |
| 1875 | Security holes in Verizon's systems | critical | 10.0 | 1 | Data Breach |
| 1876 | abuse of legitimate code-signing certificates | critical | 10.0 | 1 | ransomware |
| 1877 | Abuse of finger.exe (TCP port 79), In-memory loading techniques, Reflective DLL injection | critical | 10.0 | 1 | Malware (RAT) / Ransomware |
| 1878 | Unpatched IoMT devices | critical | 10.0 | 1 | Data Breach |
| 1879 | inadequate data loss prevention controls | critical | 10.0 | 1 | ransomware |
| 1880 | CVE-2026-50746 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1881 | Trust in open-source packages | critical | 10.0 | 1 | Supply Chain Attack |
| 1882 | Command-injection flaw in Modal-hosted application | critical | 10.0 | 1 | Zero-day exploitation |
| 1883 | Previously unknown RCE vulnerability in Max Messenger’s media processing engine, existing since the beta phase in early 2025 | critical | 10.0 | 1 | Data Breach |
| 1884 | Insufficient Real-Time Monitoring | critical | 10.0 | 1 | Insider Threat |
| 1885 | Internal System Compromise (mechanism unspecified) | critical | 10.0 | 1 | Data Breach |
| 1886 | Email Spoofing, Unsecured Computer System | critical | 10.0 | 1 | Hacking |
| 1887 | Legacy system integration vulnerabilities during platform consolidation | critical | 10.0 | 1 | Ransomware Attack |
| 1888 | Dormant Service Accounts | critical | 10.0 | 1 | Data Breach |
| 1889 | CVE-2023-46604 (Apache ActiveMQ) | critical | 10.0 | 1 | Ransomware |
| 1890 | CVE-2025-49154 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1891 | Lack of Zero-Trust for Non-Human Identities (AI agents) | critical | 10.0 | 1 | Predictive Analysis |
| 1892 | Technical Debt in Legacy OT Systems (15-20 year lifecycles) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 1893 | Poor IoT device oversight/management | critical | 10.0 | 1 | Ransomware |
| 1894 | Undisclosed Zero-Day in Oracle E-Business Suite | critical | 10.0 | 1 | Data Breach |
| 1895 | Absence of Automated Data Loss Prevention (DLP) Tools | critical | 10.0 | 1 | Data Breach |
| 1896 | Unrestricted Remote Access ('Always-On' Feature) | critical | 10.0 | 1 | Data Breach |
| 1897 | GHSA-vwf4-m7j8-wcjf (CVSS 10.0) | critical | 10.0 | 1 | Zero-Day Exploit |
| 1898 | legacy systems in healthcare and critical infrastructure | critical | 10.0 | 1 | ransomware |
| 1899 | ProxyNotShell (Microsoft Exchange) | critical | 10.0 | 1 | Cyber Espionage |
| 1900 | CVE-2017-17215 (Huawei) | critical | 10.0 | 1 | Botnet |
| 1901 | Information Disclosure Vulnerability | critical | 10.0 | 1 | Information Disclosure |
| 1902 | CVE-2025-61882 (Oracle E-Business Suite BI Publisher Integration Component) | critical | 10.0 | 1 | Data Theft |
| 1903 | CVE-2025-27363 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1904 | public cloud | critical | 10.0 | 1 | ransomware |
| 1905 | CVE-2026-27684 (SQL injection in SAP NetWeaver Feedback Notification) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1906 | Unchecked external input in workflow scripts | critical | 10.0 | 1 | Supply Chain Attack |
| 1907 | Weak administrative oversight, lack of data-protection culture | critical | 10.0 | 1 | Data Leak |
| 1908 | AI Browser Design Flaw (Fragment Inclusion in Context) | critical | 10.0 | 1 | Prompt Injection |
| 1909 | Shared operator accounts | critical | 10.0 | 1 | Cyber Espionage |
| 1910 | Network segmentation flaws or disabled/unmonitored logs | critical | 10.0 | 1 | Data Breach |
| 1911 | Ageing infrastructure, shared IT systems, lack of network segmentation | critical | 10.0 | 1 | Data Breach |
| 1912 | Lack of security monitoring | critical | 10.0 | 1 | Cyberattack |
| 1913 | Unpatched Teams Clients | critical | 10.0 | 1 | Social Engineering |
| 1914 | Vulnerable internet routers | critical | 10.0 | 1 | Cyber Espionage |
| 1915 | Lack of Multi-Factor Authentication (MFA) for high-value targets | critical | 10.0 | 1 | Cyber Theft |
| 1916 | Cross-jurisdictional regulatory gaps | critical | 10.0 | 1 | Cyber-Physical Threat |
| 1917 | CVE-2025-5086 (Deserialization of Untrusted Data) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1918 | CVE-2026-35616 (CWE-284: Improper Access Control) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1919 | Compromised LiteLLM library | critical | 10.0 | 1 | Supply Chain Attack |
| 1920 | CVE-2026-5174 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1921 | Cleo file sharing tool | critical | 10.0 | 1 | Data Breach |
| 1922 | Confused deputy problem in AI systems, failure to distinguish between data and hidden instructions in logs | critical | 10.0 | 1 | AI Agent Manipulation |
| 1923 | NETGEAR vulnerabilities | critical | 10.0 | 1 | Botnet |
| 1924 | Infection via official website | critical | 10.0 | 1 | Ransomware |
| 1925 | CVE-2024-3721 | critical | 10.0 | 1 | Malware |
| 1926 | MOVEit Transfer zero-day (Clop gang, 2023) | critical | 10.0 | 1 | ransomware |
| 1927 | third-party ecosystem vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1928 | Credential Theft via Fake Microsoft 365 Login Page | critical | 10.0 | 1 | Phishing Attack |
| 1929 | Static Authentication Methods (vulnerable to deepfakes) | critical | 10.0 | 1 | Predictive Analysis |
| 1930 | Insider Threat, Social Engineering | critical | 10.0 | 1 | Espionage, Data Breach |
| 1931 | legacy software vulnerabilities | critical | 10.0 | 1 | cyber espionage |
| 1932 | Lack of Data Processing Agreements (DPAs/DSAs) | critical | 10.0 | 1 | Data Privacy Violation |
| 1933 | Lack of User Awareness for Non-Email Threats | critical | 10.0 | 1 | Social Engineering |
| 1934 | Social Engineering (Employee Interaction) | critical | 10.0 | 1 | Ransomware |
| 1935 | Unspecified SQL Server Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1936 | weaknesses in AIS (Automatic Identification System) authentication | critical | 10.0 | 1 | AIS spoofing |
| 1937 | CVE-2026-33032 | critical | 10.0 | 1 | Authentication Bypass |
| 1938 | systemic weaknesses in data protection | critical | 10.0 | 1 | data breach |
| 1939 | CitrixBleed2 (CVE unknown, related to Citrix Netscaler) | critical | 10.0 | 1 | ransomware |
| 1940 | CVE-2025-7026 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1941 | Publicly accessible links to call recordings/transcripts | critical | 10.0 | 1 | Data Breach |
| 1942 | Cleo software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1943 | Non-shard-isolated user directory, unencrypted public chat rooms | critical | 10.0 | 1 | Data Breach |
| 1944 | CVE-2026-33017 (Langflow AI) | critical | 10.0 | 1 | ransomware |
| 1945 | Impersonation of legitimate SDK, hidden credential exfiltration logic | critical | 10.0 | 1 | Supply Chain Attack |
| 1946 | Open Redirect | critical | 10.0 | 1 | Redirect Attack |
| 1947 | Hidden registration form, JSESSIONID manipulation, and lack of server-side token validation | critical | 10.0 | 1 | Privilege Escalation, Remote Code Execution |
| 1948 | Insufficient Training | critical | 10.0 | 1 | Data Breach |
| 1949 | AES-CMAC algorithm flaw | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1950 | Fortinet FortiClient EMS flaws | critical | 10.0 | 1 | ransomware |
| 1951 | outdated property assessment funding | critical | 10.0 | 1 | physical security breach |
| 1952 | CVE-2026-21858 (n8n workflow automation) | critical | 10.0 | 1 | AI-driven cyberattack |
| 1953 | CVE-2025-9528 | critical | 10.0 | 1 | Botnet, DDoS, IoT Exploitation |
| 1954 | CVE-2025-47577 | critical | 10.0 | 1 | Software Vulnerability |
| 1955 | SaaS platforms | critical | 10.0 | 1 | Ransomware |
| 1956 | CVE-2026-21858 (n8n, CVSS 10.0) | critical | 10.0 | 1 | AI-Powered Cyber Attack |
| 1957 | no password protection on critical servers | critical | 10.0 | 1 | data breach |
| 1958 | Unauthenticated file uploads | critical | 10.0 | 1 | Cyberattack |
| 1959 | CVE-2026-6471 (PostgreSQL shared library execution flaw) | critical | 10.0 | 1 | Zero-day exploitation |
| 1960 | Lack of Endpoint Detection and Response (EDR) in Some Systems | critical | 10.0 | 1 | Malware Infection |
| 1961 | Unlimited token allowances | critical | 10.0 | 1 | Security Breach |
| 1962 | Interconnexion non sécurisée entre IT et OT | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1963 | lack of asset visibility | critical | 10.0 | 1 | unauthorized access |
| 1964 | Human Error (Phishing/Vishing) | critical | 10.0 | 1 | Data Breach |
| 1965 | IMSI-capturing | critical | 10.0 | 1 | Surveillance |
| 1966 | Poor Patch Management | critical | 10.0 | 1 | Compliance Failure |
| 1967 | CVE-2026-8206 (CVSS 9.8) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1968 | Tool disparities | critical | 10.0 | 1 | Ransomware Prediction |
| 1969 | subdomain vulnerabilities | critical | 10.0 | 1 | data breach |
| 1970 | Known flaw in a widely used healthcare management platform | critical | 10.0 | 1 | Ransomware |
| 1971 | Undetected network vulnerability | critical | 10.0 | 1 | Data Breach |
| 1972 | compromised laptop (physical or logical access) | critical | 10.0 | 1 | data breach |
| 1973 | Lack of AI Governance | critical | 10.0 | 1 | Insider Threat |
| 1974 | CVE-2021-38450 (Trane Tracer SC - Authenticated RCE, CVSS 9.9) | critical | 10.0 | 1 | Vulnerability Exposure |
| 1975 | weak identity management systems | critical | 10.0 | 1 | cyberespionage |
| 1976 | 161 distinct CVEs in H1 2025 (up from 136 in H1 2024) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1977 | CVE-2026-35194 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1978 | PowerShell script abuse | critical | 10.0 | 1 | spear-phishing |
| 1979 | Cryptographic Implementation Flaws | critical | 10.0 | 1 | Security Vulnerability |
| 1980 | Publicly Accessible Industrial Control Systems | critical | 10.0 | 1 | Ransomware |
| 1981 | Broken Authentication (CWE-287) | critical | 10.0 | 1 | Unauthorized Access |
| 1982 | Lack of anti-jamming measures in ferry's GPS system | critical | 10.0 | 1 | GPS jamming |
| 1983 | unmanaged systems (for data theft and ransomware deployment) | critical | 10.0 | 1 | ransomware |
| 1984 | shadow IT (unapproved third-party tool integrations) | critical | 10.0 | 1 | third-party breach |
| 1985 | Phone data hijacking via malicious vCard | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1986 | Programming Issue | critical | 10.0 | 1 | Data Exposure |
| 1987 | Hardcoded cryptographic keys in Unitree’s G1 humanoid | critical | 10.0 | 1 | Privacy Breach |
| 1988 | Lack of Data Review Process / Gross Negligence | critical | 10.0 | 1 | Data Breach |
| 1989 | CVE-2026-28318 (Uncontrolled Resource Consumption, CWE-400) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 1990 | CVE-2026-21536 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1991 | Unicode Private Use Area characters (0xFE00–0xFE0F, 0xE0100–0xE01EF) | critical | 10.0 | 1 | Supply Chain Attack |
| 1992 | misconfigured multi-factor authentication (MFA) | critical | 10.0 | 1 | ransomware |
| 1993 | CVE-2024-36904 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1994 | CVE-2025-34300 | critical | 10.0 | 1 | Remote Code Execution |
| 1995 | Previously unknown software vulnerability in network infrastructure | critical | 10.0 | 1 | Data Breach |
| 1996 | IT-OT Boundary Erosion | critical | 10.0 | 1 | Cyber Espionage |
| 1997 | Alcatel vulnerabilities | critical | 10.0 | 1 | Botnet |
| 1998 | Unsafe 16-bit key-length narrowing issue | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1999 | Improper handling of configuration objects in the `mergeConfig` function (CVE-2026-25639) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 2000 | Inadequate safeguards for sensitive data | critical | 10.0 | 1 | Data Breach |
| 2001 | Zero-day vulnerability in Microsoft Exchange Server | critical | 10.0 | 1 | Ransomware |
| 2002 | Lack of Basic Cyber Hygiene | critical | 10.0 | 1 | Cyberattack |
| 2003 | Microsoft Exchange vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2004 | Command Injection (QVD-2026-14149) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2005 | Auto-update mechanisms | critical | 10.0 | 1 | Session Hijacking |
| 2006 | Lack of spreadsheet security training, hidden data in Excel files | critical | 10.0 | 1 | Data Breach |
| 2007 | Reduced CISA staffing (from ~2,500 to <900) | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 2008 | Ivanti Endpoint Manager Mobile | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2009 | CVE-2026-25874 (Unsafe deserialization via Python's `pickle.loads()` in LeRobot's gRPC PolicyServer) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2010 | Exposure of GitHub token | critical | 10.0 | 1 | Vulnerability |
| 2011 | Weaknesses in maritime navigation security protocols | critical | 10.0 | 1 | GPS spoofing |
| 2012 | Stolen credentials from 2023 Salesloft Drift breach, weak credential management, lack of MFA enforcement | critical | 10.0 | 1 | Data Breach |
| 2013 | lack of centralized patching for consulting deliverables | critical | 10.0 | 1 | supply chain attack |
| 2014 | Process Drift in Third-Party Service Desk | critical | 10.0 | 1 | Social Engineering |
| 2015 | CVE-2024-8299 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 2016 | Over-Permissive API Access | critical | 10.0 | 1 | Supply Chain Attack |
| 2017 | Undetected intrusion due to oversight lapses | critical | 10.0 | 1 | Data Breach |
| 2018 | CVE-2026-56164 (Missing-Authentication Vulnerability, CWE-306) | critical | 10.0 | 1 | Privilege Escalation |
| 2019 | Cloud Security Gaps | critical | 10.0 | 1 | Cyberattack Surge |
| 2020 | Publicly accessible management interfaces | critical | 10.0 | 1 | Cloud Exploitation Campaign |
| 2021 | CVE-2026-58644 (CWE-502 - Unsafe Deserialization) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2022 | MediaProjection API abuse | critical | 10.0 | 1 | ransomware |
| 2023 | Critical vulnerabilities, unpatched systems, dark web credentials | critical | 10.0 | 1 | Supply Chain Attack |
| 2024 | Human operational error | critical | 10.0 | 1 | GPS spoofing (disputed) |
| 2025 | Type confusion vulnerabilities in Java Card | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2026 | Confluence Server Zero-Day Vulnerability | critical | 10.0 | 1 | Zero-Day Exploit |
| 2027 | Browser session tokens | critical | 10.0 | 1 | Ransomware |
| 2028 | poor cyber defenses in supplier systems | critical | 10.0 | 1 | supply chain attack |
| 2029 | Undisclosed zero-day vulnerability | critical | 10.0 | 1 | Zero-day exploitation |
| 2030 | Insufficient Real-Time Threat Intelligence | critical | 10.0 | 1 | Domain Hijacking |
| 2031 | Lack of Code Integrity Checks | critical | 10.0 | 1 | Supply Chain Attack |
| 2032 | lack of system isolation capabilities | critical | 10.0 | 1 | cyberattack |
| 2033 | End-of-Life (EoL) Hardware with No Security Updates | critical | 10.0 | 1 | Cyber Espionage |
| 2034 | Insecure Protocols (e.g., Telnet) | critical | 10.0 | 1 | Cyber Espionage |
| 2035 | CWE-93 (CRLF Injection) | critical | 10.0 | 1 | Privilege Escalation |
| 2036 | Fortinet CVEs | critical | 10.0 | 1 | Ransomware |
| 2037 | CVE-2026-64849 | critical | 10.0 | 1 | Server-Side Request Forgery (SSRF) |
| 2038 | Kernel driver update | critical | 10.0 | 1 | Software Malfunction |
| 2039 | CVE-2026-69836 (Microsoft Entra ID RCE) | critical | 10.0 | 1 | ransomware |
| 2040 | CVE-2026-5430 | critical | 10.0 | 1 | Authentication Bypass |
| 2041 | CVE-2025-34158 (Improper Input Validation) | critical | 10.0 | 1 | Vulnerability Exposure |
| 2042 | Internet-facing edge devices (40% targeted by China-nexus actors) | critical | 10.0 | 1 | AI-driven cyber threats |
| 2043 | unsecured copper infrastructure | critical | 10.0 | 1 | infrastructure vulnerability |
| 2044 | Unsecured Health Declaration Portal | critical | 10.0 | 1 | Data Breach |
| 2045 | Insufficient Disaster Recovery Plans | critical | 10.0 | 1 | Supply Chain Attack |
| 2046 | Lack of AIS/GPS signal authentication | critical | 10.0 | 1 | GPS spoofing |
| 2047 | Outdated encryption, weak cryptographic practices, poor key management | critical | 10.0 | 1 | Cyber Threat Warning |
| 2048 | CVE-2025-53770 (ToolShell, patch bypass for CVE-2025-49704/CVE-2025-49706) | critical | 10.0 | 1 | Cyber Espionage |
| 2049 | Lack of Anomaly Detection | critical | 10.0 | 1 | Data Breach Risk |
| 2050 | GPS-based navigation and landing systems | critical | 10.0 | 1 | cyber attack |
| 2051 | CVE-2025-61882 (Critical, CVSS 9.8) | critical | 10.0 | 1 | Ransomware |
| 2052 | CVE-2025-64155 (CWE-78: Improper Neutralization of Special Elements used in an OS Command) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2053 | unpatched/end-of-life devices | critical | 10.0 | 1 | unauthorized access |
| 2054 | Legitimate drivers | critical | 10.0 | 1 | Ransomware |
| 2055 | Zero-day vulnerability in Oracle E-Business Suite (advisory issued 2025-10-04) | critical | 10.0 | 1 | Data Breach |
| 2056 | CVE-2026-25108 (OS command injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2057 | PIN phishing via fake dialogs | critical | 10.0 | 1 | Data Breach |
| 2058 | Unpatched Adobe Reader zero-day vulnerability | critical | 10.0 | 1 | Zero-Day Exploit |
| 2059 | CVE-2023-28252 | critical | 10.0 | 1 | Ransomware |
| 2060 | Lack of encryption and authentication in Modbus protocol | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2061 | CVE-2026-69836 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2062 | Remote-file-transfer vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2063 | Lack of encryption, inadequate access controls, no multifactor authentication, insufficient intrusion detection and network monitoring | critical | 10.0 | 1 | Data Breach |
| 2064 | Previously unknown vulnerability in data transfer software | critical | 10.0 | 1 | Data Breach |
| 2065 | Microsoft Phone Link (formerly 'Your Phone') SQLite database access | critical | 10.0 | 1 | Cyberattack |
| 2066 | Vulnerability in the online payment system | critical | 10.0 | 1 | Data Breach |
| 2067 | MOVEit file-transfer software zero-day vulnerability | critical | 10.0 | 1 | Data Breach |
| 2068 | Unpatched vulnerabilities (27%) | critical | 10.0 | 1 | Ransomware |
| 2069 | Overwhelmed network infrastructure, misconfigurations, unused ports | critical | 10.0 | 1 | DDoS |
| 2070 | Overlooked Access Rights | critical | 10.0 | 1 | Data Breach |
| 2071 | Cloud management tools | critical | 10.0 | 1 | Ransomware |
| 2072 | CVE-2024-8300 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 2073 | lack of actionable alerting | critical | 10.0 | 1 | ransomware |
| 2074 | preventable software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2075 | Alta Payment Portal | critical | 10.0 | 1 | Data Breach |
| 2076 | Zero-day vulnerability in a third-party application (unspecified) | critical | 10.0 | 1 | Ransomware Attack |
| 2077 | Poor Access Controls for Sensitive Data | critical | 10.0 | 1 | Data Breach |
| 2078 | CVE-2025-36535 (Missing Authentication in MB-Gateway Devices) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2079 | Active Directory vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2080 | CVE-2025-55182 (CVSS 10.0) | critical | 10.0 | 1 | worm-driven campaign |
| 2081 | Incorrect host/guest network separation (allowed privilege escalation from guest to host) | critical | 10.0 | 1 | Ransomware |
| 2082 | CVE-2026-25084 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2083 | Cellebrite Software Exploitation | critical | 10.0 | 1 | State-Backed Surveillance & Hacking |
| 2084 | lack of behavioral monitoring | critical | 10.0 | 1 | data_breach |
| 2085 | unprepared incident response | critical | 10.0 | 1 | ransomware |
| 2086 | CVE-2026-4670 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2087 | Race condition in XFS filesystem’s copy-on-write (CoW) path (CVE-2026-64600) | critical | 10.0 | 1 | Privilege Escalation |
| 2088 | Insufficient Employee Training on Vishing | critical | 10.0 | 1 | Data Breach |
| 2089 | Human Vulnerability (Social Engineering via Impersonation) | critical | 10.0 | 1 | Cyber Attack |
| 2090 | CVE-2026-XXXXX (PolyShell - unauthenticated arbitrary file upload via REST API) | critical | 10.0 | 1 | Payment Skimmer Attack |
| 2091 | Insufficient Authentication and Verification Procedures | critical | 10.0 | 1 | Financial Fraud |
| 2092 | Fragmented Cybersecurity Governance (no common procedures) | critical | 10.0 | 1 | Ransomware |
| 2093 | Mitsubishi Electric vulnerabilities | critical | 10.0 | 1 | Botnet |
| 2094 | Dangling DNS records | critical | 10.0 | 1 | Subdomain Hijacking |
| 2095 | CVE-2025-22226 | critical | 10.0 | 1 | Ransomware |
| 2096 | BYOD Environments | critical | 10.0 | 1 | Data Theft Extortion |
| 2097 | Unauthorized access to cloud servers | critical | 10.0 | 1 | Data Breach |
| 2098 | compromised WordPress sites | critical | 10.0 | 1 | malware |
| 2099 | Unprotected Windows Exchange servers, Unencrypted data transfers, Lack of network segmentation, Outdated infrastructure, Unrestricted third-party access | critical | 10.0 | 1 | Cyberattack, Data Breach, Ransomware |
| 2100 | CVE-2026-44772 (SAP Commerce Cloud Data Hub Adapter) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2101 | Previously undetected vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 2102 | Insecure SOHO routers with default or weak configurations | critical | 10.0 | 1 | Espionage |
| 2103 | Geopolitical protections for cybercriminals | critical | 10.0 | 1 | Ransomware |
| 2104 | limited transparency in global supply chains | critical | 10.0 | 1 | supply chain attack |
| 2105 | Virtual Office portal public access | critical | 10.0 | 1 | ransomware |
| 2106 | leaked credentials or hacked WordPress websites | critical | 10.0 | 1 | malware |
| 2107 | CVE-2026-21643 | critical | 10.0 | 1 | SQL Injection |
| 2108 | supply chain trust abuse | critical | 10.0 | 1 | supply chain attack |
| 2109 | BACnet/Modbus Protocol Flaws (No Encryption/Authentication) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 2110 | legitimate platform abuse (e.g., Google Calendar, Azure domains) | critical | 10.0 | 1 | ransomware |
| 2111 | Unknown (potentially misconfigurations or zero-day flaws) | critical | 10.0 | 1 | Data Breach |
| 2112 | Unsupported Firmware/OS (EOL Systems) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 2113 | Expiration of State and Local Cybersecurity Grant Program | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 2114 | Exposed management ports, weak authentication | critical | 10.0 | 1 | Cyber Attack |
| 2115 | CVE-2017-7921 (Hikvision - authentication bypass) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 2116 | Lack of runtime security controls for AI agents; unmonitored agent deployments; dynamic decision-making based on external inputs | critical | 10.0 | 1 | AI Agent Compromise |
| 2117 | Stale Identity Tokens | critical | 10.0 | 1 | Data Breach |
| 2118 | Fragmented security in third-party hardware | critical | 10.0 | 1 | Privacy Breach |
| 2119 | CVE-2025-10035 (Critical, CVSS 10.0) in Fortra GoAnywhere MFT | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2120 | Technical know-how gap in solvent extraction | critical | 10.0 | 1 | Geopolitical Risk |
| 2121 | CVE-2025-27920 (directory traversal in Output Messenger) | critical | 10.0 | 1 | cyberespionage |
| 2122 | Inadequately tested code in Token Bridge smart contracts, lack of secure coding practices, and absence of automated fraud monitoring | critical | 10.0 | 1 | Data Breach, Cryptocurrency Theft |
| 2123 | Weak or Outdated Cryptographic Standards | critical | 10.0 | 1 | Emerging Threat |
| 2124 | Insecure Database Configuration | critical | 10.0 | 1 | Data Exposure |
| 2125 | Ivanti Policy Secure | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2126 | On Device Fraud (ODF) techniques | critical | 10.0 | 1 | Malware |
| 2127 | Poor Training on Data Protection Protocols | critical | 10.0 | 1 | Data Breach |
| 2128 | NtQuerySystemInformation abuse (SystemCodeFlowTransition parameter) | critical | 10.0 | 1 | Supply Chain Attack |
| 2129 | Unsecured Network Servers | critical | 10.0 | 1 | Cybersecurity Incident |
| 2130 | weak backup protection (backups were deleted by attacker) | critical | 10.0 | 1 | ransomware |
| 2131 | CVE-2026-42880 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2132 | Inadequate Data Redaction in Spreadsheets | critical | 10.0 | 1 | Data Breach |
| 2133 | CVE-2026-31694 (Heap Overflow in FUSE Subsystem) | critical | 10.0 | 1 | Privilege Escalation |
| 2134 | External content blocking bypass via CSS var() manipulation | critical | 10.0 | 1 | SQL Injection |
| 2135 | AI API key misuse | critical | 10.0 | 1 | AI-driven cyberattack |
| 2136 | Credential harvesting via malicious links/impersonation | critical | 10.0 | 1 | Cyber Espionage |
| 2137 | BlueKeep flaw | critical | 10.0 | 1 | Exposed Servers |
| 2138 | Poorly protected and vulnerable government websites | critical | 10.0 | 1 | Cyberattack, Website Defacement, Data Compromise |
| 2139 | API Key Exposure | critical | 10.0 | 1 | Supply Chain Attack |
| 2140 | Funding Pressures in State Schools | critical | 10.0 | 1 | Data Breach |
| 2141 | Poorly Secured ICS Components (PLCs, SCADA, HMIs, Industrial IoTs) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 2142 | Poorly Secured OT Systems (e.g., MV Dali electrical blackout) | critical | 10.0 | 1 | Ransomware |
| 2143 | CVE-2026-40701 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2144 | CVE-2026-31694 (FUSE directory entry caching flaw) | critical | 10.0 | 1 | Privilege Escalation |
| 2145 | AI Model Security Controls (e.g., Claude Opus) | critical | 10.0 | 1 | Automated Cyberattack Tool Development |
| 2146 | Misconfigured MongoDB databases (lack of authentication, outdated versions) | critical | 10.0 | 1 | Ransomware |
| 2147 | Insufficient access controls in multi-tenant environment | critical | 10.0 | 1 | Data Breach |
| 2148 | Inconsistent AI Safety Controls Across Languages | critical | 10.0 | 1 | Influence Operation |
| 2149 | Hardcoded Credentials in Binaries | critical | 10.0 | 1 | Supply Chain Attack |
| 2150 | Human Error (Support Staff Tricked via Impersonation) | critical | 10.0 | 1 | Data Breach |
| 2151 | Exposed Web-Accessible Operational Technology (OT) System | critical | 10.0 | 1 | Cyberattack |
| 2152 | User Information Exposure | critical | 10.0 | 1 | Data Breach |
| 2153 | Abstract Threat Perception | critical | 10.0 | 1 | Data Breach |
| 2154 | CVE-2025-4427 | critical | 10.0 | 1 | Cyber Espionage |
| 2155 | Previously unknown software flaw (zero-day) | critical | 10.0 | 1 | Cyber Espionage |
| 2156 | CVE-2021-35587 | critical | 10.0 | 1 | Data Breach |
| 2157 | Unpatched APIs | critical | 10.0 | 1 | Cyberattack Surge |
| 2158 | Lack of Segmentation | critical | 10.0 | 1 | Data Exposure |
| 2159 | CVE-2025-32434 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2160 | Wide Attack Surfaces (Retail: staff, suppliers, IT systems) | critical | 10.0 | 1 | Ransomware |
| 2161 | Outdated Android versions | critical | 10.0 | 1 | Malware |
| 2162 | Fortinet FortiGate appliances | critical | 10.0 | 1 | AI-driven cyberattack tool |
| 2163 | exploitation of maritime regulatory gaps | critical | 10.0 | 1 | AIS spoofing |
| 2164 | third-party services and integrations | critical | 10.0 | 1 | ransomware |
| 2165 | Unauthorized data transfer to private cloud storage | critical | 10.0 | 1 | Data Breach |
| 2166 | ADRecon for Active Directory mapping | critical | 10.0 | 1 | ransomware |
| 2167 | VMware Fusion root access bug | critical | 10.0 | 1 | Zero-day Exploit |
| 2168 | Exposed PLC interfaces, lack of OT security staff, insufficient budgets for robust defenses | critical | 10.0 | 1 | Cyberattack on OT Systems |
| 2169 | CVE-2026-16723 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2170 | CVE-2025-34152 | critical | 10.0 | 1 | Botnet |
| 2171 | Compromised IoT devices and routers, primarily Android TVs | critical | 10.0 | 1 | DDoS |
| 2172 | CVE-2026-3564 (CWE-347: Improper Verification of Cryptographic Signature) | critical | 10.0 | 1 | Cryptographic Vulnerability |
| 2173 | CVE-2026-89026 (CWE-321: Use of Hard-coded Cryptographic Key) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2174 | Fortra GoAnywhere MFT flaws | critical | 10.0 | 1 | Ransomware |
| 2175 | CWE-285 (Polkit Authorization Bypass) | critical | 10.0 | 1 | Privilege Escalation |
| 2176 | Opportunistic targeting | critical | 10.0 | 1 | Data Breach |
| 2177 | Malicious APKs | critical | 10.0 | 1 | Cryptocurrency Scam |
| 2178 | human vulnerabilities (vishing, native-language social engineering) | critical | 10.0 | 1 | ransomware |
| 2179 | Palo Alto Networks products | critical | 10.0 | 1 | ransomware |
| 2180 | Previously unknown vulnerability in file transfer software | critical | 10.0 | 1 | Data Breach |
| 2181 | publicly exposed personal data (e.g., YouTube videos) | critical | 10.0 | 1 | cyber espionage |
| 2182 | Tenda vulnerabilities | critical | 10.0 | 1 | Botnet |
| 2183 | Known vulnerability in remote-access software, lack of multi-factor authentication (MFA) | critical | 10.0 | 1 | Ransomware |
| 2184 | Human trust in perceived secure platforms | critical | 10.0 | 1 | Social Engineering |
| 2185 | Hardcoded tokens in code repositories | critical | 10.0 | 1 | AI-driven cyberattack |
| 2186 | AnyDesk Remote Access Application | critical | 10.0 | 1 | Data Exfiltration |
| 2187 | Entra ID application registration secrets | critical | 10.0 | 1 | cyberespionage |
| 2188 | Weak password (no MFA) on internet-facing system | critical | 10.0 | 1 | Ransomware Attack |
| 2189 | Kubernetes vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2190 | StyleSmuggler (unauthenticated RCE) | critical | 10.0 | 1 | Zero-Day Exploit |
| 2191 | Misconfigured 1C:Enterprise clusters | critical | 10.0 | 1 | Ransomware |
| 2192 | CVE-2026-31431 (Incorrect resource transfer between spheres, CWE-699) | critical | 10.0 | 1 | Privilege Escalation |
| 2193 | Salesforce OAuth Misconfiguration (via Vishing) | critical | 10.0 | 1 | Data Breach |
| 2194 | Weak or default credentials ('Password123', 'Austal123') purchased on the dark web | critical | 10.0 | 1 | ransomware |
| 2195 | CVE-2026-32194 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2196 | CVE-2026-1995 (Improper file permission handling in id_service.exe) | critical | 10.0 | 1 | Privilege Escalation |
| 2197 | Outdated Security Software | critical | 10.0 | 1 | Awareness Campaign |
| 2198 | Stolen Credentials/API Tokens | critical | 10.0 | 1 | Data Breach |
| 2199 | Weakness in mobile payment verification system (KT) | critical | 10.0 | 1 | Data Breach |
| 2200 | underwater sensor network vulnerabilities | critical | 10.0 | 1 | espionage |
| 2201 | Improper security configurations in Windows Named Pipe implementation within the Acer Control Center Service (ACCSvc.exe) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2202 | LLM scope violation (CVE-2025-32711) | critical | 10.0 | 1 | Data Breach Vulnerability |
| 2203 | Shadow AI | critical | 10.0 | 1 | Data Breach |
| 2204 | CVE-2020-35730 | critical | 10.0 | 1 | Cyberespionage |
| 2205 | Security gaps in industrial networks | critical | 10.0 | 1 | Cyber Espionage |
| 2206 | Exposed industrial control ports (TCP/44818, TCP/2222, TCP/502, TCP/22) | critical | 10.0 | 1 | Cyber Espionage |
| 2207 | Inadequate risk assessments, weak vulnerability and patch management, poor access controls, incomplete asset inventory | critical | 10.0 | 1 | Ransomware |
| 2208 | CVE-2024-21887 (Ivanti Connect Secure) | critical | 10.0 | 1 | ransomware |
| 2209 | Four zero-days | critical | 10.0 | 1 | Exploit Kit / Cyber Espionage |
| 2210 | Unpatched vulnerability in the email system | critical | 10.0 | 1 | Ransomware |
| 2211 | Kerberoasting in Active Directory | critical | 10.0 | 1 | ransomware |
| 2212 | Dirty Frag (CVE-2026-31431) | critical | 10.0 | 1 | Privilege Escalation |
| 2213 | Authentication bypasses | critical | 10.0 | 1 | Cyber Attack |
| 2214 | Log4Shell vulnerability in an unpatched VMware Horizon server | critical | 10.0 | 1 | Hacking |
| 2215 | MiniPlasma (Windows zero-day) | critical | 10.0 | 1 | Zero-day Exploit |
| 2216 | Misconfigured APN allowing client-to-client communication, default admin credentials on WAGO PFC200 controller, internet-exposed VPN without MFA, lack of security measures for cellular router management interface | critical | 10.0 | 1 | Cyberattack |
| 2217 | Unpatched firmware | critical | 10.0 | 1 | Botnet |
| 2218 | CVE-2025-68613 | critical | 10.0 | 1 | Botnet Campaign |
| 2219 | CVE-2024-37079 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2220 | CVE-2026-44773 (SAP NetWeaver ABAP) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2221 | Missing Alerts | critical | 10.0 | 1 | Data Exposure |
| 2222 | Data Scraping Vulnerability | critical | 10.0 | 1 | Data Breach |
| 2223 | CVE-2026-85889 (Missing Authentication Check - CWE-306) | critical | 10.0 | 1 | Privilege Escalation |
| 2224 | Newly discovered vulnerability | critical | 10.0 | 1 | Ransomware |
| 2225 | Lack of IT Oversight | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 2226 | Human error (opening malicious email attachment) | critical | 10.0 | 1 | Phishing Attack |
| 2227 | Unspecified Cisco ASA Vulnerabilities (ArcaneDoor Campaign) | critical | 10.0 | 1 | Espionage |
| 2228 | Lack of Employee Cybersecurity Training | critical | 10.0 | 1 | Ransomware |
| 2229 | Insufficient endpoint detection and response (EDR) | critical | 10.0 | 1 | Ransomware |
| 2230 | CVE-2025-32975 | critical | 10.0 | 1 | Authentication Bypass |
| 2231 | Microsoft Exchange Server vulnerabilities (e.g., ProxyLogon) | critical | 10.0 | 1 | Cyber Espionage |
| 2232 | CVE-2025-29927 (React2Shell) | critical | 10.0 | 1 | Cloud Misconfiguration Exploitation |
| 2233 | Implicit TLS | critical | 10.0 | 1 | Cross-protocol Application Layer Desynchronization |
| 2234 | AI-Enabled Attacks (industrial scale) | critical | 10.0 | 1 | Cyberattack |
| 2235 | Exposed remote-access services | critical | 10.0 | 1 | Botnet |
| 2236 | Outdated EnCase driver (EnPortv.sys) with revoked certificate, Windows signature validation loophole for pre-2015 certificates | critical | 10.0 | 1 | BYOVD (Bring Your Own Vulnerable Driver) |
| 2237 | CVE-2025-49156 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2238 | Inadequate input validation and output encoding in Jira’s custom priority settings | critical | 10.0 | 1 | Stored Cross-Site Scripting (XSS) |
| 2239 | CVE-2026-49975 (HTTP/2 Bomb) | critical | 10.0 | 1 | Denial of Service (DoS) |
| 2240 | Non-password-protected database | critical | 10.0 | 1 | Data Breach |
| 2241 | CVE-2025-47164 (Microsoft Office Use-After-Free) | critical | 10.0 | 1 | Patch Release |
| 2242 | CVE-2026-42945 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2243 | Critical RCE flaw in Apache Tomcat | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2244 | Poor OAuth Protections | critical | 10.0 | 1 | Data Breach |
| 2245 | CVE-2025-25181 | critical | 10.0 | 1 | Security Breach |
| 2246 | CVE-2026-54402 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2247 | disabled antivirus processes | critical | 10.0 | 1 | ransomware |
| 2248 | Employee credentials via spoofed websites | critical | 10.0 | 1 | Cryptocurrency Theft, Phishing, Identity Theft |
| 2249 | Trello | critical | 10.0 | 1 | Data Leak |
| 2250 | Bun runtime environment detection | critical | 10.0 | 1 | supply chain attack |
| 2251 | SonicWall VPN flaws | critical | 10.0 | 1 | ransomware |
| 2252 | Compromised credentials, unsegmented networks, unlogged firewall activity, administrative credentials stored in plain text, insecure remote access tools | critical | 10.0 | 1 | Data Breach, Potential Ransomware |
| 2253 | lack of 2FA for publisher accounts | critical | 10.0 | 1 | supply chain attack |
| 2254 | Absence of Multifactor Authentication | critical | 10.0 | 1 | Ransomware |
| 2255 | Local privilege escalation | critical | 10.0 | 1 | Exploit Kit / Cyber Espionage |
| 2256 | Kubernetes misconfigurations | critical | 10.0 | 1 | Botnet |
| 2257 | Inadequate identity verification processes | critical | 10.0 | 1 | Espionage |
| 2258 | Race Conditions in Object Destruction | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 2259 | Microsoft Artifact Signing service abuse | critical | 10.0 | 1 | Cybercrime Operation Disruption |
| 2260 | Trust in fraudulent bank certificates | critical | 10.0 | 1 | Identity Fraud |
| 2261 | Malicious macros in a document titled 'Act.doc' | critical | 10.0 | 1 | Cyberattack |
| 2262 | Social Engineering, Excessive Permissions | critical | 10.0 | 1 | Data Breach, Extortion, Harassment |
| 2263 | Steganography | critical | 10.0 | 1 | Malware Infection |
| 2264 | Undisclosed BIG-IP Vulnerabilities (under investigation) | critical | 10.0 | 1 | Supply Chain Attack |
| 2265 | Malware in plug-ins | critical | 10.0 | 1 | Data Privacy and Cybersecurity Advisory |
| 2266 | Impersonation of a colleague | critical | 10.0 | 1 | Cyberattack |
| 2267 | weaknesses in distributed enforcement synchronization | critical | 10.0 | 1 | data breach |
| 2268 | Typosquatted dependency (easy-day-js) with weaponized postinstall hook | critical | 10.0 | 1 | Supply Chain Attack |
| 2269 | Weaknesses and biases in AI models | critical | 10.0 | 1 | Red-Teaming Event |
| 2270 | Improper handling of the `--exec` flag in `git rebase` during 'Rebase before merging' operations | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2271 | SCADA system vulnerabilities | critical | 10.0 | 1 | DDoS |
| 2272 | operational lapses in rule propagation | critical | 10.0 | 1 | data breach |
| 2273 | Supply Chain Weakness | critical | 10.0 | 1 | Supply Chain Attack |
| 2274 | WhatsApp Artifact Exfiltration | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 2275 | inadequate least-privilege access controls | critical | 10.0 | 1 | cyberespionage |
| 2276 | Unpatched vulnerability in TP-Link Archer routers | critical | 10.0 | 1 | Botnet |
| 2277 | Inadequate privileged access management | critical | 10.0 | 1 | Ransomware |
| 2278 | Default public location sharing settings in fitness app | critical | 10.0 | 1 | Data Exposure |
| 2279 | CVE-2026-20963 (Microsoft SharePoint Server) | critical | 10.0 | 1 | ransomware |
| 2280 | 27-year-old OpenBSD vulnerability | critical | 10.0 | 1 | espionage |
| 2281 | Human Vulnerability (Insider Threat) | critical | 10.0 | 1 | Insider Threat (Attempted) |
| 2282 | MOVEit file transfer software zero-day vulnerability | critical | 10.0 | 1 | Ransomware |
| 2283 | Unsecured cloud environment, lack of proper oversight | critical | 10.0 | 1 | Data Breach |
| 2284 | GitHub Actions workflow vulnerability allowing malicious releases with provenance attestations | critical | 10.0 | 1 | Supply-Chain Attack |
| 2285 | Unpatched vulnerability in the network defenses | critical | 10.0 | 1 | Ransomware |
| 2286 | Persistent IT/OT silos | critical | 10.0 | 1 | Cyber Espionage |
| 2287 | Inadequate Backup Protection | critical | 10.0 | 1 | Ransomware Attack |
| 2288 | SonicWall SSL VPN Vulnerability (Credentials in Backup Files) | critical | 10.0 | 1 | Unauthorized Access |
| 2289 | SAP Netweaver (specific details undisclosed) | critical | 10.0 | 1 | Cyberattack |
| 2290 | OAuth vulnerability | critical | 10.0 | 1 | Exploit |
| 2291 | NVIDIA NeMo Framework Vulnerabilities | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2292 | Outdated Factory Digital Systems | critical | 10.0 | 1 | Cyberattack Surge |
| 2293 | CVE-2024-11859 | critical | 10.0 | 1 | Malware Delivery |
| 2294 | CVE-2024-27199 (JetBrains TeamCity) | critical | 10.0 | 1 | ransomware |
| 2295 | Unsecured Email Channels | critical | 10.0 | 1 | Data Breach (General Discussion) |
| 2296 | Compliance Blind Spots in Cross-Border AI Data Flows | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 2297 | Unpatched software, firmware, and operating systems | critical | 10.0 | 1 | Ransomware |
| 2298 | CVE-2025-46811 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2299 | Weak vendor compliance enforcement | critical | 10.0 | 1 | Ransomware |
| 2300 | Fortinet security devices | critical | 10.0 | 1 | Cyberespionage |
| 2301 | Security protocol bypass, weak access controls, anti-virus circumvention, secret key exposure in source code | critical | 10.0 | 1 | Insider Threat / AI Exploitation |
| 2302 | external-facing systems vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2303 | Schneider Electric safety equipment | critical | 10.0 | 1 | Cyberattack |
| 2304 | Lack of In-House Cybersecurity Expertise (17% of shipyards) | critical | 10.0 | 1 | Ransomware |
| 2305 | Trust in open-source maintainers, Fake meeting infrastructure | critical | 10.0 | 1 | Supply Chain Attack |
| 2306 | CWE-426 (Untrusted APT Source Path) | critical | 10.0 | 1 | Privilege Escalation |
| 2307 | Lack of access controls on an API used in customer onboarding | critical | 10.0 | 1 | Data Breach |
| 2308 | Insufficient Code Review for Open-Source Dependencies | critical | 10.0 | 1 | Supply Chain Attack |
| 2309 | CVE-2025-20281 | critical | 10.0 | 1 | Remote Code Execution |
| 2310 | Human trust exploitation | critical | 10.0 | 1 | Data Breach |
| 2311 | 23 exploits across five attack chains (iOS 13-17.2.1) | critical | 10.0 | 1 | Espionage |
| 2312 | Lack of Content Security Policy (CSP) enforcement | critical | 10.0 | 1 | Data Breach |
| 2313 | Vulnerabilities in SonicWall, Veeam, and Cisco products | critical | 10.0 | 1 | Ransomware |
| 2314 | Lack of adequate security measures for USIM data (SK Telecom) | critical | 10.0 | 1 | Data Breach |
| 2315 | Fortinet Fortigate | critical | 10.0 | 1 | Supply Chain Attack |
| 2316 | Driver Vulnerability (eskle.sys for Anti-AV Bypass) | critical | 10.0 | 1 | Social Engineering |
| 2317 | CVE-2024-57727 (SimpleHelp remote code execution) | critical | 10.0 | 1 | ransomware |
| 2318 | Content management system vulnerability | critical | 10.0 | 1 | Data Breach |
| 2319 | Limited staffing | critical | 10.0 | 1 | Cyberattack |
| 2320 | CVE-2019-17571 (Apache Log4j 1.2 deserialization issue) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2321 | Non-public information disclosure | critical | 10.0 | 1 | Bribery and Fraud |
| 2322 | Azure RBAC Misconfiguration | critical | 10.0 | 1 | Data Exfiltration |
| 2323 | CVE-2026-44963 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2324 | Zero-day vulnerability in Oracle E-Business Suite (EBS) financial application | critical | 10.0 | 1 | Data Breach |
| 2325 | Unauthorized system access via help desk | critical | 10.0 | 1 | Ransomware |
| 2326 | Faulty access control mechanisms in Balancer's DeFi protocol | critical | 10.0 | 1 | Cryptocurrency Theft |
| 2327 | Misconfigured document delivery platform | critical | 10.0 | 1 | Data Breach |
| 2328 | Failure to Implement Security Recommendations | critical | 10.0 | 1 | Data Breach |
| 2329 | Credential leaks (reused passwords) | critical | 10.0 | 1 | Extortion |
| 2330 | external-facing RDP/VPN misconfigurations | critical | 10.0 | 1 | ransomware |
| 2331 | CVE-2026-27771 | critical | 10.0 | 1 | Data Exposure |
| 2332 | Dependency confusion / Typosquatting | critical | 10.0 | 1 | Supply Chain Attack |
| 2333 | CVE-2026-56155 | critical | 10.0 | 1 | Zero-day exploit |
| 2334 | Vulnerabilities present during high-risk phases like satellite deployment, where telemetry, software loadouts, and encryption keys are most exposed. | critical | 10.0 | 1 | Cyber Espionage |
| 2335 | Legacy Firewall Deployments (single point of failure for ecosystems) | critical | 10.0 | 1 | Predictive Analysis |
| 2336 | insufficient encryption | critical | 10.0 | 1 | data breach |
| 2337 | Command Execution as Root | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2338 | CVE-2026-20266 (CWE-78) | critical | 10.0 | 1 | Vulnerability |
| 2339 | Service Accounts with Non-Expiring Passwords & Excessive Permissions | critical | 10.0 | 1 | Data Breach |
| 2340 | Stale Accounts (Former Employees with Retained Access) | critical | 10.0 | 1 | Data Breach |
| 2341 | Adobe Magento e-commerce platform | critical | 10.0 | 1 | Magecart Attack |
| 2342 | Weak Entra ID Configurations (e.g., external access policies) | critical | 10.0 | 1 | Social Engineering |
| 2343 | Previously unknown vulnerability in firewall software | critical | 10.0 | 1 | Ransomware Attack |
| 2344 | Technical Security Configuration Issue | critical | 10.0 | 1 | Data Breach |
| 2345 | Invalid cast vulnerability in .NET Framework serialization processes | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2346 | Payment system weaknesses | critical | 10.0 | 1 | Data Breach |
| 2347 | Apache HiveServer2 default 'NONE' authentication mode | critical | 10.0 | 1 | Cyber Intrusion |
| 2348 | Unknown vulnerabilities in operating systems and browsers | critical | 10.0 | 1 | Ransomware |
| 2349 | Social Engineering (Impersonation of coworkers/IT support) | critical | 10.0 | 1 | Extortion |
| 2350 | Session Hijacking via Stolen Cookies | critical | 10.0 | 1 | Espionage |
| 2351 | SQL injection vulnerability in Navy-SWM database | critical | 10.0 | 1 | data breach |
| 2352 | Weaknesses in AI systems | critical | 10.0 | 1 | AI-driven cyber attack |
| 2353 | CVE-2025-49155 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2354 | Cisco Catalyst SD-WAN vulnerability | critical | 10.0 | 1 | Zero-day Exploit |
| 2355 | AI-generated phishing | critical | 10.0 | 1 | credential theft |
| 2356 | Weak Signature Validation | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2357 | Proactive SIM functionality (RUN AT commands, AT command interface) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2358 | CVE-2026-19632 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2359 | CVE-2025-61882 (Critical Authentication Bypass in Oracle E-Business Suite) | critical | 10.0 | 1 | Data Breach |
| 2360 | Pre-authentication information disclosure in FlexPLM WSDL endpoint | critical | 10.0 | 1 | Ransomware, Data Theft |
| 2361 | Absence of Subresource Integrity (SRI) checks | critical | 10.0 | 1 | Data Breach |
| 2362 | Lack of Zero-Trust Architecture | critical | 10.0 | 1 | Cyber Espionage |
| 2363 | Systemic weaknesses in U.S. federal cybersecurity posture | critical | 10.0 | 1 | Cyber Espionage |
| 2364 | CVE-2026-8053 | critical | 10.0 | 1 | Vulnerability |
| 2365 | CVE-2026-15748 (Improper file-upload handling in Forminator Forms WordPress plugin) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2366 | Fragmented accountability among OEMs, MNOs, and satellite operators | critical | 10.0 | 1 | Cyber-Physical Threat |
| 2367 | PrinterBug | critical | 10.0 | 1 | Ransomware |
| 2368 | CVE-2023-4966 (Citrix Bleed) | critical | 10.0 | 1 | Ransomware |
| 2369 | Unsecured databases exposed to the public internet | critical | 10.0 | 1 | Ransomware/Extortion |
| 2370 | PTC Windchill vulnerability | critical | 10.0 | 1 | Ransomware |
| 2371 | CVE-2026-35029 | critical | 10.0 | 1 | Authorization Vulnerability Exploitation |
| 2372 | CVE-2026-91843 | critical | 10.0 | 1 | Buffer Overflow |
| 2373 | Third-Party Integration Vulnerabilities (Salesforce-connected apps) | critical | 10.0 | 1 | Data Breach |
| 2374 | Adobe Flash Vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2375 | Compromised software supply chain | critical | 10.0 | 1 | Supply Chain Attack |
| 2376 | Default-enabled remote user account, unprotected superuser accounts, user enumeration, and lack of password protection | critical | 10.0 | 1 | Misconfiguration |
| 2377 | Publicly exposed cloud buckets with critical vulnerabilities and highly privileged data | critical | 10.0 | 1 | Data Exposure |
| 2378 | Improper access controls and lack of technical safeguards | critical | 10.0 | 1 | Data Breach |
| 2379 | Weak configurations and unsecured devices left exposed online | critical | 10.0 | 1 | Cyberattack |
| 2380 | Weak Data Integrity Checks | critical | 10.0 | 1 | Supply Chain Attack |
| 2381 | Lack of modern defenses | critical | 10.0 | 1 | GPS spoofing |
| 2382 | Improper Use of Collaboration Tools (WhatsApp, Microsoft Forms) | critical | 10.0 | 1 | Data Breach |
| 2383 | Weak password policy (single compromised password) | critical | 10.0 | 1 | Ransomware |
| 2384 | Absence of MFA on Congruity’s virtual machines | critical | 10.0 | 1 | Ransomware |
| 2385 | Lack of Real-Time Threat Detection | critical | 10.0 | 1 | Third-Party Breach |
| 2386 | Zero-day vulnerabilities (42% weaponized before public disclosure) | critical | 10.0 | 1 | AI-driven cyber threats |
| 2387 | Unknown flaw in Oracle E-Business Suite (EBS) | critical | 10.0 | 1 | Data Breach |
| 2388 | Identity and Access Control Weaknesses | critical | 10.0 | 1 | Data Breach |
| 2389 | Exposure management adoption | critical | 10.0 | 1 | Ransomware Prediction |
| 2390 | Supply chain compromise of open-source security tool | critical | 10.0 | 1 | Supply Chain Attack |
| 2391 | Lack of Automated PII Detection | critical | 10.0 | 1 | Data Leak |
| 2392 | unsecured internet-facing devices | critical | 10.0 | 1 | espionage |
| 2393 | Chrome zero-day (fifth in 2026) | critical | 10.0 | 1 | ransomware |
| 2394 | Weaknesses in internet-exposed control systems and utility software | critical | 10.0 | 1 | Cyberattack |
| 2395 | Compromised OAuth token for a Heroku machine account | critical | 10.0 | 1 | Security Breach |
| 2396 | SonicWall SSL VPN endpoints | critical | 10.0 | 1 | Ransomware |
| 2397 | Supply chain compromise (malicious Axios update) | critical | 10.0 | 1 | Data Breach |
| 2398 | Cyber-Illiterate Student Population | critical | 10.0 | 1 | Data Breach |
| 2399 | Vulnerabilities in MOVEit software | critical | 10.0 | 1 | Cyberattack |
| 2400 | CVE-2026-49103 | critical | 10.0 | 1 | XSS |
| 2401 | Docker API misconfigurations | critical | 10.0 | 1 | Botnet |
| 2402 | Public-facing nodes and databases with inadequate security controls | critical | 10.0 | 1 | Research Study |
| 2403 | CVE-2023-3595 | critical | 10.0 | 1 | Cyber Espionage |
| 2404 | CVE-2025-48595 (CWE-190 - Integer Overflow) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2405 | Copilot’s handling of contextual documents and LLM parsing of hidden/invisible text | critical | 10.0 | 1 | AI Worm / Prompt Injection |
| 2406 | Compromised Okta SSO account | critical | 10.0 | 1 | Data Breach |
| 2407 | weak supply chain links | critical | 10.0 | 1 | ransomware |
| 2408 | Lack of 'Two Pairs of Eyes' Review (Pre-November 2021) | critical | 10.0 | 1 | Data Breach |
| 2409 | Inadequate Risk Management Exercises | critical | 10.0 | 1 | Data Breach |
| 2410 | Physical accessibility of undersea infrastructure | critical | 10.0 | 1 | Physical sabotage (cyber-physical attack) |
| 2411 | CVE-2026-20160 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2412 | Systemic design flaw in Anthropic’s Model Context Protocol (MCP) | critical | 10.0 | 1 | Remote Command Execution (RCE) |
| 2413 | CVE-2024-2658 (CWE-427: Uncontrolled Search Path Element) | critical | 10.0 | 1 | Privilege Escalation |
| 2414 | Legitimate credentials | critical | 10.0 | 1 | AI-enabled attack |
| 2415 | weak token security | critical | 10.0 | 1 | third-party breach |
| 2416 | Insufficient Behavioral Analysis | critical | 10.0 | 1 | Botnet Disruption |
| 2417 | Flaws in adjacent infrastructure (wallets, custody systems, or transaction layers) | critical | 10.0 | 1 | Hack |
| 2418 | React2Shell (CVE-2025-55182) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2419 | CVE-2026-87719 | critical | 10.0 | 1 | Data Breach |
| 2420 | Poor Kubernetes configurations | critical | 10.0 | 1 | Cloud Infrastructure Compromise |
| 2421 | UPnP misconfigurations | critical | 10.0 | 1 | Botnet |
| 2422 | Azure Automation Service Vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2423 | CVE-2026-1731 (BeyondTrust) | critical | 10.0 | 1 | Ransomware |
| 2424 | Weak/Reused Passwords | critical | 10.0 | 1 | Account Compromise |
| 2425 | Low Digital Literacy in Business Software | critical | 10.0 | 1 | Ransomware Attack |
| 2426 | CVE-2020-0688 | critical | 10.0 | 1 | Cyber Espionage |
| 2427 | Authenticated Reflected XSS | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2428 | MSP software flaws | critical | 10.0 | 1 | ransomware |
| 2429 | enterprise software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2430 | CVE-2021-44228 (Log4j) | critical | 10.0 | 1 | cyberespionage |
| 2431 | CVE-2025-61155 | critical | 10.0 | 1 | Ransomware |
| 2432 | CVE-2026-16812 (CWE-78 - Improper Neutralization of Special Elements used in an OS Command) | critical | 10.0 | 1 | Zero-Day Exploit |
| 2433 | Dependence on GPS/GNSS signals for navigation; lack of spoofing-resistant safeguards | critical | 10.0 | 1 | GNSS spoofing |
| 2434 | CVE-2025-52163 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2435 | Security issue with Haltdos | critical | 10.0 | 1 | Data Breach |
| 2436 | CVE-2025-2783 | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 2437 | administrator privilege escalation | critical | 10.0 | 1 | phishing |
| 2438 | Unauthorized Access by Ex-Employee | critical | 10.0 | 1 | Data Breach |
| 2439 | insufficient cloud-native security controls | critical | 10.0 | 1 | ransomware |
| 2440 | CVE-2025-0289 in BioNTdrv.sys driver | critical | 10.0 | 1 | Ransomware |
| 2441 | Roundcube vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 2442 | CVE-2026-22898 (Missing authentication check in QVR Pro) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2443 | Content-Type confusion flaw in n8n's webhook and file handling mechanism (CVE-2026-21858) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2444 | Lack of monitoring for east-west traffic in cloud environments | critical | 10.0 | 1 | Ransomware |
| 2445 | Microsoft Entra ID Enterprise Applications (mail.read, full_access_as_app scopes) | critical | 10.0 | 1 | Espionage |
| 2446 | exposed remote services | critical | 10.0 | 1 | Ransomware |
| 2447 | CVE-2023-48788 (Fortinet EMS SQL injection) | critical | 10.0 | 1 | Ransomware |
| 2448 | Unknown network vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 2449 | CVE-2024-20353 (Infinite Loop DoS) | critical | 10.0 | 1 | Cyberattack |
| 2450 | CVE-2025-40551 (CWE-502: Unsafe Deserialization) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2451 | Lack of continuous vendor monitoring | critical | 10.0 | 1 | Ransomware |
| 2452 | Modified OpenSSH binaries, tampered PAM modules, custom implants (e.g., auditdb, SOCKS5 proxies) | critical | 10.0 | 1 | Cyber Espionage |
| 2453 | Complacency in High-Turnover Workforces | critical | 10.0 | 1 | Data Breach |
| 2454 | Visual Redaction Without Data Removal | critical | 10.0 | 1 | Data Leak |
| 2455 | CVE-2025-20333 (Authentication bypass in Cisco ASA Software) | critical | 10.0 | 1 | Zero-day exploitation |
| 2456 | Lack of AI Agent Safeguards | critical | 10.0 | 1 | Espionage |
| 2457 | lack of email security by design | critical | 10.0 | 1 | phishing |
| 2458 | Lack of Multi-Factor Authentication (Assumed) | critical | 10.0 | 1 | Ransomware |
| 2459 | Unmonitored API Queries (Graph, Teams) | critical | 10.0 | 1 | Social Engineering |
| 2460 | Inadequate HR and Compliance Monitoring | critical | 10.0 | 1 | Data Breach |
| 2461 | Check Point gateway devices | critical | 10.0 | 1 | Supply Chain Attack |
| 2462 | Cybersecurity vulnerabilities in Hikvision products | critical | 10.0 | 1 | Ransomware |
| 2463 | Schneider Electric industrial controllers | critical | 10.0 | 1 | ransomware |
| 2464 | End-of-life and end-of-service network devices, outdated infrastructure | critical | 10.0 | 1 | Ransomware |
| 2465 | Zero-day flaw in Oracle E-Business Suite | critical | 10.0 | 1 | Data Breach |
| 2466 | CVE-2015-2291 | critical | 10.0 | 1 | Cyberattack |
| 2467 | Adversarial AI Tactics Against Defensive Models (ENISA 2025) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 2468 | CVE-2024-30103 (Remote Code Execution) | critical | 10.0 | 1 | Zero-Day Exploit |
| 2469 | Employee downloaded malware from untrusted source | critical | 10.0 | 1 | Ransomware Attack |
| 2470 | Mismanagement of data storage | critical | 10.0 | 1 | Data Breach |
| 2471 | lack of real-time cross-verification of vessel identities | critical | 10.0 | 1 | AIS spoofing |
| 2472 | Pulse Secure CVE-2019-11510 | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 2473 | CVE-2026-3854 (GitHub Enterprise Server RCE) | critical | 10.0 | 1 | Data Breach |
| 2474 | Vulnerabilities in the email system | critical | 10.0 | 1 | Data Breach |
| 2475 | Technical vulnerabilities | critical | 10.0 | 1 | Illegal intrusion |
| 2476 | Weak PostgreSQL credentials | critical | 10.0 | 1 | Ransomware |
| 2477 | Compromised AWS API key via supply-chain attack on Trivy | critical | 10.0 | 1 | Data Breach |
| 2478 | Inadequate validation of `gatewayUrl` parameter in ClawDBot Control UI (GHSA-g8p2-7wf7-98mq) | critical | 10.0 | 1 | Authentication Bypass, Remote Code Execution (RCE) |
| 2479 | Misconfigured permissions, weak access controls, over-privileged identities | critical | 10.0 | 1 | Misconfiguration, Privilege Escalation, Data Exfiltration, AI Security |
| 2480 | Abuse of legitimate utilities (finger.exe, curl.exe, IronPython), lack of detection for unusual User-Agent strings, flawed persistence logic exploitation | critical | 10.0 | 1 | RAT (Remote Access Trojan) |
| 2481 | CVE-2022-42475 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 2482 | Unsecured BIM/cloud platforms | critical | 10.0 | 1 | Ransomware |
| 2483 | Juniper Networks routers | critical | 10.0 | 1 | Cyberespionage |
| 2484 | 20+ Vulnerabilities | critical | 10.0 | 1 | AI-Powered Cyberattack |
| 2485 | Insufficient data access controls | critical | 10.0 | 1 | Data Exfiltration |
| 2486 | BDU-2025-10116 (CVSS 9.8) - Command injection | critical | 10.0 | 1 | Cyber Espionage |
| 2487 | SMB signing misconfigurations | critical | 10.0 | 1 | Ransomware |
| 2488 | Authentication keys | critical | 10.0 | 1 | Cyberattack |
| 2489 | Improper Public Access Configuration | critical | 10.0 | 1 | Data Exposure |
| 2490 | Previously exposed data breach (Gmail account) | critical | 10.0 | 1 | Cyber Espionage |
| 2491 | lack of threat detection tuning | critical | 10.0 | 1 | ransomware |
| 2492 | Zero-day vulnerability in ktapi.sys (Kontron driver) | critical | 10.0 | 1 | Ransomware |
| 2493 | Windows Volume Shadow Copy Service (VSS) | critical | 10.0 | 1 | ransomware |
| 2494 | Software flaw in Tesla's systems | critical | 10.0 | 1 | Hacking |
| 2495 | CVE-2023-20867 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 2496 | CVE-2026-44962 (Improper Neutralization of Data within XPath Expressions - CWE-643) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2497 | CVE-2026-41940 (authentication bypass flaw in cPanel and WHM) | critical | 10.0 | 1 | Supply Chain Attack |
| 2498 | Insecure plug-ins | critical | 10.0 | 1 | AI-enabled breach |
| 2499 | Improper input sanitization in telnetd authentication mechanism (CWE-20) | critical | 10.0 | 1 | Authentication Bypass |
| 2500 | Publicly readable Microsoft Dataverse tables due to overly permissive anonymous access settings | critical | 10.0 | 1 | Data Exposure |
| 2501 | CVE-2025-10725 (CVSS 9.9) | critical | 10.0 | 1 | Privilege Escalation / Vulnerability Exploitation |
| 2502 | Lack of IEC 62443 security standards, insufficient OT forensics, stealthy frequency manipulation, third-party optimizer vulnerabilities | critical | 10.0 | 1 | Cyber-Physical Attack |
| 2503 | CVE-2024-13804 | critical | 10.0 | 1 | Vulnerability Exploit |
| 2504 | At least 20 exploited vulnerabilities | critical | 10.0 | 1 | Data Breach, Cyberattack, AI-Enabled Attack |
| 2505 | Zero-Day in Network Appliances (e.g., VMware vCenter, ESXi) | critical | 10.0 | 1 | Espionage |
| 2506 | Insufficient Vendor Oversight | critical | 10.0 | 1 | Supply Chain Attack |
| 2507 | CVE-2025-12556 (Improper input validation in ICM Viewer’s WebSocket communication) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2508 | Exposed credentials in public repository | critical | 10.0 | 1 | Data Exposure |
| 2509 | Legacy network | critical | 10.0 | 1 | Data Breach |
| 2510 | CVE-2025-68615 (Buffer Overflow in snmptrapd) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2511 | reliance on IT generalists without specialized security training | critical | 10.0 | 1 | ransomware |
| 2512 | Default Teams App Permissions | critical | 10.0 | 1 | Social Engineering |
| 2513 | High-risk extension permissions | critical | 10.0 | 1 | Session Hijacking |
| 2514 | CVE-2026-0542 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2515 | CVEs in Cisco's routers | critical | 10.0 | 1 | Data Breach |
| 2516 | CVE-2026-42945 (NGINX) | critical | 10.0 | 1 | Zero-day Exploit |
| 2517 | abuse of Velociraptor tool | critical | 10.0 | 1 | ransomware |
| 2518 | Embedded credentials/API keys in source code | critical | 10.0 | 1 | Supply Chain Compromise |
| 2519 | CVE-2026-20045 (Improper input validation in HTTP requests) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2520 | CVE-2024-55591 (Fortinet FortiOS) | critical | 10.0 | 1 | Ransomware |
| 2521 | Azure Data Factory service certificate vulnerability | critical | 10.0 | 1 | Security Flaw |
| 2522 | CVE-2025-48595 (Integer Overflow - CWE-190) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2523 | CVE-2026-33725 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2524 | Publicly exposed Ollama AI servers without authentication or monitoring | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2525 | Improper input validation in Gogs codebase | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2526 | lack of MFA on critical systems | critical | 10.0 | 1 | ransomware |
| 2527 | CVE-2026-59310 (VMware vCenter) | critical | 10.0 | 1 | ransomware |
| 2528 | CVE-2024-57968 | critical | 10.0 | 1 | Security Breach |
| 2529 | VMware ESXi infrastructure (Linux ransomware) | critical | 10.0 | 1 | ransomware |
| 2530 | CVE-2026-42533 | critical | 10.0 | 1 | Heap Buffer Overflow |
| 2531 | Improper input validation in the plugin’s `prepare_post_data()` function, allowing PHP function injection via placeholders (e.g., `{entryCounter}`). | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2532 | CVE-2026-24301 (Copilot Personal data exfiltration) | critical | 10.0 | 1 | ransomware |
| 2533 | Cached Administrative Credentials in Workstation Memory | critical | 10.0 | 1 | Data Breach |
| 2534 | CVE-2025-8875 (Insecure Deserialization Leading to Command Execution) | critical | 10.0 | 1 | Vulnerability Exposure |
| 2535 | WinRAR RCE | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 2536 | Windows kernel vulnerabilities | critical | 10.0 | 1 | Data Exfiltration, Ransomware, Extortion |
| 2537 | Absence of Visibility/Monitoring for Non-Email Channels | critical | 10.0 | 1 | Phishing (Non-Email) |
| 2538 | Flaws in Tesla’s Mothership server | critical | 10.0 | 1 | Remote Code Execution |
| 2539 | Exposed Database | critical | 10.0 | 1 | Ransomware Attack |
| 2540 | Trust model in open-source ecosystems, self-replicating worm propagation | critical | 10.0 | 1 | Supply Chain Attack |
| 2541 | third-party tokens | critical | 10.0 | 1 | ransomware |
| 2542 | Apache Struts CVE-2017-5638 | critical | 10.0 | 1 | Data Breach |
| 2543 | CVE-2025-20352 (Cisco IOS SNMP Flaw) | critical | 10.0 | 1 | Ransomware |
| 2544 | Software Issue | critical | 10.0 | 1 | Data Breach |
| 2545 | CVE-2022-26134 (Atlassian OGNL Injection) | critical | 10.0 | 1 | cyberespionage |
| 2546 | Internet-exposed systems | critical | 10.0 | 1 | Cyber Threat Alert |
| 2547 | Unauthorized Disclosure of Sensitive Information | critical | 10.0 | 1 | Security Vulnerabilities |
| 2548 | CVE-2026-63030 (batch-route RCE) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2549 | unpatched Veeam backup servers | critical | 10.0 | 1 | ransomware |
| 2550 | Stack Buffer Overflow | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2551 | Excessive Privileges (God-level access) | critical | 10.0 | 1 | Data Breach |
| 2552 | Infostealer logs | critical | 10.0 | 1 | Extortion / Data Leak Threat |
| 2553 | CVE-2023-46805 (Ivanti Connect Secure) | critical | 10.0 | 1 | ransomware |
| 2554 | Insufficient MFA Enforcement (Ghost Logins, SSO Gaps) | critical | 10.0 | 1 | Browser-Based Attack |
| 2555 | Trust Exploitation | critical | 10.0 | 1 | Cryptocurrency Scam |
| 2556 | Thousands of zero-day vulnerabilities | critical | 10.0 | 1 | AI-driven cyber attack |
| 2557 | CVE-2025-59469 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2558 | CVE not specified (algif_aead module in Linux kernel’s AF_ALG cryptographic subsystem) | critical | 10.0 | 1 | Privilege Escalation |
| 2559 | CVE-2022-37055 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2560 | Shared Responsibility Model Gaps in Cloud Security | critical | 10.0 | 1 | Predictive Analysis |
| 2561 | CVE-2026-27966 | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 2562 | CVE-2026-1579 (Missing Authentication for Critical Function) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2563 | Policy Non-Compliance | critical | 10.0 | 1 | Data Breach (Alleged) |
| 2564 | SonicWall | critical | 10.0 | 1 | Supply Chain Attack |
| 2565 | Known vulnerability in the network | critical | 10.0 | 1 | Ransomware Attack |
| 2566 | Unpatched bugs in internet-connected cameras | critical | 10.0 | 1 | Espionage |
| 2567 | Informant Malfeasance | critical | 10.0 | 1 | Dissemination of Propaganda and Child Abuse Material |
| 2568 | Alleged zero-day vulnerability in MyBB or misconfiguration | critical | 10.0 | 1 | Data Breach |
| 2569 | Weak perimeter defenses, inadequate network segmentation | critical | 10.0 | 1 | Ransomware |
| 2570 | CVE-2025-32714 (Windows Installer EoP) | critical | 10.0 | 1 | Patch Release |
| 2571 | Weak Subcontractor Security Postures | critical | 10.0 | 1 | Supply Chain Attack |
| 2572 | CVE-2026-50751 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2573 | Unchanged credentials | critical | 10.0 | 1 | Ransomware |
| 2574 | Accellion File Transfer Appliance (FTA) vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 2575 | CVE-2026-85880 (Windows ALPC) | critical | 10.0 | 1 | Zero-day exploitation |
| 2576 | Compromised Microsoft 365 Account | critical | 10.0 | 1 | Data Breach |
| 2577 | Poor IT/OT network segmentation | critical | 10.0 | 1 | Cyber Espionage |
| 2578 | CVE-2024-40766 (SonicWall) | critical | 10.0 | 1 | ransomware |
| 2579 | Weak supply chain controls for hardware distribution | critical | 10.0 | 1 | Espionage |
| 2580 | CVE-2021-33044 (Dahua - authentication bypass) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 2581 | Improper input validation in USER environment variable handling | critical | 10.0 | 1 | Authentication Bypass |
| 2582 | Supply-chain vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2583 | weak credential governance | critical | 10.0 | 1 | phishing |
| 2584 | Unpatched VPN Devices | critical | 10.0 | 1 | Supply Chain Attack |
| 2585 | Unauthorized remote access, ATM jackpotting, Point-of-sale data compromise | critical | 10.0 | 1 | Cyber Attack |
| 2586 | Zero-day exploits, Supply-chain weaknesses | critical | 10.0 | 1 | Supply-chain attack, Data exfiltration, Reconnaissance |
| 2587 | CVE-2026-20093 | critical | 10.0 | 1 | Authentication Bypass |
| 2588 | Windows Defender Disabling | critical | 10.0 | 1 | Ransomware |
| 2589 | improper access controls on cloud storage (public bucket setting) | critical | 10.0 | 1 | data breach |
| 2590 | Known security gaps in domestic agencies | critical | 10.0 | 1 | Data Breach |
| 2591 | Physical Infrastructure | critical | 10.0 | 1 | Sabotage |
| 2592 | identity and access weaknesses | critical | 10.0 | 1 | ransomware |
| 2593 | Provider Edge (PE) routers | critical | 10.0 | 1 | Cyber Espionage |
| 2594 | CVE-2024-11120 | critical | 10.0 | 1 | Cyberattack |
| 2595 | GenAI data exfiltration | critical | 10.0 | 1 | Session Hijacking |
| 2596 | Human vulnerability (tricking employees into divulging credentials) | critical | 10.0 | 1 | Data Breach / Ransomware Attack |
| 2597 | Unlocked AWS S3 bucket | critical | 10.0 | 1 | Data Breach |
| 2598 | Web frameworks (React, Next.js) | critical | 10.0 | 1 | Reconnaissance |
| 2599 | Insecure RDP configurations | critical | 10.0 | 1 | Ransomware |
| 2600 | Trustwave’s miscategorization of breach alert as 'moderate' (delayed response) | critical | 10.0 | 1 | Ransomware |
| 2601 | CVE-2026-24423 (Missing Authentication for Critical Function - CWE-306) | critical | 10.0 | 1 | Ransomware |
| 2602 | CVE-2025-49844 (RediShell - Use-after-free in Lua sandbox) | critical | 10.0 | 1 | Vulnerability |
| 2603 | Gaps in anomaly detection for behavioral baselines | critical | 10.0 | 1 | Ransomware |
| 2604 | CVE-2023-23397 | critical | 10.0 | 1 | Cyberespionage |
| 2605 | Poor authentication controls | critical | 10.0 | 1 | Data Breach |
| 2606 | Zero-Day Vulnerabilities (1 new CVE every 17 minutes) | critical | 10.0 | 1 | Ransomware |
| 2607 | Automated execution during `npm install`, GitHub Actions environment targeting | critical | 10.0 | 1 | Supply Chain Attack |
| 2608 | Unsalted MD5 | critical | 10.0 | 1 | Data Breach |
| 2609 | Publicly accessible web service | critical | 10.0 | 1 | AI-driven cyberattack |
| 2610 | Insecure ID verification processes | critical | 10.0 | 1 | Data Breach |
| 2611 | Apache Tomcat vulnerabilities | critical | 10.0 | 1 | AI-driven cyberattack |
| 2612 | weak insider threat detection | critical | 10.0 | 1 | data breach |
| 2613 | Insecure Default Settings | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2614 | CVE-2024-12356 | critical | 10.0 | 1 | Breach |
| 2615 | ManageSieve misconfigurations | critical | 10.0 | 1 | Cyber Espionage |
| 2616 | Potential Weak MFA Implementation (2FA Prompt Bombing) | critical | 10.0 | 1 | Insider Threat (Attempted) |
| 2617 | Remote login vulnerability exacerbated by increased remote work during the pandemic | critical | 10.0 | 1 | Ransomware |
| 2618 | YellowKey (BitLocker bypass) | critical | 10.0 | 1 | Zero-day vulnerability |
| 2619 | vendor distribution pipelines | critical | 10.0 | 1 | ransomware |
| 2620 | CVE-2026-34197 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2621 | vulnerable driver | critical | 10.0 | 1 | ransomware |
| 2622 | CVE-2024-12297 | critical | 10.0 | 1 | Vulnerability Exploit |
| 2623 | Known vulnerability in cloud storage services | critical | 10.0 | 1 | Data Breach |
| 2624 | Lack of Robust Backup Systems | critical | 10.0 | 1 | Supply Chain Attack |
| 2625 | CVE-2021-39935 (CWE-918) | critical | 10.0 | 1 | Server-Side Request Forgery (SSRF) |
| 2626 | CVE-2026-16232 (Check Point SmartConsole) | critical | 10.0 | 1 | Zero-day Exploit |
| 2627 | Publicly shared GPS data from fitness app | critical | 10.0 | 1 | Data Exposure |
| 2628 | Unsecured remote connections | critical | 10.0 | 1 | Cyberattack on Operational Technology (OT) |
| 2629 | Data integrity | critical | 10.0 | 1 | Security Concerns |
| 2630 | Known vulnerability in database software | critical | 10.0 | 1 | Data Breach |
| 2631 | CVE-2025-14847 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2632 | Insecure Backups | critical | 10.0 | 1 | Compliance Failure |
| 2633 | Default password in Unitronics programmable logic controllers (PLCs) | critical | 10.0 | 1 | Cyberattack |
| 2634 | RenderShock 0-Click Vulnerability | critical | 10.0 | 1 | Zero-Click Attack |
| 2635 | Use-After-Free (UAF) in Samsung KNOX PROCA/FIVE subsystem | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2636 | Architectural flaw in Model Context Protocol (MCP) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2637 | Broken Authorization in Chunked Uploads | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2638 | Microsoft Defender Exclusion Abuse | critical | 10.0 | 1 | Cyberespionage |
| 2639 | CVE-2024-20353 | critical | 10.0 | 1 | Zero-Day Exploit |
| 2640 | publicly available personal data (e.g., photos, job titles) | critical | 10.0 | 1 | social engineering |
| 2641 | dependency trust model | critical | 10.0 | 1 | supply chain attack |
| 2642 | CVE-2026-0489 (DOM-based XSS in SAP Business One Job Service) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2643 | Unmaintained Software (e.g., FreeImage in Audi Vehicles) | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 2644 | Weak Password Security (hypothetical, based on context) | critical | 10.0 | 1 | Ransomware Attack |
| 2645 | SQL Injection vulnerabilities in WordPress-powered website | critical | 10.0 | 1 | Data Breach |
| 2646 | Unpatched zero-day vulnerability in Oracle E-Business Suite (arbitrary code execution) | critical | 10.0 | 1 | ransomware |
| 2647 | CVE-2026-29058 (CWE-78: Improper Neutralization of Special Elements) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2648 | CVE-2025-8943 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2649 | Misconfigured Cloud Storage (S3, MongoDB) | critical | 10.0 | 1 | Data Breach |
| 2650 | unsecured AWS memory dump | critical | 10.0 | 1 | ransomware |
| 2651 | CVE-2021-22681 (Rockwell Automation ICS) | critical | 10.0 | 1 | ransomware |
| 2652 | Persistent jailbreak of Google Gemini AI, Weak non-English safety controls, Memory retention flaws, Stolen API keys, Trojanized software (StellarMonster) | critical | 10.0 | 1 | Fraud, Credential Theft, Cryptocurrency Theft, Social Engineering |
| 2653 | CVE-2026-45247 (PHP object injection, CWE-502) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2654 | Undisclosed Vulnerabilities in BIG-IP (details not public) | critical | 10.0 | 1 | Data Breach |
| 2655 | CVE-2025-10035 (GoAnywhere MFT, CVSS 10.0) | critical | 10.0 | 1 | data breach |
| 2656 | Claude Code tool's contextual safeguard limitations | critical | 10.0 | 1 | cyberespionage |
| 2657 | CVE-2026-60004 (Gitea RCE flaw in diffpatch workflow) | critical | 10.0 | 1 | Cyber Espionage, Data Theft, Persistent Access |
| 2658 | Windows Driver Signature Enforcement bypass via signed driver abuse | critical | 10.0 | 1 | Ransomware |
| 2659 | StyleSmuggler (Magento/Adobe Commerce zero-day) | critical | 10.0 | 1 | Zero-day exploitation |
| 2660 | Slow Detection Capabilities | critical | 10.0 | 1 | Data Breach |
| 2661 | Insecure Remote Work Tools | critical | 10.0 | 1 | Data Breach (General Discussion) |
| 2662 | Server flaw identified via network traffic analysis | critical | 10.0 | 1 | Unauthorized Access |
| 2663 | Unpatched flaw in a popular enterprise software platform | critical | 10.0 | 1 | Cyberattack |
| 2664 | remote management tool abuse | critical | 10.0 | 1 | ransomware |
| 2665 | Malfunction at AWS data center (likely a configuration error) | critical | 10.0 | 1 | Service Disruption |
| 2666 | Lack of Real-Time Monitoring for Undersea Infrastructure | critical | 10.0 | 1 | Physical Sabotage |
| 2667 | unknown (zero-day) | critical | 10.0 | 1 | cyberattack |
| 2668 | CVE-2025-53770 (ToolShell SharePoint Flaw) | critical | 10.0 | 1 | Cyber Espionage |
| 2669 | CVE-2025-47167 (Windows KDC Proxy Service Use-After-Free) | critical | 10.0 | 1 | Patch Release |
| 2670 | Insecure support ticketing platform (bulk data export without rate-limiting or access controls) | critical | 10.0 | 1 | Data Breach |
| 2671 | Banking security systems | critical | 10.0 | 1 | Malware |
| 2672 | Over-reliance on remote desktop tools without geofencing | critical | 10.0 | 1 | Espionage |
| 2673 | Lack of Multi-Factor Authentication (2FA) for OAuth Apps | critical | 10.0 | 1 | Data Breach |
| 2674 | Unknown authentication bug, Insider knowledge of security procedures | critical | 10.0 | 1 | Corporate Espionage, Trade Secret Theft |
| 2675 | Insufficient Contractual Safeguards | critical | 10.0 | 1 | Third-Party Breach |
| 2676 | Weak Authentication for Third-Party Access | critical | 10.0 | 1 | Cyberattack |
| 2677 | SSO Misconfigurations (e.g., Microsoft Entra, Google Workspace, Okta) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 2678 | CVE-2025-64446 | critical | 10.0 | 1 | Ransomware |
| 2679 | Dormant Backdoors | critical | 10.0 | 1 | Supply Chain Attack |
| 2680 | Unpatched vulnerabilities (exploited within 24 hours of public disclosure) | critical | 10.0 | 1 | Ransomware |
| 2681 | CVE-2021-36380 | critical | 10.0 | 1 | Cyber Attack |
| 2682 | Insecure External Storage Device | critical | 10.0 | 1 | Data Breach |
| 2683 | Interconnexion entre datacenter et réseau internet | critical | 10.0 | 1 | DDoS |
| 2684 | CVE-2025-26512 | critical | 10.0 | 1 | Privilege Escalation |
| 2685 | CVE-2026-33017 (Langflow servers) | critical | 10.0 | 1 | AI-driven cyberattack |
| 2686 | OAuth Token Misuse | critical | 10.0 | 1 | Supply Chain Attack |
| 2687 | Broad systemic vulnerabilities including reliance on foreign manufacturing for supply chains, dependency on cyber-vulnerable space systems (GPS, satellite communications), and weaknesses in infrastructure resilience against climate events. | critical | 10.0 | 1 | Ransomware Attack |
| 2688 | Misconfigured Email Security Solutions (Mimecast, Proofpoint, Barracuda) | critical | 10.0 | 1 | Data Breach |
| 2689 | SysAid software update feature (DLL sideloading) | critical | 10.0 | 1 | Cyberespionage |
| 2690 | poor_network_segmentation | critical | 10.0 | 1 | ransomware |
| 2691 | insecure credential storage in CI/CD environments | critical | 10.0 | 1 | supply chain attack |
| 2692 | Hidden dependency with postinstall script execution | critical | 10.0 | 1 | Supply Chain Attack |
| 2693 | accidental exposure of regional blacklist data | critical | 10.0 | 1 | data breach |
| 2694 | Authentication tokens harvested from Anodot, bypassing multi-factor authentication | critical | 10.0 | 1 | Data Breach |
| 2695 | Human Vulnerability (Bribery/Extortion) | critical | 10.0 | 1 | Insider Threat |
| 2696 | RedSun | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2697 | CVE-2026-27944 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2698 | CVE-2026-54400 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2699 | CVE-2025-27816 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2700 | Unsupported hardware | critical | 10.0 | 1 | Cyberattack |
| 2701 | privileged credential abuse | critical | 10.0 | 1 | ransomware |
| 2702 | Weak VPN authentication | critical | 10.0 | 1 | Data Breach |
| 2703 | Stolen credentials, malicious links in trusted email chains, phishing campaigns | critical | 10.0 | 1 | Supply Chain Attack, Cargo Theft |
| 2704 | Exposed network devices and vulnerabilities in OT systems | critical | 10.0 | 1 | Cyberattack on Critical Infrastructure |
| 2705 | Vimar smart home devices | critical | 10.0 | 1 | DDoS Attack |
| 2706 | Insider access to classified systems, Lack of real-time monitoring for data exfiltration | critical | 10.0 | 1 | Insider Threat, Espionage |
| 2707 | Integer underflow in IPv6 extension header parser (Inspect.sys) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 2708 | Abuse of Native Windows Utilities (curl, certutil) | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 2709 | Insecure Third-Party Integration Controls | critical | 10.0 | 1 | Data Breach |
| 2710 | open ports | critical | 10.0 | 1 | Ransomware |
| 2711 | Stack overflow (CVE-2026-3608) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 2712 | CVE-2020-12641 | critical | 10.0 | 1 | Cyberespionage |
| 2713 | Supply chain compromise (Trivy), credential theft | critical | 10.0 | 1 | Supply Chain Attack, Data Breach |
| 2714 | CVE-2026-41050 | critical | 10.0 | 1 | Privilege Escalation |
| 2715 | weak_or_reused_passwords | critical | 10.0 | 1 | ransomware |
| 2716 | GitHub Workflows Misconfiguration | critical | 10.0 | 1 | Supply Chain Attack |
| 2717 | High-severity software flaws (Mythos AI) | critical | 10.0 | 1 | AI-driven vulnerability exploitation |
| 2718 | Vulnerabilities in enterprise platforms like Oracle EBS | critical | 10.0 | 1 | Data Theft |
| 2719 | Weak Security Controls at Third-Party Contractor | critical | 10.0 | 1 | Data Breach |
| 2720 | Lack of Centralized Log Management | critical | 10.0 | 1 | Data Breach |
| 2721 | Cross-site scripting (XSS) in Biggop Library | critical | 10.0 | 1 | Supply-Chain Attack |
| 2722 | Unauthorized access due to offshoring of IT and cybersecurity functions, bypassed consent protocols | critical | 10.0 | 1 | Data Breach |
| 2723 | Flaw in SentinelOne's agent upgrade process | critical | 10.0 | 1 | Ransomware |
| 2724 | Excessive Privileges in Connected Applications | critical | 10.0 | 1 | Data Breach |
| 2725 | CVE-2026-1358 (Unrestricted File Upload) | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2726 | Incomplete Patch (CVE-2026-21510) | critical | 10.0 | 1 | Data Breach |
| 2727 | Insufficient Threat Hunting Capabilities | critical | 10.0 | 1 | EDR/XDR Evasion |
| 2728 | Weak Identity Management (Lack of Privileged Account Separation) | critical | 10.0 | 1 | Cyber Espionage |
| 2729 | Security flaw in Neighbors app | critical | 10.0 | 1 | Data Breach |
| 2730 | Unknown vulnerability in the *Safe Smart Port (PIS)* platform | critical | 10.0 | 1 | Data Breach |
| 2731 | Compromised off-chain infrastructure for price feeds | critical | 10.0 | 1 | Exploit |
| 2732 | Human Trust, Lack of Investment Verification | critical | 10.0 | 1 | Investment Scam, Money Laundering, Cryptocurrency Fraud |
| 2733 | Linux kernel flaws (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-43503) | critical | 10.0 | 1 | Cyber Intrusion |
| 2734 | npm supply chain compromise (Nx platform) | critical | 10.0 | 1 | Supply Chain Attack |
| 2735 | Vulnerable signed drivers (exploited via BYOVD) | critical | 10.0 | 1 | Ransomware |
| 2736 | Dell BIOS firmware flaws | critical | 10.0 | 1 | Zero-day exploit |
| 2737 | CVE-2025-26399 | critical | 10.0 | 1 | Ransomware |
| 2738 | Unhashed Passwords | critical | 10.0 | 1 | Data Breach |
| 2739 | lack of physical safeguards | critical | 10.0 | 1 | infrastructure vulnerability |
| 2740 | Remote desktop gateway vulnerability | critical | 10.0 | 1 | Ransomware |
| 2741 | Symlink (junction) attack in Nessus Agent for Windows | critical | 10.0 | 1 | Privilege Escalation |
| 2742 | Human trust and credential theft | critical | 10.0 | 1 | Ransomware |
| 2743 | CVE-2026-21962 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2744 | Misconfigured GitHub Actions workflow (exposed privileged bot token) | critical | 10.0 | 1 | Supply Chain Compromise |
| 2745 | Cellular telecommunications infrastructure for remote equipment management | critical | 10.0 | 1 | Cyberattack on Industrial Control Systems (ICS) |
| 2746 | 200+ vulnerabilities in CISA’s KEV catalog (2024–2025) | critical | 10.0 | 1 | ransomware |
| 2747 | BYOVD (Bring Your Own Vulnerable Driver) activity | critical | 10.0 | 1 | Ransomware |
| 2748 | Videoconference Invitation | critical | 10.0 | 1 | Data Breach |
| 2749 | Lack of file type limitations | critical | 10.0 | 1 | Data Breach |
| 2750 | Absence of Standardized Risk Assessments | critical | 10.0 | 1 | Ransomware |
| 2751 | Lack of Centralized Logging/Monitoring | critical | 10.0 | 1 | Cyber Espionage |
| 2752 | Active Directory Certificate Services | critical | 10.0 | 1 | Ransomware |
| 2753 | Poor Access Management | critical | 10.0 | 1 | Data Breach |
| 2754 | Newly disclosed global software vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2755 | CVE-2025-7544 | critical | 10.0 | 1 | Botnet Campaign |
| 2756 | Unpatched vulnerability in remote access software | critical | 10.0 | 1 | Cyberattack |
| 2757 | CVE-2025-4428 | critical | 10.0 | 1 | Cyber Espionage |
| 2758 | Manque de sauvegardes régulières | critical | 10.0 | 1 | Cyberattaque ciblée |
| 2759 | Exposed Database Credentials | critical | 10.0 | 1 | Data Exposure |
| 2760 | CVE-2024-12856 | critical | 10.0 | 1 | DDoS |
| 2761 | CVE-2025-58434 (Unauthenticated Password Reset Token Disclosure in `/api/v1/account/forgot-password`) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2762 | CVE-2025-48057 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2763 | JetBrains TeamCity | critical | 10.0 | 1 | Ransomware |
| 2764 | Weak Third-Party Security Controls | critical | 10.0 | 1 | Data Breach |
| 2765 | Improper Data Handling Practices | critical | 10.0 | 1 | Data Breach |
| 2766 | CVE-2026-9739 (CWE-942 - Permissive Cross-domain Policy with Untrusted Domains) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2767 | Visual Studio Code extension compromise | critical | 10.0 | 1 | ransomware |
| 2768 | Seven critical-severity CVEs across 10 product families | critical | 10.0 | 1 | Cyber Attack |
| 2769 | CVE-2026-19490 (Citrix NetScaler auth bypass) | critical | 10.0 | 1 | ransomware |
| 2770 | Unpatched VPN software | critical | 10.0 | 1 | Ransomware |
| 2771 | Weak data protections | critical | 10.0 | 1 | Data Breach |
| 2772 | Loose Sharing Permissions | critical | 10.0 | 1 | Data Breach Risk |
| 2773 | CVE-2022-41040 | critical | 10.0 | 1 | Ransomware |
| 2774 | CVE-2025-2492 | critical | 10.0 | 1 | botnet |
| 2775 | User Trust in Browser Prompts (Copy-Paste Commands, Fake Error Messages) | critical | 10.0 | 1 | Browser-Based Attack |
| 2776 | Access to sensitive infrastructure data | critical | 10.0 | 1 | Insider Threat |
| 2777 | Shared login credentials | critical | 10.0 | 1 | Data Breach |
| 2778 | CVE-2025-27520 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2779 | CVE-2026-43499 (GhostLock) | critical | 10.0 | 1 | Privilege Escalation, Container Escape |
| 2780 | CVE-2026-33017 (Langflow, CVSS 9.8) | critical | 10.0 | 1 | AI-Powered Cyber Attack |
| 2781 | Improper origin validation | critical | 10.0 | 1 | Data Breach |
| 2782 | Misconfigured or overly permissive Active Directory replication permissions | critical | 10.0 | 1 | Credential Theft |
| 2783 | Third-Party Supplier Weakness | critical | 10.0 | 1 | Ransomware |
| 2784 | Ungoverned AI Systems | critical | 10.0 | 1 | Data Breach |
| 2785 | Poor Data Management | critical | 10.0 | 1 | Data Breach |
| 2786 | Unpatched Solaris servers | critical | 10.0 | 1 | APT Attack |
| 2787 | LNK file execution | critical | 10.0 | 1 | spear-phishing |
| 2788 | Unknown vulnerabilities in routers and VPN appliances | critical | 10.0 | 1 | Botnet |
| 2789 | Shared Accounts | critical | 10.0 | 1 | Data Breach |
| 2790 | Weak/reused passwords, coding flaw in 'DNA Relatives' feature | critical | 10.0 | 1 | Data Breach |
| 2791 | Inadequate Email Security Protocols | critical | 10.0 | 1 | Data Breach |
| 2792 | CVE-2026-3854 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2793 | unrestricted RDP/remote tool access | critical | 10.0 | 1 | ransomware |
| 2794 | CVE-2026-21571 | critical | 10.0 | 1 | OS Command Injection |
| 2795 | Poorly secured networks, MFA vulnerabilities | critical | 10.0 | 1 | Cyberattack, Initial Access Brokerage, Ransomware |
| 2796 | Security flaw in MOVEit software | critical | 10.0 | 1 | Data Breach |
| 2797 | help-desk protocol vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2798 | Long-standing vulnerabilities in SonicWall firewall systems, unmanaged exceptions, temporary rules, unprotected backups, administrative credentials | critical | 10.0 | 1 | Ransomware, Data Breach |
| 2799 | Architectural weakness in LLM input processing and trust boundaries | critical | 10.0 | 1 | Zero-Click Remote Code Execution (RCE) |
| 2800 | Poor Oversight of Third-Party Vendor (PowerSchool) | critical | 10.0 | 1 | Data Breach |
| 2801 | Malicious TestFlight app | critical | 10.0 | 1 | Financial Theft |
| 2802 | Reused Apple ID logins | critical | 10.0 | 1 | Data Breach, Phishing |
| 2803 | Previously Patched Vulnerabilities (Exploited Post-Patch) | critical | 10.0 | 1 | Data Breach |
| 2804 | Unpatched or end-of-life networking equipment (TP-Link routers) | critical | 10.0 | 1 | Cyberespionage, DNS Hijacking, Adversary-in-the-Middle (AiTM) Attack |
| 2805 | CitrixBleed2 (CVE not explicitly mentioned but inferred as Citrix NetScaler vulnerability) | critical | 10.0 | 1 | data breach |
| 2806 | BDU:2025-10115 (CVSS 7.5) - Arbitrary file read | critical | 10.0 | 1 | Cyber Espionage |
| 2807 | CVE-2026-8181 | critical | 10.0 | 1 | Authentication Bypass |
| 2808 | Weak password storage (SHA-256 with salt) | critical | 10.0 | 1 | Data Breach |
| 2809 | Insufficient Access Controls (Assumed) | critical | 10.0 | 1 | Ransomware |
| 2810 | CVE-2023-34362 (MOVEit Transfer) | critical | 10.0 | 1 | Ransomware |
| 2811 | Geopolitical Tensions (NATO Expansion, Ukraine War) | critical | 10.0 | 1 | Physical Sabotage |
| 2812 | Unknown Third-Party Relationships | critical | 10.0 | 1 | Data Breach |
| 2813 | Stolen secret code for cookie generation | critical | 10.0 | 1 | Data Breach |
| 2814 | Poor Email Security Practices | critical | 10.0 | 1 | Data Breach |
| 2815 | high market value of copper | critical | 10.0 | 1 | infrastructure vulnerability |
| 2816 | Incorrect access permissions and configuration settings | critical | 10.0 | 1 | Data Breach |
| 2817 | CVE-2024-48248 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2818 | Weakened power grid infrastructure | critical | 10.0 | 1 | Cyberattack |
| 2819 | CVE-2024-40766 (SonicWall improper access control, CVSS 9.8) | critical | 10.0 | 1 | ransomware |
| 2820 | CVE-2024-7014 | critical | 10.0 | 1 | Vulnerability Exploit |
| 2821 | Lack of multifactor authentication (MFA) on administrator accounts | critical | 10.0 | 1 | Data Breach |
| 2822 | Poor Spam Filtering | critical | 10.0 | 1 | Ransomware |
| 2823 | DLL Sideloading via legitimate Windows callback functions | critical | 10.0 | 1 | Cyber Espionage |
| 2824 | CVE-2024-21893 | critical | 10.0 | 1 | Ransomware |
| 2825 | API code change flaw, predictable device serial numbers, unencrypted MFA scratch codes | critical | 10.0 | 1 | Ransomware |
| 2826 | SMS-based MFA interception, lack of FIDO2 hardware keys | critical | 10.0 | 1 | Phishing-as-a-Service (PhaaS) |
| 2827 | Unrestricted Access Controls | critical | 10.0 | 1 | Ransomware |
| 2828 | Misconfigured or unprotected cloud logging mechanisms (AWS CloudTrail, Google Cloud Logging) | critical | 10.0 | 1 | Cloud Security Incident |
| 2829 | Over-Reliance on Email-Based Security Controls | critical | 10.0 | 1 | Social Engineering |
| 2830 | Vulnerable IoT hardware (digital video recorders, web cameras, home Wi-Fi routers) | critical | 10.0 | 1 | DDoS Attack |
| 2831 | Outdated Juniper Networks Junos OS MX routers | critical | 10.0 | 1 | Cyber Espionage |
| 2832 | CVE-2025-61882 (Oracle E-Business Suite - Unauthenticated RCE) | critical | 10.0 | 1 | Data Breach |
| 2833 | Trust in official source repository | critical | 10.0 | 1 | Supply Chain Attack |
| 2834 | Software Infrastructure Vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 2835 | Blind SQL Vulnerability | critical | 10.0 | 1 | Data Breach |
| 2836 | CVE-2024-53676 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2837 | Outdated remote access policies | critical | 10.0 | 1 | Ransomware |
| 2838 | CVE-2017-17562 (GoAhead RCE) | critical | 10.0 | 1 | cyberespionage |
| 2839 | Supply Chain Weaknesses | critical | 10.0 | 1 | Domain Hijacking |
| 2840 | Unpatched linked servers | critical | 10.0 | 1 | Ransomware |
| 2841 | insecure communication protocols | critical | 10.0 | 1 | unauthorized access |
| 2842 | Exposed FortiGate Management Interface | critical | 10.0 | 1 | Data Breach |
| 2843 | Weak private key generation algorithm | critical | 10.0 | 1 | Cryptocurrency Theft |
| 2844 | Outdated software (EOL Windows versions) | critical | 10.0 | 1 | Exposed Servers |
| 2845 | weak security in satellite communication systems | critical | 10.0 | 1 | cyberattack |
| 2846 | Publicly accessible Elasticsearch database | critical | 10.0 | 1 | Data Exposure |
| 2847 | Aging hardware | critical | 10.0 | 1 | Hardware Malfunction |
| 2848 | Windows SMB vulnerability (MS17-010), Unpatched systems, Windows XP | critical | 10.0 | 1 | Ransomware |
| 2849 | External call to 'transfer' function using a fake hash | critical | 10.0 | 1 | Cryptocurrency Theft |
| 2850 | Poor key management and access controls | critical | 10.0 | 1 | Data Breach |
| 2851 | APIs | critical | 10.0 | 1 | AI-enabled breach |
| 2852 | Weaknesses in third-party integrations, lack of real-time monitoring | critical | 10.0 | 1 | Third-Party Breach |
| 2853 | CVE-2025-53770 (Deserialization of untrusted data in SharePoint Server) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2854 | AI-enabled attack vectors | critical | 10.0 | 1 | ransomware |
| 2855 | Software Bug in MCP Server | critical | 10.0 | 1 | Data Exposure |
| 2856 | SonicWall SMA1000 flaws | critical | 10.0 | 1 | ransomware |
| 2857 | CVE-2026-12569 (CVSS 9.8) | critical | 10.0 | 1 | Ransomware, Data Theft |
| 2858 | Outdated Software (e.g., Iranian oil tankers) | critical | 10.0 | 1 | Ransomware |
| 2859 | Insufficient ESXi Logging Configurations | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 2860 | Obsolete Traditional Detection Systems | critical | 10.0 | 1 | Ransomware |
| 2861 | ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) | critical | 10.0 | 1 | ransomware |
| 2862 | Compromised Subcontractor Credentials | critical | 10.0 | 1 | Data Breach |
| 2863 | Tool sprawl and visibility gaps | critical | 10.0 | 1 | Data Breach |
| 2864 | CVE-2026-40175 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2865 | Compromised Software Development Tools | critical | 10.0 | 1 | Malware |
| 2866 | Zero-Authentication (Zero-Auth) Flaw | critical | 10.0 | 1 | Data Breach |
| 2867 | Political Distractions | critical | 10.0 | 1 | Operational Risk |
| 2868 | Insufficient cybersecurity training | critical | 10.0 | 1 | Data Breach |
| 2869 | CVE-2026-43500 | critical | 10.0 | 1 | Privilege Escalation |
| 2870 | CVE-2026-57807 (Broken Authentication - CWE-288) | critical | 10.0 | 1 | Authentication Bypass |
| 2871 | CVE-2025-8876 (Command Injection via Improper Input Sanitization) | critical | 10.0 | 1 | Vulnerability Exposure |
| 2872 | Trust in Professional Networking Platforms | critical | 10.0 | 1 | Phishing (Non-Email) |
| 2873 | overlooked vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2874 | BDU:2025-10114 (CVSS 7.5) - Insufficient access control | critical | 10.0 | 1 | Cyber Espionage |
| 2875 | OAuth Application Abuse | critical | 10.0 | 1 | Data Breach |
| 2876 | Unidentified network vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 2877 | Lack of Network Segmentation in Targeted Systems | critical | 10.0 | 1 | Distributed Denial of Service (DDoS) |
| 2878 | Weak Supplier Security Controls | critical | 10.0 | 1 | Ransomware |
| 2879 | Known flaw in a widely used healthcare IT management platform | critical | 10.0 | 1 | Ransomware |
| 2880 | weak SCADA system security | critical | 10.0 | 1 | cyber-physical attack |
| 2881 | CVE-2026-47876 (VMware ESXi VMXNET3) | critical | 10.0 | 1 | Zero-day Exploit |
| 2882 | human error (employee downloading malware-laced tool) | critical | 10.0 | 1 | ransomware |
| 2883 | Weak Enforcement of ISO SAE 21434 (Pre-Release Security) | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 2884 | CVE-2025-59470 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2885 | CVE-2026-70426 (JEP-200 class filter bypass) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2886 | Type Confusion via Memory Reuse | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 2887 | AI System Autonomy (unsupervised decision-making) | critical | 10.0 | 1 | Predictive Analysis |
| 2888 | CVE-2025-5777 (CitrixBleed2) | critical | 10.0 | 1 | ransomware |
| 2889 | inconsistent digital signatures and certificates | critical | 10.0 | 1 | spearphishing |
| 2890 | Third-Party Supply Chain Weaknesses | critical | 10.0 | 1 | Data Breach |
| 2891 | CVSS 9.0+ vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2892 | Internet-exposed databases | critical | 10.0 | 1 | Ransomware |
| 2893 | CVE-2017-7921 (CWE-287: Improper Authentication) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2894 | Outdated Operating Systems/Applications | critical | 10.0 | 1 | Malware |
| 2895 | CVE-2025-47953 (Microsoft Office Heap-Based Buffer Overflow) | critical | 10.0 | 1 | Patch Release |
| 2896 | Compromised software update mechanism | critical | 10.0 | 1 | Supply Chain Attack |
| 2897 | CVE-2026-20230 (Improper input validation in HTTP requests, CWE-918) | critical | 10.0 | 1 | SSRF (Server-Side Request Forgery) |
| 2898 | Lack of MFA on FortiGate VPN firewalls | critical | 10.0 | 1 | Cyberattack (Wiper Malware, Firmware Tampering) |
| 2899 | CVE-2025-52665 (Improper Input Validation in Backup API Endpoint) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2900 | Systemic weaknesses in government cybersecurity | critical | 10.0 | 1 | Unauthorized Access |
| 2901 | Authentication key theft | critical | 10.0 | 1 | Data Breach |
| 2902 | Ivanti Connect Secure | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2903 | CVE-2025-42957 (ABAP Code Injection in SAP S/4HANA) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2904 | Unclear Accountability Frameworks | critical | 10.0 | 1 | Data Privacy Violation |
| 2905 | CVE-2025-69263 (CVSS 7.5) | critical | 10.0 | 1 | Supply Chain Attack |
| 2906 | Unencrypted Satellite Backhaul | critical | 10.0 | 1 | Data Interception |
| 2907 | Inconsistent authentication | critical | 10.0 | 1 | Data Breach |
| 2908 | CEA-852 Standard Weaknesses | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2909 | Oracle zero-day vulnerability | critical | 10.0 | 1 | Ransomware |
| 2910 | Inadequate cybersecurity frameworks for space-based infrastructure | critical | 10.0 | 1 | Cyber-Physical Threat |
| 2911 | CVE-2026-5027 (Path Traversal) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2912 | Outdated Kentico CMS (unpatched since September 2019) | critical | 10.0 | 1 | Data Breach |
| 2913 | exposed SMB services | critical | 10.0 | 1 | ransomware |
| 2914 | MOVEit Software Vulnerabilities | critical | 10.0 | 1 | Cyber Attack |
| 2915 | Permanent URL Accessibility | critical | 10.0 | 1 | Data Leak |
| 2916 | visibility gaps | critical | 10.0 | 1 | ransomware |
| 2917 | SSRF in Artifactory | critical | 10.0 | 1 | Zero-day exploitation |
| 2918 | CVE-2025-20362 (Cisco ASA/Firepower - Privilege Escalation) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2919 | Path traversal (CVE-2025-64712) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2920 | CVE-2026-19598 (Inadequate file-type and path validation in `EVF_Form_Fields_Upload` class) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2921 | Outdated Junos OS routers | critical | 10.0 | 1 | Espionage |
| 2922 | Lack of Out-of-Band Authentication | critical | 10.0 | 1 | Social Engineering |
| 2923 | Weak access controls, lack of data classification protocols, unencrypted data, unrestricted physical access to devices, absence of audit logs | critical | 10.0 | 1 | Data Leak |
| 2924 | weaknesses in AIS protocol | critical | 10.0 | 1 | spoofing |
| 2925 | Lack of Syslog Forwarding to External Systems | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 2926 | Insecure Withdrawal Locking Mechanism | critical | 10.0 | 1 | Data Breach |
| 2927 | Newly disclosed vulnerabilities | critical | 10.0 | 1 | Botnet, Cyber Espionage |
| 2928 | Default credentials (e.g., Hitachi RTU admin account 'Default') | critical | 10.0 | 1 | Cyberattack (Wiper Malware, Firmware Tampering) |
| 2929 | Exposed NAS devices | critical | 10.0 | 1 | Ransomware |
| 2930 | Compromised Mailing List | critical | 10.0 | 1 | Phishing |
| 2931 | CVE-2023-38831 | critical | 10.0 | 1 | Cyberespionage |
| 2932 | Exposed credentials through configuration API calls | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2933 | Lack of OT Asset Management | critical | 10.0 | 1 | Ransomware |
| 2934 | unauthorized API usage | critical | 10.0 | 1 | AI-driven cyberattack |
| 2935 | CVE-2024-43468 | critical | 10.0 | 1 | SQL Injection |
| 2936 | Transition-Minimized Differential Signaling (TMDS) in HDMI/DVI interfaces | critical | 10.0 | 1 | Data Exfiltration |
| 2937 | CVE-2026-87491 (Chrome V8 zero-day) | critical | 10.0 | 1 | Zero-day exploitation |
| 2938 | OAuth Token Theft | critical | 10.0 | 1 | Data Breach |
| 2939 | Weak vendor credentials | critical | 10.0 | 1 | Data Breach |
| 2940 | over-reliance on vendors | critical | 10.0 | 1 | data breach |
| 2941 | Neterbit routers | critical | 10.0 | 1 | DDoS Attack |
| 2942 | Influence of Radical Literature | critical | 10.0 | 1 | Domestic Terrorism |
| 2943 | Delayed Incident Notification | critical | 10.0 | 1 | Cybersecurity Incident |
| 2944 | Weak Authentication (68% of breaches involve credentials) | critical | 10.0 | 1 | Ransomware |
| 2945 | CVE-2025-52691 (SmarterMail) | critical | 10.0 | 1 | ransomware |
| 2946 | Weak Helpdesk Authentication | critical | 10.0 | 1 | Cyber Extortion |
| 2947 | Outdated accounting infrastructure | critical | 10.0 | 1 | Ransomware |
| 2948 | End-to-End Encryption | critical | 10.0 | 1 | Government Order |
| 2949 | Elasticsearch RCE | critical | 10.0 | 1 | Botnet |
| 2950 | Outdated IT infrastructure, obsolete software (Lotus Notes), aging hardware | critical | 10.0 | 1 | Infrastructure Vulnerability |
| 2951 | Oracle PeopleSoft applications | critical | 10.0 | 1 | Data Breach |
| 2952 | GPS reliance | critical | 10.0 | 1 | GPS spoofing (disputed) |
| 2953 | Poor password hygiene, lack of multi-factor authentication, unsecured third-party services | critical | 10.0 | 1 | Credential Compromise |
| 2954 | Document Management Systems | critical | 10.0 | 1 | Data Theft Extortion |
| 2955 | Customer Edge (CE) routers | critical | 10.0 | 1 | Cyber Espionage |
| 2956 | Unauthorized Cloud Storage | critical | 10.0 | 1 | Data Breach (Alleged) |
| 2957 | Excessive agent authority | critical | 10.0 | 1 | AI-driven breach |
| 2958 | Unpatched Web Applications | critical | 10.0 | 1 | AI-Powered Cyberattack |
| 2959 | Input validation bypass in MWEB transactions | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 2960 | prolonged lapses in security oversight | critical | 10.0 | 1 | data breach |
| 2961 | Obfuscated .NET Reactor-protected infostealer, JIT compilation hooking (clrjit.dll!getJit) | critical | 10.0 | 1 | Supply Chain Attack |
| 2962 | Off-by-one error in encryption process | critical | 10.0 | 1 | Ransomware |
| 2963 | Lack of End-to-End Email Encryption | critical | 10.0 | 1 | Data Breach |
| 2964 | Misconfigured OIDC trust relationships | critical | 10.0 | 1 | Supply-Chain Attack |
| 2965 | lack of AIS authentication mechanisms | critical | 10.0 | 1 | sabotage |
| 2966 | Website Security | critical | 10.0 | 1 | Data Breach |
| 2967 | Social Engineering (Impersonation of IT support) | critical | 10.0 | 1 | Ransomware |
| 2968 | CVE-2020-3580 (Cisco) | critical | 10.0 | 1 | ransomware |
| 2969 | CVE-2025-49158 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2970 | Lack of IP Restrictions on Tokens | critical | 10.0 | 1 | Supply Chain Attack |
| 2971 | Immutable Log Gaps in AI Pipelines | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 2972 | CVE-2026-24061 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2973 | Improper handling of BOOTP file field in DHCP server responses (CVE-2026-42511) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2974 | Publicly accessible Raiko SGX enclave signing key on GitHub | critical | 10.0 | 1 | Exploit |
| 2975 | CVE-2025-55182 (React2Shell, CVSS 10.0) | critical | 10.0 | 1 | Web Application Exploitation |
| 2976 | Manual Recovery Reliance | critical | 10.0 | 1 | Supply Chain Attack |
| 2977 | Lack of multi-factor authentication, Lack of encryption | critical | 10.0 | 1 | Data Breach, Ransomware |
| 2978 | CVE-2020-8515 (DrayTek) | critical | 10.0 | 1 | Botnet |
| 2979 | CVE-2026-70426 (SECURITY-3911) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2980 | PetitPotam | critical | 10.0 | 1 | Ransomware |
| 2981 | CVE-2026-59726 (Ruflo MCP) | critical | 10.0 | 1 | Zero-day Exploit |
| 2982 | CVE-2026-20079 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2983 | human error (e.g., clicking malicious links) | critical | 10.0 | 1 | phishing |
| 2984 | Social engineering (MFA bypass via Teams screen-sharing) | critical | 10.0 | 1 | Espionage |
| 2985 | CVE-2026-64531 (OVSwrap) | critical | 10.0 | 1 | Local Privilege Escalation |
| 2986 | Unpatched Software in Data Centers | critical | 10.0 | 1 | Cyber Espionage |
| 2987 | Remote Disabling Capability | critical | 10.0 | 1 | Repurposing of Commercial Technology for Military Use |
| 2988 | CVE-2026-5140 | critical | 10.0 | 1 | Privilege Escalation |
| 2989 | CVE-2022-35733 | critical | 10.0 | 1 | Botnet, DDoS, IoT Exploitation |
| 2990 | Palo Alto vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2991 | Google Docs | critical | 10.0 | 1 | Data Leak |
| 2992 | template injection in dataset configuration | critical | 10.0 | 1 | AI-driven cyber attack |
| 2993 | Lack of VPN, multifactor authentication (MFA), and poor access controls | critical | 10.0 | 1 | Data Breach |
| 2994 | Password reminder bug | critical | 10.0 | 1 | Account Takeover |
| 2995 | Malicious PowerPoint Add-Ins | critical | 10.0 | 1 | Cyber Espionage |
| 2996 | unsecured legacy data storage | critical | 10.0 | 1 | fraud |
| 2997 | Unspecified CVEs identified via Shodan/Censys scans | critical | 10.0 | 1 | Research Study |
| 2998 | poor network segmentation (IT/OT convergence) | critical | 10.0 | 1 | ransomware |
| 2999 | CVE-2025-60021 (Inadequate input validation in Apache bRPC heap profiler endpoint) | critical | 10.0 | 1 | Remote Command Injection |
| 3000 | Insecure GitHub Actions workflows misclassified as configuration rather than code, enabling untrusted data to carry into high-privilege workflows | critical | 10.0 | 1 | Supply Chain Attack |
| 3001 | CVE-2025-54068 (Laravel Livewire v3 improper validation during hydration process) | critical | 10.0 | 1 | Credential Theft |
| 3002 | GHSA-7xvx-8pf2-pv5g (CVSS 9.1) | critical | 10.0 | 1 | Sandbox Escape Vulnerability |
| 3003 | Misconfigured public repository | critical | 10.0 | 1 | Data Leak |
| 3004 | CVE-2026-20190 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3005 | CVE-2025-60710 | critical | 10.0 | 1 | Ransomware |
| 3006 | Known vulnerability in the email system | critical | 10.0 | 1 | Data Breach |
| 3007 | firewall vulnerabilities | critical | 10.0 | 1 | ransomware |
| 3008 | Hardware Vulnerabilities | critical | 10.0 | 1 | Hardware Vulnerability Exploitation |
| 3009 | Jenkins Script Console | critical | 10.0 | 1 | Botnet |
| 3010 | Improper data classification procedures | critical | 10.0 | 1 | Data Breach |
| 3011 | lack of package verification in CI/CD pipelines | critical | 10.0 | 1 | supply chain attack |
| 3012 | Unburied or Lightly Buried Cables in Steep Terrain | critical | 10.0 | 1 | Physical Sabotage |
| 3013 | SonicWall SSLVPN misconfigurations | critical | 10.0 | 1 | ransomware |
| 3014 | Zero-day vulnerability in Oracle E-Business Suite | critical | 10.0 | 1 | Ransomware |
| 3015 | Poor visibility in cloud/hybrid environments | critical | 10.0 | 1 | Ransomware |
| 3016 | Known vulnerabilities in DNN platform | critical | 10.0 | 1 | Data Breach |
| 3017 | TerraMaster NAS Vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3018 | Passive Storage Component Treatment (Missing Threat Signals) | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 3019 | metadata retention in files | critical | 10.0 | 1 | data breach |
| 3020 | Output Messenger | critical | 10.0 | 1 | Cyberespionage |
| 3021 | End-of-life (EOL) and end-of-support (EOS) Microsoft IIS servers | critical | 10.0 | 1 | Vulnerability Exposure |
| 3022 | Self-Service Password Reset (SSPR) | critical | 10.0 | 1 | Data Exfiltration |
| 3023 | Zero-day vulnerability in GoAnywhere MFT (Managed File Transfer) software | critical | 10.0 | 1 | Data Breach |
| 3024 | Improper authorization/callback handling in V2 vaults | critical | 10.0 | 1 | Exploit |
| 3025 | Design flaw in VSCode’s webview security model (Window.postMessage() API misuse), lack of CSRF protections in github.dev, unrestricted Node.js API access in extensions | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3026 | Weaknesses in SolarWinds' Orion platform | critical | 10.0 | 1 | Supply Chain Attack |
| 3027 | Improper input sanitization in GNU InetUtils telnetd (USER environment variable handling) | critical | 10.0 | 1 | Authentication Bypass |
| 3028 | Data Sharing with Third-Party AI Services | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 3029 | DNS infrastructure | critical | 10.0 | 1 | Cyberattack |
| 3030 | Outdated and vulnerable infrastructure | critical | 10.0 | 1 | State-sponsored cyberattack |
| 3031 | Unauthorized disclosure of SL2000 and SL3000 certificates | critical | 10.0 | 1 | Data Breach |
| 3032 | OAuth Token Misconfiguration | critical | 10.0 | 1 | Data Breach |
| 3033 | Open academic networks | critical | 10.0 | 1 | Data Breach |
| 3034 | Human Trust in Help-Desk Processes | critical | 10.0 | 1 | Cyberattack |
| 3035 | Outdated Fortinet VPNs | critical | 10.0 | 1 | Ransomware |
| 3036 | Undisclosed vulnerabilities in F5 BIG-IP (actively patched but stolen pre-disclosure) | critical | 10.0 | 1 | Supply Chain Compromise |
| 3037 | Known vulnerability in legacy IT infrastructure (unpatched) | critical | 10.0 | 1 | Ransomware, Data Breach |
| 3038 | Cisco VPN vulnerabilities | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 3039 | CVE-2026-63077 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3040 | Vulnerability in widely used utility software | critical | 10.0 | 1 | Cyberattack |
| 3041 | Progress MOVEit transfer systems | critical | 10.0 | 1 | Data Breach |
| 3042 | Internet-connected cameras | critical | 10.0 | 1 | Ransomware, Cyber Espionage, Industrial Sabotage |
| 3043 | Legitimate features of Signal | critical | 10.0 | 1 | Phishing |
| 3044 | CVE-2026-35616 (Fortinet flaw) | critical | 10.0 | 1 | Botnet, Cyber Espionage |
| 3045 | weak MFA implementations (Evilginx tool) | critical | 10.0 | 1 | ransomware |
| 3046 | Unpatched Domain Controllers (Privilege Escalation Flaw, April 2025) | critical | 10.0 | 1 | Data Breach |
| 3047 | CVE-2025-20337 | critical | 10.0 | 1 | Remote Code Execution |
| 3048 | Novel method | critical | 10.0 | 1 | Ransomware |
| 3049 | Delayed Threat Response | critical | 10.0 | 1 | Operational Risk |
| 3050 | CVE-2025-64328 | critical | 10.0 | 1 | Webshell Deployment |
| 3051 | CVE-2026-53435 | critical | 10.0 | 1 | Deserialization Vulnerability |
| 3052 | Human Trust in Job Recruitment Schemes, Supply Chain Compromise (npm Packages) | critical | 10.0 | 1 | Cyberespionage, Cryptocurrency Theft, Malware Deployment |
| 3053 | Unsecured devices and networks | critical | 10.0 | 1 | Ransomware |
| 3054 | Improper GitHub Access Controls | critical | 10.0 | 1 | Supply Chain Attack |
| 3055 | Error by a third-party contractor | critical | 10.0 | 1 | Data Breach |
| 3056 | CVE-2025-31324 (unspecified CRM/DBMS/SaaS target) | critical | 10.0 | 1 | Cybercriminal Alliance Formation |
| 3057 | Compromised contractor credentials (specific vulnerability undisclosed) | critical | 10.0 | 1 | Data Breach |
| 3058 | CVE-2026-24423 | critical | 10.0 | 1 | Ransomware |
| 3059 | Insufficient Integration Lifecycle Management | critical | 10.0 | 1 | Supply Chain Attack |
| 3060 | authentication_bypass_flaw | critical | 10.0 | 1 | ransomware |
| 3061 | Unauthorized access to Tetra mobile device signals, lack of robust signal authentication | critical | 10.0 | 1 | Radio Signal Spoofing |
| 3062 | Ivanti Cloud Service Appliances | critical | 10.0 | 1 | Supply Chain Attack |
| 3063 | Trivy | critical | 10.0 | 1 | Ransomware |
| 3064 | Exposed secrets in S3 buckets and CI/CD environments, overly permissive cloud permissions | critical | 10.0 | 1 | Cloud Intrusion |
| 3065 | CVE-2026-55200 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3066 | Obfuscation Techniques | critical | 10.0 | 1 | Malware Infection |
| 3067 | unsecured_API | critical | 10.0 | 1 | ransomware |
| 3068 | Cloud Misconfigurations (23% of cloud incidents) | critical | 10.0 | 1 | Ransomware |
| 3069 | Lack of Browser-Specific Security Controls | critical | 10.0 | 1 | Browser-Based Attack |
| 3070 | Microsoft 365 authorization flows | critical | 10.0 | 1 | Phishing |
| 3071 | Cloud access keys | critical | 10.0 | 1 | AI-driven cyberattack |
| 3072 | Absence of AI Governance Frameworks | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 3073 | Misconfiguration of the project’s main smart contract | critical | 10.0 | 1 | Cryptocurrency Heist |
| 3074 | Third-party library bug in Google Chrome | critical | 10.0 | 1 | Zero-Day Exploit |
| 3075 | Log4j (CVE-2021-44228) | critical | 10.0 | 1 | ransomware |
| 3076 | Abuse of Legitimate Tools (BITSAdmin) | critical | 10.0 | 1 | Targeted Attack |
| 3077 | Social engineering (malicious link disguised as system error) | critical | 10.0 | 1 | Data Breach |
| 3078 | Vulnerable drivers (BYOVD), misused legitimate software, obfuscation techniques (VX Crypt, VMProtect, control-flow flattening) | critical | 10.0 | 1 | Ransomware |
| 3079 | abuse of elevated privileges post-compromise (e.g., Trend Vision One uninstaller) | critical | 10.0 | 1 | ransomware |
| 3080 | Weak Passwords (WordPress Admin Accounts) | critical | 10.0 | 1 | Influence Operation |
| 3081 | CVE-2026-34910 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3082 | Weaknesses in multi-vendor, containerized architectures with strict timing constraints | critical | 10.0 | 1 | Side-Channel Attack |
| 3083 | Improper escaping of LangChain’s internal marker key during serialization | critical | 10.0 | 1 | Serialization/Deserialization Injection |
| 3084 | Deception of AI safeguards (simulated security test pretext) | critical | 10.0 | 1 | Ransomware |
| 3085 | Zero-day vulnerability (claimed by Qilin) | critical | 10.0 | 1 | Ransomware |
| 3086 | Lack of Third-Party Supplier Accountability | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 3087 | API misconfiguration | critical | 10.0 | 1 | Data Breach |
| 3088 | Untrusted forked code in CI/CD pipelines | critical | 10.0 | 1 | Supply Chain Attack |
| 3089 | Modified Files on Server | critical | 10.0 | 1 | Data Breach |
| 3090 | Unspecified vulnerability in third-party call center platform (linked to Salesforce customer management instances) | critical | 10.0 | 1 | Data Breach |
| 3091 | CVE-2025-66376 (Stored XSS in Zimbra Collaboration) | critical | 10.0 | 1 | Espionage |
| 3092 | CVE-2026-10702 (Firefox JIT) | critical | 10.0 | 1 | Zero-day Exploit |
| 3093 | Unpatched VPN services | critical | 10.0 | 1 | Ransomware |
| 3094 | Publicly Accessible Executive Profiles (for AI Phishing) | critical | 10.0 | 1 | Supply Chain Attack |
| 3095 | xfrm-ESP Page-Cache Write | critical | 10.0 | 1 | Local Privilege Escalation (LPE) |
| 3096 | CVE-2026-7473 | critical | 10.0 | 1 | Zero-Day Exploit |
| 3097 | Liquidity Token Contracts | critical | 10.0 | 1 | Cyberattack |
| 3098 | Unauthenticated Reboot Commands | critical | 10.0 | 1 | Vulnerability Disclosure |
| 3099 | CVE-2024-24919 | critical | 10.0 | 1 | Ransomware |
| 3100 | CVE-2026-81963 (Windows Update Stack) | critical | 10.0 | 1 | Zero-day exploitation |
| 3101 | Lateral Movement via Salesforce OAuth | critical | 10.0 | 1 | Supply Chain Attack |
| 3102 | Kernel compromise | critical | 10.0 | 1 | Espionage |
| 3103 | Delayed access revocation for terminated employees | critical | 10.0 | 1 | Data Breach, Unauthorized Access, Data Deletion |
| 3104 | SAP Solution Manager | critical | 10.0 | 1 | Cyber Espionage |
| 3105 | Known flaws in outdated software | critical | 10.0 | 1 | Ransomware |
| 3106 | Zero-day | critical | 10.0 | 1 | Ransomware |
| 3107 | CVE-2026-59774 (GHSA-6v53-hr58-556r) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3108 | Exposed SonicWall SSL VPN without Multi-Factor Authentication (MFA) | critical | 10.0 | 1 | Ransomware |
| 3109 | CVE-2024-21887 (Ivanti Connect Secure/Policy Secure) | critical | 10.0 | 1 | Ransomware |
| 3110 | Weak Password Hashing (Early Breaches like LinkedIn 2012) | critical | 10.0 | 1 | Data Breach |
| 3111 | CVE-2024-54085 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3112 | Missing Function-Level Access Control (CWE-639) | critical | 10.0 | 1 | Unauthorized Access |
| 3113 | CVE-2026-20127 | critical | 10.0 | 1 | Authentication Bypass |
| 3114 | Lack of Real-Time Identity Data Sync | critical | 10.0 | 1 | Identity Security Crisis |
| 3115 | Funding constraints | critical | 10.0 | 1 | Data Breach |
| 3116 | Trust in technical support specialists | critical | 10.0 | 1 | Data Breach |
| 3117 | Exposed Boot Guard private keys | critical | 10.0 | 1 | Security Breach |
| 3118 | NoPac | critical | 10.0 | 1 | Ransomware |
| 3119 | Sinkclose vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3120 | Budget Constraints | critical | 10.0 | 1 | Operational Risk |
| 3121 | Compromised administrative accounts (26 user accounts, including admin-level) | critical | 10.0 | 1 | Ransomware Attack |
| 3122 | Lack of Rate-Limiting | critical | 10.0 | 1 | Data Breach |
| 3123 | Web server vulnerability | critical | 10.0 | 1 | Data Breach |
| 3124 | Browser Fetch API abuse via Service Workers (CVE not specified) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3125 | Token replay vulnerability | critical | 10.0 | 1 | Data Breach |
| 3126 | outdated IT infrastructure | critical | 10.0 | 1 | data breach |
| 3127 | Reduced Workforce Capacity | critical | 10.0 | 1 | Operational Risk |
| 3128 | Gaps in Endpoint Detection and Response (EDR) | critical | 10.0 | 1 | Domain Hijacking |
| 3129 | Microsoft Exchange (unspecified CVEs) | critical | 10.0 | 1 | ransomware |
| 3130 | CVE-2025-42999 | critical | 10.0 | 1 | vulnerability |
| 3131 | Unauthorized Admin Role Assignments | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 3132 | CVE-2025-23320 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3133 | CVE-2024-* (Buffer manipulation in NTFS disk image handling) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3134 | BootROM keys extraction | critical | 10.0 | 1 | Data Breach / Unauthorized Access |
| 3135 | CVE-2020-3259 (Cisco) | critical | 10.0 | 1 | ransomware |
| 3136 | CVE-2026-24135 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3137 | Email reply-chain exploitation | critical | 10.0 | 1 | Phishing |
| 3138 | CVE-2024-28000 (WordPress LiteSpeed Cache plugin) | critical | 10.0 | 1 | Data Breach |
| 3139 | No AI-Enabled Identity Threat Detection | critical | 10.0 | 1 | Identity Security Crisis |
| 3140 | CVE-2024-21410 (Privilege Escalation), CVE-2024-21413 | critical | 10.0 | 1 | Zero-Day Exploit |
| 3141 | Insufficient IT resources | critical | 10.0 | 1 | Cyberattack |
| 3142 | Lack of real-time detection for initial intrusion (May 14 to August 24) | critical | 10.0 | 1 | Ransomware Attack |
| 3143 | high_risk_assessment_ignored | critical | 10.0 | 1 | data_at_risk |
| 3144 | Social Engineering (Disguised as Legitimate npm Package) | critical | 10.0 | 1 | Malware Campaign |
| 3145 | Untrusted data deserialization in LeRobot's PolicyServer | critical | 10.0 | 1 | Phishing |
| 3146 | Recently discovered vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 3147 | Weak Authentication for Publish Access (npm, PyPI) | critical | 10.0 | 1 | Supply Chain Attack |
| 3148 | macOS Backdoor | critical | 10.0 | 1 | State-Backed Surveillance & Hacking |
| 3149 | CVE (CVSS 9.7) - Lack of origin validation, authentication tokens, and CORS protections in WebSocket listener | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3150 | CVE-2026-12569 (Improper Input Validation, CVSS 9.3) | critical | 10.0 | 1 | Ransomware |
| 3151 | ScreenConnect flaws | critical | 10.0 | 1 | ransomware |
| 3152 | Typosquatting | critical | 10.0 | 1 | Cyber Theft |
| 3153 | DeFi infrastructure weaknesses (historical) | critical | 10.0 | 1 | cyber theft |
| 3154 | Manual Redaction Errors | critical | 10.0 | 1 | Data Leak |
| 3155 | Network infiltration | critical | 10.0 | 1 | Security Concerns |
| 3156 | Lack of identity controls | critical | 10.0 | 1 | AI-driven breach |
| 3157 | Lack of validation check in ReceiverAxelar contract | critical | 10.0 | 1 | Smart Contract Exploit |
| 3158 | Unencrypted and unprotected data accessible on the network | critical | 10.0 | 1 | Data Breach, Ransomware |
| 3159 | Weak Authentication (compromised social media accounts) | critical | 10.0 | 1 | Cyber Theft |
| 3160 | Default/Weak Admin Credentials | critical | 10.0 | 1 | Data Breach |
| 3161 | Unauthorized transaction approvals | critical | 10.0 | 1 | Security Breach |
| 3162 | Previously unknown vulnerability in file-sharing system | critical | 10.0 | 1 | Ransomware Attack |
| 3163 | Security Vulnerabilities in Verizon’s Web site | critical | 10.0 | 1 | Data Breach |
| 3164 | CVE-2026-50752 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 3165 | CVE-2026-8037 | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 3166 | human error (weakness in operational security) | critical | 10.0 | 1 | cyber theft |
| 3167 | Marimo Notebook vulnerabilities | critical | 10.0 | 1 | AI-driven cyberattack |
| 3168 | CVE-2026-16723 (Fastjson 1.x) | critical | 10.0 | 1 | Zero-day Exploit |
| 3169 | CVE-2026-47301 (Microsoft SCCM) | critical | 10.0 | 1 | ransomware |
| 3170 | Telesquare vulnerabilities | critical | 10.0 | 1 | Botnet |
| 3171 | Improper Access Controls (Shared Credentials) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 3172 | Outdated network infrastructure | critical | 10.0 | 1 | Data Breach |
| 3173 | CVE-2025-69264 (CVSS 8.8) | critical | 10.0 | 1 | Supply Chain Attack |
| 3174 | kernel-level access via vulnerable driver | critical | 10.0 | 1 | ransomware |
| 3175 | CVE-2026-32746 (Buffer Overflow - CWE-120) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3176 | Weak passwords, lack of two-factor authentication (2FA) | critical | 10.0 | 1 | Ransomware |
| 3177 | Lack of Multi-Factor Authentication (MFA) for remote hires | critical | 10.0 | 1 | Espionage |
| 3178 | React2Shell vulnerability in React frontend application | critical | 10.0 | 1 | Data Breach |
| 3179 | Undocumented n-day vulnerability | critical | 10.0 | 1 | APT Attack |
| 3180 | Misconfigured Azure RBAC permissions | critical | 10.0 | 1 | Data Exfiltration |
| 3181 | Collateral valuation mechanism in decentralized lending protocols | critical | 10.0 | 1 | Price Manipulation Attack |
| 3182 | Misconfigured private APN | critical | 10.0 | 1 | OT Breach |
| 3183 | Vulnerability in Huawei routers' VRP network operating system | critical | 10.0 | 1 | Cyberattack |
| 3184 | Citrix device vulnerabilities (specific CVE not disclosed) | critical | 10.0 | 1 | Cyberattack |
| 3185 | CVE-2026-21902 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 3186 | Flaw in CI/CD pipeline | critical | 10.0 | 1 | Supply-Chain Attack |
| 3187 | weak credential management (golden ticket risk) | critical | 10.0 | 1 | ransomware |
| 3188 | CVE-2025-0921, CVE-2024-7587 | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 3189 | CVE-2025-21590 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 3190 | CVE-2025-43200 | critical | 10.0 | 1 | Spyware |
| 3191 | PoisonX kernel driver (BYOVD attack) | critical | 10.0 | 1 | Ransomware |
| 3192 | Oracle E-Business Suite (EBS) exploit (unspecified) | critical | 10.0 | 1 | potential data breach |
| 3193 | Known Exploited Vulnerabilities (CISA Catalog) | critical | 10.0 | 1 | System Intrusion |
| 3194 | Drupal core security flaw (unspecified) | critical | 10.0 | 1 | Vulnerability |
| 3195 | Infostealer malware infection, lack of multi-factor authentication, static security question, unchanged default credentials | critical | 10.0 | 1 | Unauthorized Access |
| 3196 | Lack of Advanced DNS Monitoring | critical | 10.0 | 1 | Domain Hijacking |
| 3197 | AI voice cloning limitations | critical | 10.0 | 1 | social engineering |
| 3198 | CVE-2026-63093 (Cursor IDE binary planting) | critical | 10.0 | 1 | ransomware |
| 3199 | AI guardrail bypass | critical | 10.0 | 1 | AI-powered cyberattack |
| 3200 | SQL Injection in Main Application | critical | 10.0 | 1 | Data Breach |
| 3201 | aging IT systems | critical | 10.0 | 1 | data breach |
| 3202 | supply-chain weakness | critical | 10.0 | 1 | data breach |
| 3203 | Third-party software (Famly) used by Kido nursery chain | critical | 10.0 | 1 | ransomware |
| 3204 | Mobile device and app security weaknesses | critical | 10.0 | 1 | Cyber Espionage |
| 3205 | Human error (help desk staff tricked into resetting credentials) | critical | 10.0 | 1 | Cyberattack |
| 3206 | Oracle Cloud Infrastructure Flaw (from March 2025 breach) | critical | 10.0 | 1 | Data Breach |
| 3207 | Over-Privileged Accounts | critical | 10.0 | 1 | Data Breach |
| 3208 | Reused passwords from previous breaches | critical | 10.0 | 1 | Data Breach |
| 3209 | CVE-2026-35273 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 3210 | Customer Accounts | critical | 9.0 | 1 | Credential Stuffing |
| 3211 | Sophos Firewall versions 18.5 MR3 (18.5.3) | critical | 9.0 | 1 | Vulnerability Exploitation |
| 3212 | Multiple vulnerabilities in Cisco Small Business RV Series routers | critical | 9.0 | 1 | Vulnerability Exploitation |
| 3213 | Weak or Stolen Login Credentials | critical | 9.0 | 1 | Data Breach |
| 3214 | Misplaced Portable Flash Drive | critical | 9.0 | 1 | Data Breach |
| 3215 | Past Data Breach | critical | 9.0 | 1 | Phishing Campaign |
| 3216 | Unauthorized Access by Terminated Employee | critical | 9.0 | 1 | Data Breach |
| 3217 | Lack of authentication controls | critical | 9.0 | 1 | Data Exposure |
| 3218 | Charting software | critical | 9.0 | 1 | Ransomware |
| 3219 | File Transfer Service Provider | critical | 9.0 | 1 | Data Breach |
| 3220 | Accellion FTA server vulnerability | critical | 9.0 | 1 | Data Breach |
| 3221 | Human Error (Misaddressed Email) | critical | 8.5 | 1 | Data Breach (Phishing / Unauthorized Disclosure) |
| 3222 | Critical vulnerability | critical | 8.5 | 1 | Data Breach, Account Hijacking |
| 3223 | Checkout page code issue | critical | 8.5 | 1 | Data Breach |
| 3224 | Insufficient access controls, disabled security measures | critical | 8.5 | 1 | Data Breach, Election Security Tampering |
| 3225 | Insufficient Monitoring of EHR Access | critical | 8.5 | 1 | Data Breach |
| 3226 | Unauthorized access due to unverified data-sharing requests | critical | 8.5 | 1 | Data Breach |
| 3227 | Weak incident response plans | critical | 8.5 | 1 | Data exfiltration |
| 3228 | CVE-2026-12935 (Stack-based buffer overflow in RTSP connection tracking module) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3229 | CVE-2025-60727 (Out-of-bounds read condition - CWE-125) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3230 | CVE-2026-73324 | critical | 8.5 | 1 | Heap Out-of-Bounds Write |
| 3231 | Lack of execution isolation | critical | 8.5 | 1 | AI-driven attack |
| 3232 | Confidential Virtual Machine (CVM) exploitation | critical | 8.5 | 1 | Zero-day vulnerability |
| 3233 | Zero-day vulnerability in third-party software platform | critical | 8.5 | 1 | Data Breach |
| 3234 | CVE-2026-19478 | critical | 8.5 | 1 | Code Injection |
| 3235 | Deceptive imposter commit via attacker-controlled fork | critical | 8.5 | 1 | Supply Chain Attack |
| 3236 | Third-party vulnerability | critical | 8.5 | 1 | Data Breach |
| 3237 | Out-of-bounds read (Grassroot DICOM) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3238 | RxGK subsystem flaw in `rxgk_decrypt_skb()` function (Linux kernel) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3239 | Weak Third-party Security | critical | 8.5 | 1 | Data Breach |
| 3240 | mDNS Misconfiguration | critical | 8.5 | 1 | Misconfiguration |
| 3241 | CVE-2025-47813 (CWE-209) | critical | 8.5 | 1 | Information Disclosure |
| 3242 | Vulnerability in e-commerce portal | critical | 8.5 | 1 | Data Breach |
| 3243 | CVE-2025-43300 (Apple OS-level vulnerability) | critical | 8.5 | 1 | Zero-day vulnerability |
| 3244 | Unauthenticated Access | critical | 8.5 | 1 | Data Breach |
| 3245 | inadequate validation of third-party services (Cloudflare Pages) | critical | 8.5 | 1 | phishing |
| 3246 | OAuth device authorization abuse | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 3247 | CVE-2026-69836 (Microsoft Entra ID) | critical | 8.5 | 1 | Data Breach |
| 3248 | Progress Software's MOVEit File Transfer solution | critical | 8.5 | 1 | Data Breach |
| 3249 | CVE-2026-78175 (CVSS 8.8) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3250 | CVE-2026-45659 (Improper deserialization of untrusted data) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3251 | Legacy file-transfer software vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3252 | CVE-2026-53565 | critical | 8.5 | 1 | Privilege Escalation |
| 3253 | Human Error (Employee Susceptibility to Social Engineering) | critical | 8.5 | 1 | Data Breach (Social Engineering) |
| 3254 | CVE-2026-68820 (Use-after-free in Windows Ancillary Function Driver for WinSock - AFD) | critical | 8.5 | 1 | Privilege Escalation |
| 3255 | Okta SSO page vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3256 | Citrix Software Vulnerability (unspecified) | critical | 8.5 | 1 | Data Breach |
| 3257 | CVE-2025-51683 (Blind SQL Injection) | critical | 8.5 | 1 | SQL Injection |
| 3258 | Misconfiguration in Salesforce environment, lack of least privilege principle, absence of Zero Trust architecture, inadequate behavioral monitoring | critical | 8.5 | 1 | Data Breach |
| 3259 | Social Engineering, Impersonation of Legitimate Services | critical | 8.5 | 1 | Phishing |
| 3260 | Coldcard hardware wallet firmware vulnerability | critical | 8.5 | 1 | Cryptocurrency Theft |
| 3261 | Compromised third-party OAuth integration | critical | 8.5 | 1 | Data Breach |
| 3262 | Free for Teacher environment vulnerability in Canvas LMS | critical | 8.5 | 1 | Data Breach |
| 3263 | weak security protocols | critical | 8.5 | 1 | Data Breach |
| 3264 | CVE-2026-63093 | critical | 8.5 | 1 | Binary Planting Vulnerability |
| 3265 | Procedural weakness in verifying government data requests | critical | 8.5 | 1 | Data Breach |
| 3266 | User execution of malicious Terminal commands, Lack of macOS Gatekeeper enforcement for script-based payloads | critical | 8.5 | 1 | Malware Distribution |
| 3267 | CVE-2025-27889 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3268 | Flawed email verification process in Lenovo IDs and lack of secondary authentication for new SSO logins in Dropbox | critical | 8.5 | 1 | Unauthorized Access |
| 3269 | Impersonation Feature in Employee Portals | critical | 8.5 | 1 | Data Exposure |
| 3270 | Default remote user account, no-password accounts, unsecured 'superuser' account | critical | 8.5 | 1 | Misconfiguration |
| 3271 | npm run dev execution | critical | 8.5 | 1 | Supply Chain Attack |
| 3272 | Social Engineering (Fake VPN Software), Lack of User Awareness | critical | 8.5 | 1 | Credential Theft |
| 3273 | OPENROWSET (file-level exfiltration) | critical | 8.5 | 1 | Data Exfiltration |
| 3274 | Inherited permissions from privileged users | critical | 8.5 | 1 | Data Breach |
| 3275 | Inadequate data retention/deletion policies | critical | 8.5 | 1 | Data Breach Risk |
| 3276 | CVE-2023-43000 (WebKit RCE - terrorbird) | critical | 8.5 | 1 | Exploit Kit / Malware Campaign |
| 3277 | iCloud+ Hide My Email feature flaw | critical | 8.5 | 1 | Data Exposure |
| 3278 | Weak or reused passwords, lack of multi-factor authentication | critical | 8.5 | 1 | Credential Stuffing |
| 3279 | Unencrypted Computers | critical | 8.5 | 1 | Data Breach |
| 3280 | Flaw in online portal allowing unauthorized access to personal annual benefit statements (ABS) | critical | 8.5 | 1 | Data Breach |
| 3281 | Gateway between the airline and a payment processor | critical | 8.5 | 1 | Data Breach |
| 3282 | Poor credential management | critical | 8.5 | 1 | Unauthorized Access |
| 3283 | Improper access controls on PDF-generating page | critical | 8.5 | 1 | Data Exposure |
| 3284 | CVE-2025-5775 | critical | 8.5 | 1 | Reconnaissance |
| 3285 | CVE-2026-26133 | critical | 8.5 | 1 | Cross-Prompt Injection Attack (XPIA) |
| 3286 | A setting within one of Petco's software applications that inadvertently allowed certain files to be accessible online | critical | 8.5 | 1 | Data Breach |
| 3287 | CVE-2026-39875 | critical | 8.5 | 1 | Local Privilege Escalation |
| 3288 | Lack of visibility into employee AI tool usage | critical | 8.5 | 1 | Data Leakage |
| 3289 | Verbose error messages exposing OAuth 2.0 bearer tokens | critical | 8.5 | 1 | Phishing, Data Theft, Persistent Access |
| 3290 | Legacy email protocols (IMAP/POP3) | critical | 8.5 | 1 | Data Breach |
| 3291 | eCompli application vulnerability | critical | 8.5 | 1 | Data Breach |
| 3292 | Stolen Usernames and Passwords | critical | 8.5 | 1 | Data Breach |
| 3293 | High-severity vulnerability in ADSelfService Plus software | critical | 8.5 | 1 | Vulnerability Exploit |
| 3294 | Human error, lack of centralized IT control, decentralized IT departments | critical | 8.5 | 1 | Data Breach |
| 3295 | Unauthorized data transmission via third-party trackers | critical | 8.5 | 1 | Data Breach |
| 3296 | Bypass of tool allowlisting under --yolo mode | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3297 | Compromised shipping contractors | critical | 8.5 | 1 | Phishing |
| 3298 | Lack of multi-factor authentication (MFA) on file-transfer services (ShareFile, OwnCloud, Nextcloud) | critical | 8.5 | 1 | Data Breach |
| 3299 | CVE-2026-27728 | critical | 8.5 | 1 | Command Injection |
| 3300 | Internal Glitch | critical | 8.5 | 1 | Data Exposure |
| 3301 | untested incident response plans | critical | 8.5 | 1 | ransomware |
| 3302 | Trusted developer workflows, npm package installation (no user interaction required) | critical | 8.5 | 1 | Supply-Chain Attack, Malware Campaign |
| 3303 | Software vulnerability in the online shop portal | critical | 8.5 | 1 | Data Breach |
| 3304 | Signature-coverage gap in Steam’s installation workflow (failure to validate caller-controlled installation root path) | critical | 8.5 | 1 | Privilege Escalation |
| 3305 | Misconfigured domain-based safe sender exclusions | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 3306 | CVE-2026-87491 (Out-of-bounds write in V8 JavaScript engine) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3307 | CVE-2025-61884 (CVSS 7.5 - Information Disclosure in Runtime UI) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3308 | CVE-2026-0234 (Improper Verification of Cryptographic Signature - CWE-347) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3309 | Compromised WooCommerce, PrestaShop, Magento, and WordPress installations; fake Google Tag Manager (GTM) snippet injection | critical | 8.5 | 1 | Magecart, Payment Card Skimming |
| 3310 | Cryptographic Flaw in Infineon Microcontroller | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 3311 | CVE-2024-3210 | critical | 8.5 | 1 | Data Breach |
| 3312 | Race conditions in merge request approval rules | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3313 | Insecure Direct Object Reference (Sapphos API) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3314 | Insufficient Third-Party Vendor Security | critical | 8.5 | 1 | Data Breach |
| 3315 | Lack of Timely Incident Reporting | critical | 8.5 | 1 | Data Breach |
| 3316 | Weak Access Controls (Absent MFA, Insufficient Lockout Policies) in SonicWall SSLVPN | critical | 8.5 | 1 | Ransomware |
| 3317 | Unspecified vulnerability in Oracle EBS | critical | 8.5 | 1 | Data Breach |
| 3318 | Excessive permissions, hidden app functionality, cloud service abuse (Firebase, Google Apps Script, Telegram, Google Drive) | critical | 8.5 | 1 | Malware (Remote Access Trojan - RAT) |
| 3319 | CVE-2025-41115 (Improper Mapping of SCIM 'externalId' to Internal 'user.uid') | critical | 8.5 | 1 | Vulnerability |
| 3320 | CVE-2026-29146 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3321 | Weak Internal Access Controls | critical | 8.5 | 1 | Data Breach |
| 3322 | Exposed management services | critical | 8.5 | 1 | Credential Theft |
| 3323 | Auto-installation of GX Mods without user interaction | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3324 | Shared authentication key across all KARR devices | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3325 | Full takeover of Tesla’s infotainment system | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 3326 | Misuse of partner-managed repository credentials | critical | 8.5 | 1 | Data Breach |
| 3327 | Compromised OAuth app linked to Google Workspace | critical | 8.5 | 1 | Data Breach |
| 3328 | Inadequate security protections | critical | 8.5 | 1 | Data Breach / Cybersecurity Failure |
| 3329 | Kademlia-based P2P Network | critical | 8.5 | 1 | Zero-day Exploitation |
| 3330 | Weak incident response policies and procedures | critical | 8.5 | 1 | Data Breach |
| 3331 | First Party Authentication (FPA) v2 Exploitation | critical | 8.5 | 1 | API Vulnerability |
| 3332 | CVE-2025-7850 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3333 | Native-messaging bridges, forged Chrome Secure Preferences, enterprise policies | critical | 8.5 | 1 | Malicious Browser Extension |
| 3334 | Weak backend protections, unrestricted API access, lack of follower consent requirements | critical | 8.5 | 1 | Data Exposure |
| 3335 | Incorrect authorization (Lovable, CVE-2025-48757) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 3336 | Weaknesses in university authentication processes | critical | 8.5 | 1 | Data Breach |
| 3337 | Unauthorized access to cloud-based file-sharing application | critical | 8.5 | 1 | Data Breach |
| 3338 | Gemini Search Personalization Model (Prompt Injection via Browsing History) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3339 | Human error, limited cybersecurity resources | critical | 8.5 | 1 | Data Breach |
| 3340 | CVE-2025-68664 | critical | 8.5 | 1 | Data Exfiltration |
| 3341 | Contact Discovery Mechanism Flaw | critical | 8.5 | 1 | Privacy Violation |
| 3342 | Unsecured Kafka Broker instance | critical | 8.5 | 1 | Data Exposure |
| 3343 | Absence of Visibility/Monitoring Tools | critical | 8.5 | 1 | Data Leakage |
| 3344 | Over-Permissioned OAuth Applications, Exposed Credentials, Weak Monitoring of Environment Variables | critical | 8.5 | 1 | OAuth Abuse, Credential Theft, Lateral Movement |
| 3345 | Click2Gov online payment system | critical | 8.5 | 1 | Data Breach |
| 3346 | Unauthorized access to cloud system | critical | 8.5 | 1 | Data Exposure |
| 3347 | CVE-2026-1592 | critical | 8.5 | 1 | Supply Chain Attack |
| 3348 | Vulnerability in third-party software library | critical | 8.5 | 1 | Data Breach |
| 3349 | User trust in online platforms | critical | 8.5 | 1 | Phishing |
| 3350 | CVE-2025-43509, Plaintext Token Storage, Lack of Token Validation, Weak Keychain Access Controls | critical | 8.5 | 1 | Data Breach, Privilege Escalation, Denial-of-Service (DoS) |
| 3351 | Delayed activation and obfuscation in VS Code extensions | critical | 8.5 | 1 | Credential Theft |
| 3352 | CVE-2026-77846 | critical | 8.5 | 1 | JSONPath Injection Vulnerability |
| 3353 | Weak Password ('123456') | critical | 8.5 | 1 | Data Breach |
| 3354 | Gaps in safeguarding technical identifiers under the IAB Europe Transparency and Consent Framework (TCF) | critical | 8.5 | 1 | Data Exposure |
| 3355 | Third-party outsourcing vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3356 | Over-collection of sensitive PII (e.g., full ID scans vs. minimal verification) | critical | 8.5 | 1 | Data Breach Risk |
| 3357 | Human Error (Employee Susceptibility to Phishing) | critical | 8.5 | 1 | Data Breach |
| 3358 | Cloud Infrastructure Security | critical | 8.5 | 1 | Cyberattack |
| 3359 | Unprotected personal data in financial/healthcare systems | critical | 8.5 | 1 | Identity Theft |
| 3360 | CVE-2026-32475 | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3361 | MOVEit Transfer application vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3362 | CVE-2026-84115 (CWE-269: Improper Privilege Management) | critical | 8.5 | 1 | Privilege Escalation |
| 3363 | Access Control Mechanisms | critical | 8.5 | 1 | Data Breach |
| 3364 | Context Poisoning in AI Conversation History | critical | 8.5 | 1 | Data Breach |
| 3365 | Improper sanitization of authorization URLs in n8n | critical | 8.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 3366 | Unauthorized administrative access | critical | 8.5 | 1 | Data Leak |
| 3367 | Lack of API Key Ownership Validation | critical | 8.5 | 1 | Data Exfiltration |
| 3368 | CVE-2025-0520 (ShowDoc) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3369 | Unauthorized access to Salesforce instance | critical | 8.5 | 1 | Data Breach |
| 3370 | Compromised maintainer account (atiertant) | critical | 8.5 | 1 | Supply Chain Attack |
| 3371 | Improper validation of key descriptions in the CIFs.Spnego key type (logic flaw between Linux kernel’s CIFS client and cifs-utils package) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3372 | NULL Pointer Dereference | critical | 8.5 | 1 | Privilege Escalation |
| 3373 | Publicly accessible profile information | critical | 8.5 | 1 | Data Scraping |
| 3374 | CVE-2025-49596 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3375 | outdated software (13 months without updates) | critical | 8.5 | 1 | data breach |
| 3376 | Vulnerability in GoAnywhere file transfer platform | critical | 8.5 | 1 | Data Breach |
| 3377 | Hardcoded API Keys in Public Repositories and Websites | critical | 8.5 | 1 | Data Exposure |
| 3378 | Misconfiguration in Electron framework | critical | 8.5 | 1 | Security Vulnerability |
| 3379 | CVE-2021-39935 | critical | 8.5 | 1 | Server-Side Request Forgery (SSRF) |
| 3380 | CVE-2026-49157 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3381 | Tracking code sharing data with third-party advertisers | critical | 8.5 | 1 | Data Breach |
| 3382 | Legitimate sender reputations (SPF, DKIM, IP-based filters bypass) | critical | 8.5 | 1 | Account Hijacking |
| 3383 | Inadequate security measures, lack of authentication tokens | critical | 8.5 | 1 | Data Breach |
| 3384 | Exposed .git directories with sensitive data in version history | critical | 8.5 | 1 | Data Exposure |
| 3385 | CVE-2026-54121 | critical | 8.5 | 1 | AI Security Breach |
| 3386 | Supply chain compromise via NPM packages | critical | 8.5 | 1 | Supply Chain Attack |
| 3387 | Juniper PTX router RCE flaw | critical | 8.5 | 1 | APT Activity |
| 3388 | CVE-2026-28277 (Unsafe msgpack deserialization) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3389 | CVE-2026-42530 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3390 | Third-party data breaches | critical | 8.5 | 1 | Identity Theft |
| 3391 | Unsecured Data Transfer Methods | critical | 8.5 | 1 | Insider Threat |
| 3392 | limited cybersecurity resources | critical | 8.5 | 1 | data breach |
| 3393 | CVE-2025-30247 (OS Command Injection in My Cloud UI) | critical | 8.5 | 1 | Vulnerability |
| 3394 | MOVEit application by IBM | critical | 8.5 | 1 | Data Breach |
| 3395 | CVE-2026-20643 (WebKit Navigation API improper input validation) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3396 | Default credentials accepted | critical | 8.5 | 1 | Data Exposure |
| 3397 | Weak or Stolen OAuth Token Management (External App Connection to Salesforce) | critical | 8.5 | 1 | Data Breach |
| 3398 | Transaction Front-running | critical | 8.5 | 1 | Security Breach |
| 3399 | Cisco Unified Communications Manager (CM) bug | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3400 | Inadequate Data Redaction | critical | 8.5 | 1 | Data Breach |
| 3401 | CVE-2026-39987 (CVSS 9.3) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3402 | Memory address mapping manipulation via DDR4 interposer | critical | 8.5 | 1 | Supply Chain Attack |
| 3403 | CVE-2026-26980 (SQL Injection in Ghost CMS) | critical | 8.5 | 1 | SQL Injection, Malware Campaign |
| 3404 | CVE-2025-22231 | critical | 8.5 | 1 | Vulnerability |
| 3405 | Lack of Multi-Factor Authentication (MFA) (inferred) | critical | 8.5 | 1 | Data Breach |
| 3406 | Network Segmentation Protocols | critical | 8.5 | 1 | Data Breach |
| 3407 | CVE-2026-27913 (Improper Input Validation - CWE-20) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3408 | PHP Backdoor in WordPress Plugins | critical | 8.5 | 1 | Data Breach |
| 3409 | CVE-2026-40361 (Use-after-free bug in Outlook’s email rendering engine) | critical | 8.5 | 1 | Zero-Click Remote Code Execution (RCE) |
| 3410 | Reuse of compromised credentials | critical | 8.5 | 1 | Credential Stuffing |
| 3411 | Inadequate data retention and access controls for customer order details | critical | 8.5 | 1 | Data Exposure |
| 3412 | Inability to Distinguish Content from Directives in Prompts | critical | 8.5 | 1 | Data Exfiltration |
| 3413 | CVE-2026-5281 (Use-after-free in Dawn GPU abstraction layer) | critical | 8.5 | 1 | Zero-Day Exploitation |
| 3414 | Publicly exposed RPC endpoint lacking authentication, rate limiting, or permission checks | critical | 8.5 | 1 | Supply Chain Attack |
| 3415 | Lack of Physical Security for Devices Containing Sensitive Data | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 3416 | CWE-269: Improper Privilege Management | critical | 8.5 | 1 | Data Exposure |
| 3417 | Lack of encryption in pager network transmissions | critical | 8.5 | 1 | Data Breach |
| 3418 | Lack of verification processes | critical | 8.5 | 1 | Scam, Phishing, Fraud |
| 3419 | Server-Side Request Forgery (SSRF) via Bing’s image search endpoint | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3420 | Reused passwords from third-party data leaks | critical | 8.5 | 1 | Data Breach |
| 3421 | Weak encryption in data-sharing mandates | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 3422 | Delayed breach detection | critical | 8.5 | 1 | Data Breach |
| 3423 | Silverlight | critical | 8.5 | 1 | Cyber Attack |
| 3424 | CVE-2026-21876 | critical | 8.5 | 1 | vulnerability |
| 3425 | CVE-2026-33826 (Improper Input Validation - CWE-20) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3426 | CVE-2026-41613 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3427 | CVE-2025-1724 | critical | 8.5 | 1 | Authentication Vulnerability |
| 3428 | MOVEit file transfer tool | critical | 8.5 | 1 | Data Breach |
| 3429 | CVE-2026-25089 | critical | 8.5 | 1 | Data Breach |
| 3430 | Human Error (Misconfigured Email Distribution List) | critical | 8.5 | 1 | Data Breach (Unintentional Disclosure) |
| 3431 | Personal Information Exposure | critical | 8.5 | 1 | Account Hijacking, Data Theft, Sextortion |
| 3432 | Notification data retention flaw in iOS | critical | 8.5 | 1 | Privacy Flaw / Data Retention Vulnerability |
| 3433 | Absence of web application firewall (WAF) | critical | 8.5 | 1 | Data Security Audit |
| 3434 | Mirasvit flaw in Magento servers | critical | 8.5 | 1 | Third-Party Risk Management Failure |
| 3435 | Listable Algolia Search Indexes (PII Exposure) | critical | 8.5 | 1 | Data Exposure |
| 3436 | misconfiguration in HR/finance team servers | critical | 8.5 | 1 | ransomware |
| 3437 | Compromised JavaScript library (trackpoint-async.js) | critical | 8.5 | 1 | Supply-Chain Attack |
| 3438 | VMware Aria Operations | critical | 8.5 | 1 | APT Activity |
| 3439 | CVE-2024-40766 (SonicWall Improper Access Control) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3440 | Undisclosed vulnerabilities | critical | 8.5 | 1 | Zero-day exploitation |
| 3441 | Misconfigured or repurposed API keys (e.g., Google Maps keys used for Gemini access) | critical | 8.5 | 1 | API Key Exploitation |
| 3442 | Third-party oversight failures | critical | 8.5 | 1 | Data Breach |
| 3443 | Insecure facial recognition databases, Lack of encryption, Third-party vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3444 | CVE-2026-6687 (exFAT label-length stack overflow) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3445 | Session cookies | critical | 8.5 | 1 | Data Breach |
| 3446 | Unauthorized access to internal systems | critical | 8.5 | 1 | Data Breach, Extortion |
| 3447 | CVE-2025-55232 (Microsoft HPC Pack RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3448 | lack of encryption and authentication (non-password-protected database) | critical | 8.5 | 1 | data exposure |
| 3449 | AMPScript/SSJS template injection | critical | 8.5 | 1 | Data Breach |
| 3450 | CVE-2026-45504 | critical | 8.5 | 1 | SSRF (Server-Side Request Forgery) |
| 3451 | WebTransport | critical | 8.5 | 1 | Privacy Bypass |
| 3452 | CVE-2026-42980 (Integer underflow in Windows NT Kernel) | critical | 8.5 | 1 | Privilege Escalation |
| 3453 | hardcoded credentials in source code | critical | 8.5 | 1 | data breach |
| 3454 | CVE-2026-65638 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3455 | CVE-2021-24917 (GiveWP) | critical | 8.5 | 1 | ransomware |
| 3456 | Cloud Database Platform | critical | 8.5 | 1 | Data Breach |
| 3457 | CVE-2024-13496 | critical | 8.5 | 1 | SQL Injection |
| 3458 | Vulnerabilities in online quote tools | critical | 8.5 | 1 | data breach |
| 3459 | CVE-2026-2285 | critical | 8.5 | 1 | Remote Code Execution |
| 3460 | Broken object-level authorization (BOLA) (40%) | critical | 8.5 | 1 | API Security Breach |
| 3461 | Compromised legitimate email account (Italian government email system) | critical | 8.5 | 1 | Data Breach |
| 3462 | Stolen Login Information | critical | 8.5 | 1 | Data Breach |
| 3463 | user trust in legitimate-looking emails/websites | critical | 8.5 | 1 | spear-phishing |
| 3464 | Unsecured AWS bucket | critical | 8.5 | 1 | Data Breach |
| 3465 | Oracle platform vulnerability | critical | 8.5 | 1 | Data Breach |
| 3466 | Lack of input sanitization in AI agents parsing GitHub content | critical | 8.5 | 1 | Indirect Prompt-Injection Vulnerability |
| 3467 | CVE-2026-19478 (GitLab) | critical | 8.5 | 1 | Data Breach |
| 3468 | CVE-2026-20204 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3469 | Outdated or poorly secured API interfaces | critical | 8.5 | 1 | Data Breach |
| 3470 | CVE-2026-85103 (Check Point VPN) | critical | 8.5 | 1 | AI-driven cyberattack |
| 3471 | Social Engineering (Trust in Brand, Urgency) | critical | 8.5 | 1 | Phishing |
| 3472 | Insecure APIs | critical | 8.5 | 1 | Data Breach |
| 3473 | MOVEit file transfer platform | critical | 8.5 | 1 | Data Breach |
| 3474 | SharePoint Server (CVE-2026-56164) | critical | 8.5 | 1 | ransomware |
| 3475 | Unauthorized access to shared network drive | critical | 8.5 | 1 | Data Breach |
| 3476 | CW1226324 (Copilot DLP bypass) | critical | 8.5 | 1 | AI Integration Bug |
| 3477 | Generic Out-of-Bounds Read/Write in C/C++ (e.g., unchecked array indexing, `strcpy` overflows) | critical | 8.5 | 1 | Memory Corruption |
| 3478 | compromised user devices (suspected) | critical | 8.5 | 1 | data breach (unverified) |
| 3479 | Operational security lapse (SSH authentication key reuse across servers) | critical | 8.5 | 1 | phishing |
| 3480 | Branch Predictor Race Conditions (BPRC) in Intel Processors (Speculative Execution Side Channel) | critical | 8.5 | 1 | Hardware Vulnerability |
| 3481 | Inadequate protection of sensitive data | critical | 8.5 | 1 | Data Breach |
| 3482 | CVE-2026-11374 | critical | 8.5 | 1 | Account Takeover |
| 3483 | CVE-2026-20230 | critical | 8.5 | 1 | Ransomware |
| 3484 | Lack of Content Verification Mechanisms | critical | 8.5 | 1 | Content Theft and Fraud |
| 3485 | Client-side vulnerabilities | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 3486 | Website Vulnerabilities | critical | 8.5 | 1 | Data Leak |
| 3487 | Legitimate Microsoft 365 device-code authentication feature | critical | 8.5 | 1 | Phishing-as-a-Service, Business Email Compromise (BEC) |
| 3488 | Phishing vulnerabilities | critical | 8.5 | 1 | Scam, Phishing, Fraud |
| 3489 | Incremental features and customizations accumulating risk, lack of proper access controls | critical | 8.5 | 1 | Misconfiguration |
| 3490 | Social engineering, 2FA bypass via credential harvesting | critical | 8.5 | 1 | Phishing |
| 3491 | Improper TLS Certificate Validation (CWE-295) | critical | 8.5 | 1 | Vulnerability |
| 3492 | CVE-2026-8452 (Improper restriction of operations within a memory buffer, CWE-119) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3493 | Publicly accessible sensitive data | critical | 8.5 | 1 | Data Exposure |
| 3494 | Customer inadvertent disclosure of credentials | critical | 8.5 | 1 | Data Breach |
| 3495 | Browser extension permissions and network traffic interception | critical | 8.5 | 1 | Data Theft |
| 3496 | Unsecured public Wi-Fi networks | critical | 8.5 | 1 | Credential Theft |
| 3497 | identity relationship exposures | critical | 8.5 | 1 | identity-based attack |
| 3498 | Predictable passwords (e.g., team names with numbers or capital letters) | critical | 8.5 | 1 | Data Breach |
| 3499 | CVE-2026-4048 | critical | 8.5 | 1 | vulnerability |
| 3500 | Improper handling of IPv6 extension headers in Comodo Internet Security | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3501 | CVE-2025-3102 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3502 | Unauthorized use of Stripe API key | critical | 8.5 | 1 | Data Breach |
| 3503 | CVE-2015-2051 (D-Link Dir-645) | critical | 8.5 | 1 | Exploit Trends |
| 3504 | Legacy system vulnerability | critical | 8.5 | 1 | Data Breach |
| 3505 | Reused passwords across multiple accounts | critical | 8.5 | 1 | Credential Stuffing |
| 3506 | Mishandled private keys in AI-generated JavaScript | critical | 8.5 | 1 | Data Breach |
| 3507 | Abandoned email domains of financial administrators | critical | 8.5 | 1 | Data Breach |
| 3508 | improper access controls / misconfigured storage | critical | 8.5 | 1 | data exposure |
| 3509 | MongoDB database vulnerability | critical | 8.5 | 1 | Data Breach |
| 3510 | CVE-2024-3177 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3511 | CVE-2025-14847 (Improper handling of length parameter inconsistency, CWE-130) | critical | 8.5 | 1 | Memory-Read Vulnerability |
| 3512 | Social Engineering, Lack of Multi-Factor Authentication (MFA) awareness | critical | 8.5 | 1 | Phishing, Credential Harvesting |
| 3513 | 15 security flaws in graphics drivers, including nine high-severity vulnerabilities | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3514 | Lack of Encryption on Portable Device | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 3515 | Authentication bypass in Passwordstate Emergency Access (CVE pending) | critical | 8.5 | 1 | Authentication Bypass Vulnerability |
| 3516 | CVE-2026-21514 (CWE-807) | critical | 8.5 | 1 | Security Feature Bypass |
| 3517 | Improper disposal of hardware containing sensitive data | critical | 8.5 | 1 | Data Breach (Physical/Improper Disposal) |
| 3518 | Lack of authentication and access controls in Firebase instances | critical | 8.5 | 1 | Data Breach |
| 3519 | Abuse of trusted cloud platforms (GitHub Pages, SheetBest), lack of multi-factor authentication, social engineering | critical | 8.5 | 1 | Phishing |
| 3520 | FortiOS 7.2.x | critical | 8.5 | 1 | Exploit Sale |
| 3521 | ADB Pairing | critical | 8.5 | 1 | Banking Malware |
| 3522 | CVE-2026-1591 | critical | 8.5 | 1 | Supply Chain Attack |
| 3523 | Inadequate audit logging | critical | 8.5 | 1 | Data Breach |
| 3524 | E-commerce Website | critical | 8.5 | 1 | Data Breach |
| 3525 | Heap-based buffer overflow (CVE-2026-69449) | critical | 8.5 | 1 | Vulnerability |
| 3526 | Trusted domain chaining, search engine trust exploitation | critical | 8.5 | 1 | Phishing |
| 3527 | CVE-2020-17103 | critical | 8.5 | 1 | Privilege Escalation |
| 3528 | Weaknesses in lock systems | critical | 8.5 | 1 | Hardware vulnerability |
| 3529 | CVE-2025-31191 | critical | 8.5 | 1 | Sandbox Escape Vulnerability |
| 3530 | Incorrect data validation protocols | critical | 8.5 | 1 | Data Exposure |
| 3531 | Several vulnerabilities in the Likud app | critical | 8.5 | 1 | Data Breach |
| 3532 | configuration gap in Amazon S3 server | critical | 8.5 | 1 | data breach |
| 3533 | Unencrypted HTTP update mechanism in FireAnt MetaKit | critical | 8.5 | 1 | Supply-chain attack |
| 3534 | unsecured teacher credentials | critical | 8.5 | 1 | unauthorized access |
| 3535 | AirSnitch (exploits gaps in MAC address, encryption key, and IP address linking across network layers) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3536 | CVE-2024-XXXX (Oracle PeopleSoft Environment Management remote code execution flaw) | critical | 8.5 | 1 | Data Breach |
| 3537 | Predictable local storage of credentials | critical | 8.5 | 1 | Infostealer Malware |
| 3538 | unauthorized data upload to external platform | critical | 8.5 | 1 | data breach |
| 3539 | SolarWinds Serv-U flaw | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3540 | MOVEit Transfer environment vulnerability | critical | 8.5 | 1 | Data Breach |
| 3541 | SIM swapping | critical | 8.5 | 1 | wire fraud |
| 3542 | CVE-2025-37899 (Use-After-Free in ksmbd SMB2 LOGOFF handler) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3543 | Feature flag misconfiguration (Split.io-based system) | critical | 8.5 | 1 | Data Exposure |
| 3544 | Web application vulnerability (Click2Gov online payment system) | critical | 8.5 | 1 | Data Breach |
| 3545 | Lack of AI-Specific Security Controls | critical | 8.5 | 1 | Supply Chain Attack |
| 3546 | Lack of Email Spoofing Protections | critical | 8.5 | 1 | Data Breach |
| 3547 | Sanctioned Platform Persistence | critical | 8.5 | 1 | Surveillance |
| 3548 | Absence of phishing-resistant MFA | critical | 8.5 | 1 | Data Breach |
| 3549 | Compromised GitHub Tokens | critical | 8.5 | 1 | Identity Compromise |
| 3550 | Ability to self-apply for admin privileges on the FIA Driver Categorisation portal | critical | 8.5 | 1 | data breach |
| 3551 | CVE-Pending (CamoLeak: Copilot Chat's parsing of invisible markdown + Camo image-proxy exfiltration) | critical | 8.5 | 1 | Data Exfiltration |
| 3552 | Zero-click indirect prompt injection (*PleaseFix*) | critical | 8.5 | 1 | AI Prompt Injection |
| 3553 | Exploitation of accessibility permissions, fake overlays | critical | 8.5 | 1 | Trojan |
| 3554 | Critical CVEs | critical | 8.5 | 1 | Identity Compromise |
| 3555 | Weak hiring verification, lack of device authenticity checks | critical | 8.5 | 1 | Insider Threat |
| 3556 | CVE-2026-0073 (Android Debug Bridge daemon - adbd) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3557 | Human Error (Employee Mistake) | critical | 8.5 | 1 | Data Breach |
| 3558 | CVE-2026-53566 | critical | 8.5 | 1 | Privilege Escalation |
| 3559 | CVE-2026-82079 (Stack-Based Buffer Overflow) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3560 | Insecure handling of pseudonymous identifiers in TCF ecosystem | critical | 8.5 | 1 | Data Exposure |
| 3561 | Ease of onboarding and business-grade tools in fintech platforms, hybrid account functionality | critical | 8.5 | 1 | Financial Fraud, Money Laundering, Phishing |
| 3562 | Inadequate safeguards | critical | 8.5 | 1 | Data Breach |
| 3563 | Technical Issue with Third-Party Service Provider | critical | 8.5 | 1 | Data Breach |
| 3564 | Secure file transfer software | critical | 8.5 | 1 | Data Breach |
| 3565 | CVE-2026-24301 (CoSnitch) | critical | 8.5 | 1 | Data Exfiltration |
| 3566 | Improper access control in cloud storage | critical | 8.5 | 1 | Data Breach |
| 3567 | CWE-352: Cross-Site Request Forgery (CSRF) (via API manipulation) | critical | 8.5 | 1 | Data Breach |
| 3568 | CVE-2026-26111 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3569 | CVE-2018-25270 (ThinkPHP) | critical | 8.5 | 1 | Exploit Trends |
| 3570 | Network-connected systems | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 3571 | Social Engineering, Fake Authentication Screens | critical | 8.5 | 1 | Phishing |
| 3572 | previously_compromised_data | critical | 8.5 | 1 | data_breach |
| 3573 | Unspecified zero-day in FreePBX (versions 16 and 17 with endpoint module installed) | critical | 8.5 | 1 | Zero-day exploitation |
| 3574 | CVE-2025-1080 | critical | 8.5 | 1 | Remote Code Execution |
| 3575 | CVE-2026-21533 | critical | 8.5 | 1 | Elevation of Privilege |
| 3576 | CVE-2026-53412 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3577 | Privilege Escalation Flaw in FIA Driver Categorisation Website | critical | 8.5 | 1 | Data Breach |
| 3578 | CVE-2025-71260 | critical | 8.5 | 1 | Malware Distribution |
| 3579 | Android Debug Bridge (ADB) Pairing | critical | 8.5 | 1 | Malware (Banking Trojan) |
| 3580 | Unauthorized access to a third-party data processor | critical | 8.5 | 1 | Data Breach |
| 3581 | Unverified execution of README instructions by AI coding agents | critical | 8.5 | 1 | Semantic Injection |
| 3582 | CVE-2026-45585, CERT/CC VU#226679 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3583 | Lack of encryption, plaintext password storage, default passwords, no access restrictions or detection mechanisms | critical | 8.5 | 1 | Data Breach |
| 3584 | CVE-2026-9080 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3585 | CVE-2026-1237 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3586 | Oracle EBS zero-day flaw | critical | 8.5 | 1 | Data Breach |
| 3587 | Wireshark 4.6.8 Parsers | critical | 8.5 | 1 | Data Breach |
| 3588 | Reused usernames, weak security questions, password reuse | critical | 8.5 | 1 | Data Breach |
| 3589 | Lack of Data Encryption in University Advancement Database | critical | 8.5 | 1 | Data Breach |
| 3590 | Over-Permissive Third-Party App Access (Gmail, Google Drive, Dropbox) | critical | 8.5 | 1 | Data Breach |
| 3591 | Setting turned on by Patient Portal vendor | critical | 8.5 | 1 | Data Breach |
| 3592 | Overly permissive guest-user configurations in Salesforce Experience Cloud and ServiceNow portals | critical | 8.5 | 1 | Data Theft |
| 3593 | Progress Software's MOVEit secure file transfer tool | critical | 8.5 | 1 | Data Breach |
| 3594 | Inadequate acceptable use policies for AI | critical | 8.5 | 1 | Data Leakage |
| 3595 | Insufficient access controls / Policy violation | critical | 8.5 | 1 | Unauthorized Access / Data Breach |
| 3596 | Lack of Network Segmentation in Cloud | critical | 8.5 | 1 | Cloud Security Breach |
| 3597 | CVE-2025-68686 (Information Exposure - CWE-200) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3598 | Adobe Campaign Classic maximum-severity vulnerability | critical | 8.5 | 1 | Data Breach |
| 3599 | Unauthorized access due to exposed credentials | critical | 8.5 | 1 | Data Breach |
| 3600 | CVE-2025-15629 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3601 | Insufficient safeguards to prevent unauthorized access | critical | 8.5 | 1 | Data Breach |
| 3602 | MOVEit Transfer Server Vulnerability | critical | 8.5 | 1 | Data Breach |
| 3603 | Inadequate safeguards in government online portals | critical | 8.5 | 1 | Credential Stuffing |
| 3604 | WooCommerce website vulnerabilities, third-party script injection | critical | 8.5 | 1 | Magecart (Digital Skimming) |
| 3605 | Notepad++ WinGUp Update Verification Flaw | critical | 8.5 | 1 | Supply Chain Attack |
| 3606 | Malicious code in online store | critical | 8.5 | 1 | Data Breach |
| 3607 | CVE-2026-8451 | critical | 8.5 | 1 | Memory Disclosure Vulnerability Exploitation |
| 3608 | CVE (not specified) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3609 | Delayed account recovery processes | critical | 8.5 | 1 | Account Hijacking |
| 3610 | Poorly secured platform | critical | 8.5 | 1 | Data Breach |
| 3611 | Chrome’s App-Bound Encryption | critical | 8.5 | 1 | Malware |
| 3612 | CVE-2026-15975 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3613 | Software misconfiguration exposing files to the internet | critical | 8.5 | 1 | Data Breach |
| 3614 | Social Engineering (Fake CAPTCHA/Anti-Bot Prompt) | critical | 8.5 | 1 | Malware Campaign |
| 3615 | NPM Dependencies | critical | 8.5 | 1 | Malware Deployment |
| 3616 | Unverified JWT payload | critical | 8.5 | 1 | Vulnerability Exploit |
| 3617 | GHSA-wpqr-6v78-jr5g (workspace trust bypass, tool allowlisting bypass, improper input validation, OS command injection) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3618 | Recently patched vulnerability in Oracle E-Business Suite (for Cl0p ransomware incident) | critical | 8.5 | 1 | Data Breach |
| 3619 | Remote Work Vulnerabilities (COVID-19 Exploitation) | critical | 8.5 | 1 | Data Breach |
| 3620 | CVE-2025-61984 (Inadequate filtering of control characters in usernames for ProxyCommand in OpenSSH) | critical | 8.5 | 1 | Vulnerability |
| 3621 | Unsecured Backups | critical | 8.5 | 1 | Fraud |
| 3622 | Timing Attack via Rendering Pipeline | critical | 8.5 | 1 | Data Theft |
| 3623 | Shopping cart portions of the company's websites | critical | 8.5 | 1 | Data Breach |
| 3624 | CVE-2017-3881 (Cluster Management Protocol RCE in Cisco IOS/IOS XE) | critical | 8.5 | 1 | unauthorized access |
| 3625 | Windows’ Restart Manager (RstrtMgr.dll) exploitation for disabling security processes | critical | 8.5 | 1 | Potentially Unwanted Application (PUA) |
| 3626 | Inadequate security measures, potential internal mismanagement | critical | 8.5 | 1 | Data Breach |
| 3627 | CVE-2026-23595 | critical | 8.5 | 1 | Privilege Escalation |
| 3628 | Fractured auditability across communication channels | critical | 8.5 | 1 | Data Governance Blind Spot |
| 3629 | CVE-2025-14560 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3630 | SureTriggers Vulnerability | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3631 | Salesforce environment access | critical | 8.5 | 1 | Data Breach |
| 3632 | Vulnerability in SonicWall firewall | critical | 8.5 | 1 | Data Breach |
| 3633 | Docker MCP Gateway RCE | critical | 8.5 | 1 | Supply Chain Attack |
| 3634 | Abuse of Microsoft 365 mailbox rules and Outlook features | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 3635 | CVE-2025-48561 | critical | 8.5 | 1 | Data Theft |
| 3636 | CVE-2026-6683 (exFAT divide-by-zero) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3637 | Outdated cryptographic practices | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 3638 | Incomplete deployment steps (live /install/install.php page), lack of reinstallation safeguards, server-side session state storage | critical | 8.5 | 1 | Security Misconfiguration |
| 3639 | Abuse of Wallpaper Engine’s 'application' wallpaper type to execute arbitrary code | critical | 8.5 | 1 | Malware Campaign |
| 3640 | Health Information Exchange (HIE) platform misconfiguration | critical | 8.5 | 1 | Data Breach |
| 3641 | Lack of access controls, default admin permissions, unmanaged AI-driven applications | critical | 8.5 | 1 | Data Exposure |
| 3642 | Lack of segmentation between IT and operational systems | critical | 8.5 | 1 | Data Breach |
| 3643 | Email and SharePoint account access | critical | 8.5 | 1 | Data Breach |
| 3644 | Trust in community integrations, lack of sandboxing in n8n community nodes | critical | 8.5 | 1 | Supply Chain Attack |
| 3645 | LegacyHive (MSNightmare) - User Profile Service (ProfSvc) race condition | critical | 8.5 | 1 | Privilege Escalation |
| 3646 | insufficient workforce training | critical | 8.5 | 1 | ransomware |
| 3647 | Internet-exposed SSH (port 22 open to 0.0.0.0/0), Overly permissive IAM roles | critical | 8.5 | 1 | Cryptomining Attack |
| 3648 | CVE-2017-7921 | critical | 8.5 | 1 | Espionage |
| 3649 | GitHub Actions OIDC tokens, trusted publishing subversion | critical | 8.5 | 1 | Supply Chain Attack |
| 3650 | Absence of authentication tokens | critical | 8.5 | 1 | Data Breach |
| 3651 | No Technical Vulnerability (Human Factor) | critical | 8.5 | 1 | Trade Secret Theft |
| 3652 | Publicly accessible cloud storage | critical | 8.5 | 1 | Credential Theft |
| 3653 | Policy/Procedural Failure | critical | 8.5 | 1 | Data Breach |
| 3654 | CVE-2026-34486 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3655 | Potential Configuration Flaws in Shared Platforms (e.g., Salesforce-like systems) | critical | 8.5 | 1 | Data Breach |
| 3656 | Insufficient Behavioral Monitoring for Authorized Users | critical | 8.5 | 1 | Data Breach |
| 3657 | lack of security risk analysis | critical | 8.5 | 1 | ransomware |
| 3658 | CVE-2026-4798 (CVSS 7.5) | critical | 8.5 | 1 | SQL Injection |
| 3659 | Accidental source code leak (Claude Code) | critical | 8.5 | 1 | Malware Distribution |
| 3660 | Impersonation of legitimate Go module (*golang.org/x/crypto*) | critical | 8.5 | 1 | Supply-Chain Attack |
| 3661 | Misconfigured Stravito Access (Internal Documents) | critical | 8.5 | 1 | Data Exposure |
| 3662 | Endpoint Detection and Response (EDR) Services | critical | 8.5 | 1 | Ransomware Attack |
| 3663 | CVE-2025-59145 (Invisible Markdown Comment Syntax Abuse) | critical | 8.5 | 1 | Data Exfiltration |
| 3664 | SMS phishing (smishing) attack | critical | 8.5 | 1 | Data Breach |
| 3665 | System update flaw (October 2023) | critical | 8.5 | 1 | Data Exposure |
| 3666 | CVE-2026-41241 | critical | 8.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 3667 | CVE-2026-42824 (Parameter-to-Prompt Injection, HTML Injection Race Condition, SSRF via Bing) | critical | 8.5 | 1 | Data Exfiltration |
| 3668 | Insecure device adoption processes (predictable serial numbers, default credentials, unauthenticated temporary download links) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3669 | AcroForms, FlateDecode (PDF features), abuse of legitimate cloud services (Vercel Blob storage) | critical | 8.5 | 1 | Phishing |
| 3670 | Compromised package versions (2.6.0, 2.6.1, 2.6.2) | critical | 8.5 | 1 | Supply Chain Attack |
| 3671 | lack of multi-signature validation for critical operations | critical | 8.5 | 1 | blockchain exploit |
| 3672 | Lack of access controls and encryption | critical | 8.5 | 1 | Data Breach |
| 3673 | Compromised Salesforce integrations, Zendesk customer support system | critical | 8.5 | 1 | Data Breach |
| 3674 | Lack of encryption in radio communications used by public health systems | critical | 8.5 | 1 | Data Breach |
| 3675 | CVE-2025-9290 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3676 | Third-party data handling vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3677 | CVE-2025-67644 | critical | 8.5 | 1 | Data Exfiltration |
| 3678 | CVE-2026-20320 (XXE Injection, CWE-611) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3679 | Three separate flaws in Automotive Grade Linux | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 3680 | CVE-2025-20333 & CVE-2025-20363 (Cisco ASA VPN) | critical | 8.5 | 1 | Ransomware |
| 3681 | CVE-2026-20184 (CWE-295) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3682 | Computer Virus | critical | 8.5 | 1 | Data Breach |
| 3683 | CVE-2026-29191 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3684 | Security vulnerability in a third-party service provider | critical | 8.5 | 1 | Cyberattack |
| 3685 | CVE-2026-48294 (Universal Cross-Site Scripting - UXSS) | critical | 8.5 | 1 | Data Breach |
| 3686 | Vulnerability in Progress Software Corporation's MOVEit Transfer product | critical | 8.5 | 1 | Data Breach |
| 3687 | CVE-2025-33229 | critical | 8.5 | 1 | Vulnerability |
| 3688 | Unauthorized access via subcontractor credentials | critical | 8.5 | 1 | Data Breach |
| 3689 | MOVEit Transfer Critical Vulnerability (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 3690 | Unsecured VPN | critical | 8.5 | 1 | Data Breach |
| 3691 | Password reset flaw via AI chatbot instructions | critical | 8.5 | 1 | Data Breach |
| 3692 | Fundamental trust vulnerability in AI safety guardrails (context-aware manipulation) | critical | 8.5 | 1 | AI Security Vulnerability Exploitation |
| 3693 | Remote code execution vulnerability in Secure Mobile Access (SMA) appliances | critical | 8.5 | 1 | Remote Code Execution |
| 3694 | lack of monitoring | critical | 8.5 | 1 | data breach |
| 3695 | Weak security controls, lack of detection for suspicious login attempts | critical | 8.5 | 1 | Data Breach |
| 3696 | inadequate segmentation between Discord and vendor systems | critical | 8.5 | 1 | data breach |
| 3697 | Supply-chain compromise via malicious dependency | critical | 8.5 | 1 | Supply-Chain Attack |
| 3698 | CVE-2025-71257 | critical | 8.5 | 1 | Malware Distribution |
| 3699 | automated CI/CD pipeline execution | critical | 8.5 | 1 | supply-chain attack |
| 3700 | Lack of Robust Security Controls on Third-Party Platforms | critical | 8.5 | 1 | Data Breach |
| 3701 | inadequate contractor oversight | critical | 8.5 | 1 | data breach |
| 3702 | Unrestricted failed authentication attempts, weak encryption for passwords and resident registration numbers | critical | 8.5 | 1 | Data Breach |
| 3703 | CVE pending (related to 'node-forge' cryptographic signature verification flaw) | critical | 8.5 | 1 | Vulnerability |
| 3704 | Lack of Privacy-Preserving Mechanisms in QML | critical | 8.5 | 1 | Privacy Breach |
| 3705 | Remote-viewing software | critical | 8.5 | 1 | Data Breach |
| 3706 | third-party vendor (Salesforce) security flaw | critical | 8.5 | 1 | data breach |
| 3707 | Identity and Access Management (IAM) Failures | critical | 8.5 | 1 | Data Breach |
| 3708 | Personal devices infected with malware | critical | 8.5 | 1 | Credential Leak |
| 3709 | Automatic execution of npm preinstall scripts | critical | 8.5 | 1 | Supply Chain Attack |
| 3710 | Weak authentication (Dior Instagram) | critical | 8.5 | 1 | Data Breach |
| 3711 | Outdated hashing algorithms (MD5) | critical | 8.5 | 1 | Data Breach |
| 3712 | Improper Authorization (routerd.wificfg_get and routerd.get_rand_key methods) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3713 | Mishandling of sensitive data by workers | critical | 8.5 | 1 | Data Breach |
| 3714 | Unknown system flaws in retail/luxury brand infrastructure | critical | 8.5 | 1 | Data Breach |
| 3715 | Oracle vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3716 | Remote-code execution (RCE) flaw | critical | 8.5 | 1 | Autonomous Hacking Campaign |
| 3717 | Insufficient sanitization in the `serialize` function (CVE-2026-0969) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3718 | Architectural weakness in Google Gemini Enterprise and Vertex AI Search (RAG-based trust boundary exploitation) | critical | 8.5 | 1 | Zero-Click Vulnerability, Indirect Prompt Injection |
| 3719 | Plain text credential storage in memory | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3720 | Browser-saved passwords | critical | 8.5 | 1 | Data Breach |
| 3721 | Web vulnerabilities in Subaru's Starlink service | critical | 8.5 | 1 | Web Vulnerabilities |
| 3722 | Publicly Available Code Repository | critical | 8.5 | 1 | Data Breach |
| 3723 | Password recovery and sharing features | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 3724 | Lack of prompt injection detection | critical | 8.5 | 1 | Data Breach |
| 3725 | Skimming | critical | 8.5 | 1 | Data Breach |
| 3726 | Default Data Retention Policies in LLMs (e.g., OpenAI’s 30-day deletion lag) | critical | 8.5 | 1 | Data Leakage |
| 3727 | CVE-2026-57992 (Use-After-Free in Microsoft Edge’s rendering engine) | critical | 8.5 | 1 | Vulnerability |
| 3728 | Supply chain vulnerability in SaaS integrations | critical | 8.5 | 1 | Extortion-as-a-Service (EaaS) |
| 3729 | Automatic Opt-Ins | critical | 8.5 | 1 | Data Privacy Issue |
| 3730 | Limited IT Infrastructure | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 3731 | CVE-2026-32647 (Out-of-bounds read in ngx_http_mp4_module) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3732 | Signal’s 'linked devices' feature | critical | 8.5 | 1 | Cyber Espionage |
| 3733 | improper data retention by third-party vendor | critical | 8.5 | 1 | data breach |
| 3734 | Failure to implement and maintain reasonable security measures | critical | 8.5 | 1 | Data Breach |
| 3735 | Improper deployment of third-party tracking technologies on public website leading to unauthorized data transfer | critical | 8.5 | 1 | Data Privacy Violation |
| 3736 | Awareness of Medicare data breach | critical | 8.5 | 1 | Phishing/Scam |
| 3737 | AutoConsent JS bridge in DuckDuckGo Android browser (UXSS) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3738 | CVE-2025-13328 | critical | 8.5 | 1 | Information Leak |
| 3739 | Lack of audit and oversight of third-party SDK configurations | critical | 8.5 | 1 | Data Exposure |
| 3740 | CVE-2025-0033 (Race Condition in AMD SEV-SNP RMP Initialization) | critical | 8.5 | 1 | Vulnerability |
| 3741 | Weak password storage (base64 hashes or unhashed passwords) | critical | 8.5 | 1 | Data Breach |
| 3742 | manque de protection des terminaux personnels | critical | 8.5 | 1 | cyberattaque |
| 3743 | SSRF bypasses | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 3744 | Mali GPU Data Compression | critical | 8.5 | 1 | Data Theft |
| 3745 | Insecure Direct Object Reference (IDOR), lack of rate limiting, improper email validation | critical | 8.5 | 1 | Data Exposure |
| 3746 | Docker container escape | critical | 8.5 | 1 | Supply Chain Attack |
| 3747 | Unauthorized access to Salesforce | critical | 8.5 | 1 | Data Breach |
| 3748 | Flaws in passkey synchronization and authentication processes, over-reliance on 'user verified' flag | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3749 | Programming Errors | critical | 8.5 | 1 | Data Breach |
| 3750 | Publicly Accessible Cloud Database | critical | 8.5 | 1 | Data Exposure |
| 3751 | Failure to detect excessive access attempts | critical | 8.5 | 1 | Data Breach |
| 3752 | CVE-2026-85046 (CWE-843) | critical | 8.5 | 1 | Type Confusion Vulnerability |
| 3753 | Android’s accessibility features | critical | 8.5 | 1 | Malware-as-a-Service (MaaS) |
| 3754 | Default Network Access Settings (Pro/Max accounts) | critical | 8.5 | 1 | Data Exfiltration |
| 3755 | User Email Accounts | critical | 8.5 | 1 | Data Breach |
| 3756 | Overprivileged OAuth Tokens | critical | 8.5 | 1 | Data Breach (OAuth Token Compromise) |
| 3757 | CVE-2026-23598 | critical | 8.5 | 1 | Privilege Escalation |
| 3758 | Unpatched vulnerabilities, Unintentional installation of malware by IT personnel with admin privileges | critical | 8.5 | 1 | Supply Chain Attack, Data Breach |
| 3759 | CVE-2026-8932 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3760 | Unauthorized access to secure portal requiring authorized logins | critical | 8.5 | 1 | Data Breach |
| 3761 | Gemini Browsing Tool (Web Page Summarization Data Exfiltration) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3762 | MOVEit Transfer zero-day vulnerability (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 3763 | User Trust in Signature Requests | critical | 8.5 | 1 | DNS Hijacking |
| 3764 | Zero-day vulnerabilities in Microsoft Exchange Server | critical | 8.5 | 1 | Cyberespionage |
| 3765 | CVE-2026-2031 (CVSS 10.0), access control misconfigurations, IDOR, protobuf descriptor leakage | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3766 | CVE-2026-23980 (Improper Neutralization of Special Elements in SQL Commands) | critical | 8.5 | 1 | SQL Injection |
| 3767 | Hard-coded passwords in HTML/APIs | critical | 8.5 | 1 | Unauthorized Access |
| 3768 | DNS prefetching | critical | 8.5 | 1 | Privacy Bypass |
| 3769 | Overly permissive guest user settings in Salesforce Experience Cloud | critical | 8.5 | 1 | Data Harvesting |
| 3770 | Bypassing Google’s *App-Bound Encryption* and endpoint security tools via remote decryption | critical | 8.5 | 1 | Infostealer Malware |
| 3771 | Inadequate security policies, unvetted AI-driven chatbot, lack of robust access controls | critical | 8.5 | 1 | Data Breach |
| 3772 | Plugin4Shell (AI coding assistants) | critical | 8.5 | 1 | AI-driven attack |
| 3773 | Inadequate Third-Party Vetting | critical | 8.5 | 1 | Data Breach |
| 3774 | Android Activity Layering | critical | 8.5 | 1 | Data Theft |
| 3775 | Insufficient sanitization of user input in XML processing | critical | 8.5 | 1 | XML External Entity (XXE) Injection |
| 3776 | Session tokens stored in browsers | critical | 8.5 | 1 | Account Hijacking |
| 3777 | CVE-2025-3648 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3778 | Third-party shopping cart software | critical | 8.5 | 1 | Data Breach |
| 3779 | OTP exfiltration via malicious instructions | critical | 8.5 | 1 | Data Breach |
| 3780 | MOVEit® Secure File Transfer software | critical | 8.5 | 1 | Data Breach |
| 3781 | MOVEit secure file transfer solution vulnerability | critical | 8.5 | 1 | Data Breach |
| 3782 | CVE-2025-12807 (SQL Injection) | critical | 8.5 | 1 | Denial-of-Service |
| 3783 | Lack of Data Minimization in Blockchain Transactions | critical | 8.5 | 1 | Privacy Violation |
| 3784 | Login Page Bug | critical | 8.5 | 1 | Data Breach |
| 3785 | Inadequate encryption, insufficient vendor security vetting | critical | 8.5 | 1 | Data Breach |
| 3786 | Bing SSRF bypass | critical | 8.5 | 1 | Data Exfiltration |
| 3787 | Lack of disclosure and user consent for data collection | critical | 8.5 | 1 | Data Exfiltration |
| 3788 | CVE-2025-15631 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3789 | Insecure Age-Verification System | critical | 8.5 | 1 | Surveillance |
| 3790 | WebKit vulnerability in iCloud Private Relay | critical | 8.5 | 1 | Privacy Vulnerability |
| 3791 | Outdated SCADA systems, integrated IT/OT environment | critical | 8.5 | 1 | Ransomware |
| 3792 | user trust in legitimate cryptocurrency wallet applications | critical | 8.5 | 1 | malware |
| 3793 | Third-Party CRM Security Weaknesses | critical | 8.5 | 1 | Data Breach |
| 3794 | Irreversible Identity Linking in NFT Ownership | critical | 8.5 | 1 | Privacy Violation |
| 3795 | Inadequate User Data Protection | critical | 8.5 | 1 | Data Breach |
| 3796 | Google Tag Manager | critical | 8.5 | 1 | Data Breach |
| 3797 | Legacy encryption | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 3798 | CVE-2026-XXXXX (Local WebSocket Gateway Authentication Bypass) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3799 | Undisclosed flaws (Smallstep step-ca) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3800 | Insufficient identity verification in remote hiring processes, reliance on AI-assisted deception | critical | 8.5 | 1 | Employment Fraud / Identity Theft / Cyber Espionage |
| 3801 | CVE-2026-45447 (heap use-after-free in PKCS#7 signature verification) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3802 | CVE-2026-53409 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3803 | Human Error (Failure to Redact Sensitive Data) | critical | 8.5 | 1 | Data Breach (Unintentional Disclosure) |
| 3804 | CVE-2026-58048 | critical | 8.5 | 1 | Privilege Escalation |
| 3805 | Soliton Systems K.K FileZen | critical | 8.5 | 1 | APT Activity |
| 3806 | human trust in search engine ads | critical | 8.5 | 1 | phishing |
| 3807 | Default public settings in low-code/AI tools | critical | 8.5 | 1 | Data Exposure |
| 3808 | Sending sensitive data in unencrypted emails | critical | 8.5 | 1 | Data Breach |
| 3809 | Improper handling of ACME HTTP-01 challenge paths in Cloudflare WAF | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3810 | Test mode left enabled allowing OTP login via email keyword | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 3811 | Unencrypted USIM keys, plaintext admin credentials, unpatched vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3812 | Password-reset flaws in DMV systems | critical | 8.5 | 1 | Data Breach |
| 3813 | Unpatched flaw (addressed in July 2023 update, additional vulnerabilities patched in October 2023) | critical | 8.5 | 1 | Data Breach |
| 3814 | Postinstall hook abuse, self-dependency trick | critical | 8.5 | 1 | Supply Chain Attack |
| 3815 | Security hole in MOVEit Transfer software | critical | 8.5 | 1 | Ransomware |
| 3816 | Account recovery workflows (password resets, MFA re-enrollment, help-desk recovery requests) | critical | 8.5 | 1 | Identity Breach |
| 3817 | CVE-2026-3098 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3818 | CVE-2025-60727 (Out-of-bounds read, CWE-125) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3819 | Use-after-free in DRM GEM core ioctl (DRM_IOCTL_GEM_CHANGE_HANDLE) | critical | 8.5 | 1 | Privilege Escalation |
| 3820 | Critical security flaw allowing unauthorized 'super admin' account creation | critical | 8.5 | 1 | Data Breach |
| 3821 | CVE-2026-7201 (CVSS 8.8) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3822 | weaknesses in backend systems | critical | 8.5 | 1 | data breach |
| 3823 | Improper Input/Output Sanitization in AI Chatbot (XSS) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3824 | CVE-2025-59451 (Predictable Identifiers) | critical | 8.5 | 1 | Denial-of-Service |
| 3825 | Session management vulnerability in cookie-based authentication | critical | 8.5 | 1 | Authentication Bypass |
| 3826 | CVE-2026-40050 (Path-Traversal) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3827 | CVE-2026-3517 | critical | 8.5 | 1 | vulnerability |
| 3828 | One-click RCE flaw in link handling | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3829 | Compromised contributor credentials, orphan commit in GitHub repository, Sigstore OIDC token abuse | critical | 8.5 | 1 | Supply Chain Attack |
| 3830 | Image-proxy bypass in Proton Mail | critical | 8.5 | 1 | Data Breach |
| 3831 | System weaknesses in generic files | critical | 8.5 | 1 | Data Breach |
| 3832 | Encryption key stored on device | critical | 8.5 | 1 | Data Breach |
| 3833 | Authentication bypass, unknown vulnerabilities in the system | critical | 8.5 | 1 | Data Breach |
| 3834 | CVE-2021-44228 (Log4Shell) | critical | 8.5 | 1 | Exploit Trends |
| 3835 | High-severity flaws | critical | 8.5 | 1 | Zero-day exploitation |
| 3836 | Unauthorized Access to API Key | critical | 8.5 | 1 | Data Breach |
| 3837 | CVE-2026-85046 (Type confusion bug in V8 JavaScript and WebAssembly engine) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3838 | Over-reliance on mutable version tags in CI/CD pipelines, stolen credentials | critical | 8.5 | 1 | Supply Chain Attack |
| 3839 | AWS Trusted Advisor Bypass via S3 Bucket Policy Misconfiguration (Deny Rules for `s3:GetBucketPolicyStatus`, `s3:GetBucketPublicAccessBlock`, `s3:GetBucketAcl`) | critical | 8.5 | 1 | Misconfiguration |
| 3840 | Potential unauthorized access to LDLC's customer database (timing suggests link to LDLC's server breach) | critical | 8.5 | 1 | phishing |
| 3841 | Failure to remediate known vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3842 | CVE-2025-43300 (Image I/O framework - out-of-bounds write) | critical | 8.5 | 1 | Zero-day vulnerability |
| 3843 | Trust in enterprise software (Microsoft Teams), SaaS vulnerabilities | critical | 8.5 | 1 | Phishing/Social Engineering, Malware Deployment |
| 3844 | MOVEit Transfer programme zero-day vulnerability | critical | 8.5 | 1 | Data Breach |
| 3845 | Exposed Elasticsearch Database without Password | critical | 8.5 | 1 | Data Breach |
| 3846 | Lack of regulatory compliance and proper data handling procedures | critical | 8.5 | 1 | Data Breach |
| 3847 | CVE-2025-7775 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3848 | Incorrect privacy settings on public maps | critical | 8.5 | 1 | Data Exposure |
| 3849 | SWIFT system vulnerability | critical | 8.5 | 1 | ATM cash-out fraud |
| 3850 | Session hijacking via stolen MFA-authenticated session cookies, lack of conditional access policies | critical | 8.5 | 1 | Phishing (AiTM) |
| 3851 | Improper Access Control (Publicly Exposed Sensitive Data) | critical | 8.5 | 1 | Data Breach |
| 3852 | Blender’s 'Auto Run Python Scripts' feature | critical | 8.5 | 1 | malware |
| 3853 | Lack of organization-wide two-factor authentication | critical | 8.5 | 1 | Data Breach |
| 3854 | Cardinality-Based Rate Limiting Bypass | critical | 8.5 | 1 | Privacy Violation |
| 3855 | unpatched vulnerabilities in network devices | critical | 8.5 | 1 | ransomware |
| 3856 | Single extracted key bypassing authentication | critical | 8.5 | 1 | Unauthorized Access |
| 3857 | Third-party cloud applications, insufficient detection of anomalous activity | critical | 8.5 | 1 | Data Breach |
| 3858 | Unsecured storage of sensitive data | critical | 8.5 | 1 | Data Breach |
| 3859 | Unauthorized data transmission via third-party integrations | critical | 8.5 | 1 | Data Breach |
| 3860 | Node-trust assumption in SPIFFE/SPIRE workload attestation; manipulation of cgroup metadata | critical | 8.5 | 1 | Identity Compromise |
| 3861 | System Setup Error | critical | 8.5 | 1 | Data Exposure |
| 3862 | Instagram API (alleged) | critical | 8.5 | 1 | Data Scrape / Alleged Breach |
| 3863 | CVE-2025-9291 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3864 | Unsecured AWS bucket with direct file access via backend bug | critical | 8.5 | 1 | Data Exposure |
| 3865 | Stack-based buffer overflow (Libbiosig) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3866 | session tokens | critical | 8.5 | 1 | phishing |
| 3867 | Third-party Cloud Service | critical | 8.5 | 1 | Data Breach |
| 3868 | Weak or default SSH credentials | critical | 8.5 | 1 | Botnet |
| 3869 | Weak multi-factor authentication (MFA) enforcement, password reuse, exposed network edge devices (e.g., Fortinet FortiGate-60E with open ports) | critical | 8.5 | 1 | Credential Stuffing |
| 3870 | Fake Kubernetes tools | critical | 8.5 | 1 | Supply Chain Attack |
| 3871 | malicious CI/CD pipeline injection | critical | 8.5 | 1 | supply-chain attack |
| 3872 | CVE-2026-3061 (Out-of-bounds read in Media component) | critical | 8.5 | 1 | Vulnerability Patch |
| 3873 | Inadequate monitoring of low-volume, time-distributed unauthorized access | critical | 8.5 | 1 | Data Breach |
| 3874 | Unauthorized access by staff | critical | 8.5 | 1 | Data Breach |
| 3875 | Weak verification processes for new user accounts on online gambling platforms | critical | 8.5 | 1 | Fraud Scheme |
| 3876 | Inadequate Data Handling Controls | critical | 8.5 | 1 | Data Breach |
| 3877 | CVE-2026-53411 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3878 | CVE-2026-21519 | critical | 8.5 | 1 | Privilege Escalation |
| 3879 | Plaintext storage of validation_hash | critical | 8.5 | 1 | Data Breach |
| 3880 | Unsecured Data Repositories | critical | 8.5 | 1 | Credential Exposure |
| 3881 | Data Exposure | critical | 8.5 | 1 | Data Leak |
| 3882 | UAC bypass via COM auto-elevation (ICMLuaUtil through cmlua.dll) | critical | 8.5 | 1 | Trojan |
| 3883 | Third-party software flaw (University of Phoenix) | critical | 8.5 | 1 | Data Breach |
| 3884 | WebKit remote code execution (RCE) | critical | 8.5 | 1 | Exploit Kit |
| 3885 | weak phishing detection | critical | 8.5 | 1 | phishing |
| 3886 | Authentication disabled by default in Flask-based API server | critical | 8.5 | 1 | Misconfiguration |
| 3887 | OpenClaw WebSocket API Authentication Bypass | critical | 8.5 | 1 | Supply Chain Attack |
| 3888 | Unique Identification Number Guessing | critical | 8.5 | 1 | Data Breach |
| 3889 | Inadequately secured network (Salesloft) | critical | 8.5 | 1 | Data Breach (Third-Party Vendor Compromise) |
| 3890 | CVE-2025-4366 | critical | 8.5 | 1 | HTTP Request Smuggling |
| 3891 | Human error (social engineering of third-party employee) | critical | 8.5 | 1 | Data Breach |
| 3892 | Unauthorized data sharing via embedded trackers | critical | 8.5 | 1 | Data Privacy Violation |
| 3893 | Implicit trust in internal communications | critical | 8.5 | 1 | Phishing |
| 3894 | CVE-2025-14174 | critical | 8.5 | 1 | Exploit Kit |
| 3895 | Improper handling of technical identifiers | critical | 8.5 | 1 | Data Exposure |
| 3896 | Clickjacking (CWE-1021) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3897 | CVE-2026-22218 (Arbitrary File Read) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3898 | Vulnerability management failures | critical | 8.5 | 1 | Data Breach |
| 3899 | CVE-2025-40778 (Logic Flaw in BIND 9’s Resolver - Bailiwick Principle Violation) | critical | 8.5 | 1 | Vulnerability |
| 3900 | Improper FOIA Redaction Procedures | critical | 8.5 | 1 | Data Breach |
| 3901 | Starlink network access control | critical | 8.5 | 1 | Data Breach |
| 3902 | CVE-2025-10184 (Improper Permission Handling in OxygenOS Telephony Package) | critical | 8.5 | 1 | Vulnerability |
| 3903 | Unauthenticated vulnerabilities (56% of tracked vulnerabilities in 2025) | critical | 8.5 | 1 | Supply Chain Attack |
| 3904 | Social Engineering, Lack of User Awareness | critical | 8.5 | 1 | Phishing |
| 3905 | Quantum Model Memorization of Training Data | critical | 8.5 | 1 | Privacy Breach |
| 3906 | third-party integrations (speculated) | critical | 8.5 | 1 | data breach |
| 3907 | Lack of input validation controls | critical | 8.5 | 1 | Data Security Audit |
| 3908 | Vulnerability in Accellion FTA system | critical | 8.5 | 1 | Data Breach |
| 3909 | Over-permissioned OAuth scopes | critical | 8.5 | 1 | Data Breach |
| 3910 | Vulnerable drivers (8 distinct drivers), FortiGate misconfigurations | critical | 8.5 | 1 | Ransomware |
| 3911 | Lack of AI Agent Management | critical | 8.5 | 1 | Data Breach |
| 3912 | CVE-2025-15544 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3913 | Misconfigured Microsoft Power Pages data tables | critical | 8.5 | 1 | Data Breach |
| 3914 | Isolation of employees | critical | 8.5 | 1 | Scam, Phishing, Fraud |
| 3915 | lack_of_comprehensive_security_measures | critical | 8.5 | 1 | data_breach |
| 3916 | Zero-Day in Avast Sandbox (SAM Database Access) | critical | 8.5 | 1 | Privilege Escalation |
| 3917 | user susceptibility to phishing | critical | 8.5 | 1 | phishing |
| 3918 | Use-After-Free | critical | 8.5 | 1 | Privilege Escalation |
| 3919 | CVE-2026-19489 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3920 | RAG system poisoning | critical | 8.5 | 1 | Data Breach |
| 3921 | Inadequate data security controls / unauthorized access by insider | critical | 8.5 | 1 | Data Breach |
| 3922 | lack of data access controls | critical | 8.5 | 1 | data breach |
| 3923 | Legitimate remote access tool abuse (ScreenConnect) | critical | 8.5 | 1 | Malware Campaign |
| 3924 | Prompt injection in GitLab Duo | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3925 | CVE-2026-24512 | critical | 8.5 | 1 | Supply Chain Attack |
| 3926 | CVE-2026-34070 | critical | 8.5 | 1 | Data Exfiltration |
| 3927 | Auto-install mechanism of GX Mods, universal CSS injection, XS-Leak (cross-site leak) | critical | 8.5 | 1 | Data Theft |
| 3928 | CVE-pending (Overly Permissive Origin Allowlist, DOM-Based XSS in Arkose Labs CAPTCHA component) | critical | 8.5 | 1 | Zero-Click Vulnerability, Prompt-Injection Attack |
| 3929 | User trust in AI-themed extensions, lack of stringent Chrome Web Store security checks | critical | 8.5 | 1 | Malicious Browser Extensions |
| 3930 | No Rate Limiting | critical | 8.5 | 1 | Data Breach |
| 3931 | Lack of multi-factor authentication (MFA), Third-party vendor compromise | critical | 8.5 | 1 | Data Breach |
| 3932 | Third-party credentials | critical | 8.5 | 1 | Data Breach |
| 3933 | Access control failures | critical | 8.5 | 1 | Data Breach |
| 3934 | Unsecured legacy server | critical | 8.5 | 1 | Data Exposure |
| 3935 | Unpatched Cloud Services | critical | 8.5 | 1 | Cloud Security Breach |
| 3936 | CVE-2013-4786 | critical | 8.5 | 1 | Data Leak |
| 3937 | Exposed Validation Hashes | critical | 8.5 | 1 | Data Breach |
| 3938 | Apple’s Activation Lock | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 3939 | Cisco Unified CM exploit | critical | 8.5 | 1 | Third-Party Risk Management Failure |
| 3940 | TNEF decoder infinite loop | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 3941 | Human error (tricked customer support employees into granting access) | critical | 8.5 | 1 | Data Breach |
| 3942 | Exposed SSH services | critical | 8.5 | 1 | Malware |
| 3943 | Ray on Vertex AI Insecure Default Access | critical | 8.5 | 1 | Privilege Escalation |
| 3944 | Unsecured third-party server | critical | 8.5 | 1 | Data Breach |
| 3945 | Lack of access controls and adherence to data protection policies | critical | 8.5 | 1 | Data Breach |
| 3946 | FG-IR-26-060 (CWE-288: Authentication Bypass Using an Alternate Path or Channel) | critical | 8.5 | 1 | Authentication Bypass |
| 3947 | Unauthorized use of tracking technologies on patient portal | critical | 8.5 | 1 | Data Breach |
| 3948 | improper access controls / misconfigured portal | critical | 8.5 | 1 | data breach |
| 3949 | Unprotected checkout endpoint in Funnel Builder WordPress plugin (versions prior to 3.15.0.3) | critical | 8.5 | 1 | Payment Card Skimming |
| 3950 | Unsecured Azure Entra ID (formerly Azure Active Directory) with lack of multi-factor authentication (MFA) | critical | 8.5 | 1 | Data Breach |
| 3951 | Lack of multimodal review in AI code reviewers, exclusion of image files from analysis | critical | 8.5 | 1 | Data Exfiltration |
| 3952 | CVE-2026-25172 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3953 | Customer Contract Search Tool | critical | 8.5 | 1 | Data Breach |
| 3954 | Trust in the platform's review system and verification processes | critical | 8.5 | 1 | Disinformation and Scams |
| 3955 | lack of access controls and encryption for cloud-hosted databases | critical | 8.5 | 1 | data breach |
| 3956 | Insufficient URL Security | critical | 8.5 | 1 | Data Breach |
| 3957 | Inadequate Technology and Agency Understaffing | critical | 8.5 | 1 | Data Exposure |
| 3958 | Weak third-party credential management | critical | 8.5 | 1 | Data Breach |
| 3959 | Lack of Robust Encryption/Monitoring in Data Flows | critical | 8.5 | 1 | Data Breach |
| 3960 | Typosquatting (proc-macro1 vs. proc-macro2), build script execution during compilation | critical | 8.5 | 1 | Supply Chain Attack |
| 3961 | lack of enterprise-grade security for AI tools | critical | 8.5 | 1 | ransomware |
| 3962 | Inadequate logging | critical | 8.5 | 1 | Data Breach |
| 3963 | Unfixed JavaScript execution flaw in Chromium Service Worker | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3964 | Abuse of Bubble’s no-code platform infrastructure, complex JavaScript bundles, Shadow DOM structures | critical | 8.5 | 1 | Phishing |
| 3965 | Misconfigured SPNs, delegated permissions, RC4-HMAC encryption | critical | 8.5 | 1 | Kerberoasting / Credential Theft |
| 3966 | identity weaknesses | critical | 8.5 | 1 | credential compromise |
| 3967 | WhatsApp Web | critical | 8.5 | 1 | Malware Campaign |
| 3968 | E-commerce web platform | critical | 8.5 | 1 | Data Breach |
| 3969 | One-click IP leak via MTProxy | critical | 8.5 | 1 | Data Leak |
| 3970 | Legitimate Telegram API authentication mechanisms | critical | 8.5 | 1 | Phishing |
| 3971 | CVE-2026-2835 | critical | 8.5 | 1 | HTTP Request Smuggling |
| 3972 | System vulnerability in Brevo's platform | critical | 8.5 | 1 | Phishing Attack |
| 3973 | Inadequate governance for AI systems | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 3974 | unpatched_systems | critical | 8.5 | 1 | data_breach |
| 3975 | CVE-2026-3518 | critical | 8.5 | 1 | vulnerability |
| 3976 | Misconfigured Google Firebase database | critical | 8.5 | 1 | Data Breach |
| 3977 | Trust model flaws in AI agent workflows (command approvals, output handling, inter-stage handoffs) | critical | 8.5 | 1 | Data Exfiltration |
| 3978 | human trust in AI-generated content | critical | 8.5 | 1 | fraud |
| 3979 | Human error in CMS settings (defaulted to public URLs unless manually restricted) | critical | 8.5 | 1 | Data Leak |
| 3980 | CVE-2026-4387 | critical | 8.5 | 1 | Authentication Flaw |
| 3981 | Improper escaping of special characters in button labels during HTML exports | critical | 8.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 3982 | CVE-2026-22153 (FG-IR-25-1052), CWE-305 (Authentication Bypass by Primary Weakness) | critical | 8.5 | 1 | Authentication Bypass |
| 3983 | Agentic Supply Chain Vulnerability (OWASP AI Top 10 - December 2025) | critical | 8.5 | 1 | AI Agent Hijacking |
| 3984 | Supply chain compromise in CI/CD dependencies | critical | 8.5 | 1 | Supply Chain Attack |
| 3985 | Browser Blob URL APIs | critical | 8.5 | 1 | Phishing |
| 3986 | Vulnerabilities in Google’s Salesforce environment | critical | 8.5 | 1 | Data Breach |
| 3987 | Outdated PHP versions (e.g., PHP 7.4 and earlier) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3988 | CVE not specified (Linux kernel `net/bridge` component, STP timers) | critical | 8.5 | 1 | Use-After-Free Vulnerability |
| 3989 | Software Flaw | critical | 8.5 | 1 | Ransomware |
| 3990 | CVE-2026-39364 | critical | 8.5 | 1 | Cyberattack |
| 3991 | Trivial vulnerability | critical | 8.5 | 1 | Data Breach |
| 3992 | CVE-2026-20040 | critical | 8.5 | 1 | Privilege Escalation |
| 3993 | Improper Access Control in SharePoint | critical | 8.5 | 1 | Data Exposure |
| 3994 | Public Repository Misconfiguration | critical | 8.5 | 1 | Data Breach |
| 3995 | Third-Party Platform Security (Salesforce) | critical | 8.5 | 1 | Data Breach |
| 3996 | CWE-862 (Missing Authorization) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3997 | Lack of purpose-built identity verification during hiring/onboarding, fragmented fraud detection, unclear ownership of pre-hire identity risk | critical | 8.5 | 1 | Identity Fraud / Insider Threat |
| 3998 | CVE-2026-26030 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3999 | Missile defense system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4000 | Lack of spotlighting defense in Azure DevOps MCP PR descriptions | critical | 8.5 | 1 | Data Exfiltration |
| 4001 | CVE-2026-22219 (CVSS 8.3) | critical | 8.5 | 1 | Data Breach |
| 4002 | CVE-2026-42253 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4003 | Multi-factor Authentication (MFA) Bypass, Credential Theft | critical | 8.5 | 1 | Vishing (Voice Phishing) |
| 4004 | Malicious postinstall scripts | critical | 8.5 | 1 | Supply Chain Attack |
| 4005 | TOCTOU (Time-of-Check Time-of-Use) race condition in a SETUID binary | critical | 8.5 | 1 | Privilege Escalation |
| 4006 | CVE-2025-0994 | critical | 8.5 | 1 | Cyber Attack |
| 4007 | Download of malicious apps | critical | 8.5 | 1 | Malware |
| 4008 | CVE-2025-15628 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4009 | Logic error in NextAuth JWT callback (GHSA-7hg4-x4pr-3hrg) | critical | 8.5 | 1 | Authentication Bypass |
| 4010 | CVE-2026-7312 (CVSS 10.0) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4011 | CVE-2025-59448 (Session Token Lifetimes) | critical | 8.5 | 1 | Denial-of-Service |
| 4012 | Long-Term Data Retention | critical | 8.5 | 1 | Data Breach |
| 4013 | Insufficient DLP and behavioral analytics | critical | 8.5 | 1 | Data Breach |
| 4014 | Redis code execution | critical | 8.5 | 1 | Supply Chain Attack |
| 4015 | CVE-2026-9560 (OS Command Injection - CWE-78) | critical | 8.5 | 1 | Privilege Escalation |
| 4016 | Lack of SecureBoot, unprotected live streams, SMS-activated backdoor | critical | 8.5 | 1 | Backdoor |
| 4017 | Lack of MFA resilience, Human susceptibility to social engineering | critical | 8.5 | 1 | Phishing/Social Engineering |
| 4018 | Lack of Secure Document Destruction Procedures | critical | 8.5 | 1 | Data Breach (Improper Disposal / Physical Security Failure) |
| 4019 | Progress Software’s MOVEit Transfer solution | critical | 8.5 | 1 | Data Breach |
| 4020 | Unencrypted data on decommissioned equipment | critical | 8.5 | 1 | Data Breach |
| 4021 | CVE-2025-54106 (Windows RRAS RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4022 | Improperly configured AWS S3 storage | critical | 8.5 | 1 | Data Breach |
| 4023 | Internal system flaw exposing plain text passwords | critical | 8.5 | 1 | Data Breach |
| 4024 | CVE-2026-48907 (Joomla JCE editor) | critical | 8.5 | 1 | Webshell Attack |
| 4025 | Unrestricted internet access to real-time surveillance data without authentication | critical | 8.5 | 1 | Data Breach |
| 4026 | human trust in legacy inheritance process | critical | 8.5 | 1 | phishing |
| 4027 | CVE-2025-64496 | critical | 8.5 | 1 | Code Injection |
| 4028 | Automated link preview generation in AI agents | critical | 8.5 | 1 | Data Exfiltration |
| 4029 | CVE-2024-55591 (FortiOS/FortiProxy) | critical | 8.5 | 1 | ransomware |
| 4030 | Lack of zero-liability protections for ad accounts | critical | 8.5 | 1 | Account Hijacking |
| 4031 | Insufficient Log Retention | critical | 8.5 | 1 | Data Breach |
| 4032 | Unencrypted student data | critical | 8.5 | 1 | Data Breach |
| 4033 | Insufficient Conditional Access Controls | critical | 8.5 | 1 | Cloud Security Breach |
| 4034 | Previously unknown vulnerability in Oracle E-Business Suite | critical | 8.5 | 1 | Data Breach |
| 4035 | Lack of encryption and intrusion detection systems | critical | 8.5 | 1 | Data Breach |
| 4036 | improper access controls in the Texas Integrated Grant Reporting system | critical | 8.5 | 1 | data breach |
| 4037 | CVE-2026-44930 | critical | 8.5 | 1 | LDAP Injection |
| 4038 | Vulnerable fund member lookup screen | critical | 8.5 | 1 | Data Breach |
| 4039 | Heap-buffer overflow in libheif 1.19.7 (CVE not specified) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4040 | Public URLs for client-worker communications instead of secured, expiring links | critical | 8.5 | 1 | Data Exposure |
| 4041 | Disabled Workspace Trust in Cursor (VS Code fork) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4042 | Shared Access Protocols with Weak Authentication | critical | 8.5 | 1 | Data Breach |
| 4043 | Failure to Enforce 'Minimum Necessary' HIPAA Requirements | critical | 8.5 | 1 | Data Breach |
| 4044 | Weak security practices | critical | 8.5 | 1 | Fraud/Scam |
| 4045 | Insecure defaults in Google Cloud Platform (GCP) API key architecture | critical | 8.5 | 1 | Data Exposure |
| 4046 | Stolen credentials from 2025 Salesloft breach | critical | 8.5 | 1 | Data Breach |
| 4047 | AVrecon Malware | critical | 8.5 | 1 | Zero-day Exploitation |
| 4048 | Weakness in OAuth token security for Salesloft Drift integrations | critical | 8.5 | 1 | Data Breach |
| 4049 | Third-party platforms used for marketing and operations | critical | 8.5 | 1 | Data Breach |
| 4050 | Aeries Software | critical | 8.5 | 1 | Data Breach |
| 4051 | Insecure Amazon S3 databases | critical | 8.5 | 1 | Data Exposure |
| 4052 | CVE-2026-0628 (declarativeNetRequest API misconfiguration in Gemini AI panel) | critical | 8.5 | 1 | Privilege Escalation |
| 4053 | CVE-2026-32202 (Windows Shell Protection Mechanism Failure - CWE-693) | critical | 8.5 | 1 | Zero-Day Vulnerability Exploitation |
| 4054 | Software Misconfiguration in Online Grant System | critical | 8.5 | 1 | Data Breach |
| 4055 | Static default password in remote desktop software | critical | 8.5 | 1 | Data Breach |
| 4056 | Unspecified security flaw | critical | 8.5 | 1 | Data Leak |
| 4057 | Known system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4058 | Inadequate cybersecurity measures (alleged) | critical | 8.5 | 1 | Data Breach |
| 4059 | CVE-2026-22218 (CVSS 7.1) | critical | 8.5 | 1 | Data Breach |
| 4060 | CVE-2026-31635 (Missing COW guard in rxgk_decrypt_skb() function) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 4061 | Endpoint-level credential theft | critical | 8.5 | 1 | Data Breach |
| 4062 | Falcon Sensor's remediation workflow for Microsoft Office macros | critical | 8.5 | 1 | Local Privilege Escalation |
| 4063 | Lack of Multi-Factor Authentication (MFA) for Call-In Access | critical | 8.5 | 1 | Cyberattack |
| 4064 | Credential theft via Microsoft Entra account | critical | 8.5 | 1 | Phishing Attack |
| 4065 | Heap buffer overread in Squid’s FTP directory listing parser (CVE pending) | critical | 8.5 | 1 | Memory Disclosure Vulnerability |
| 4066 | Unauthenticated Admin Functions (GRS Panel, HTML Injection) | critical | 8.5 | 1 | Data Exposure |
| 4067 | Human error (employee susceptibility to scams), lack of robust multi-factor authentication (MFA) enforcement | critical | 8.5 | 1 | Data Breach |
| 4068 | CWE-200: Exposure of Sensitive Information | critical | 8.5 | 1 | Data Exposure |
| 4069 | Impersonation of legitimate brands, social engineering (discounts) | critical | 8.5 | 1 | Payment Data Theft |
| 4070 | Unpatched vulnerability in unnamed VPN product | critical | 8.5 | 1 | Data Breach |
| 4071 | Improper Handling of Sensitive Data | critical | 8.5 | 1 | Data Breach |
| 4072 | F5 BIG-IP AMP vulnerability | critical | 8.5 | 1 | data_breach |
| 4073 | CVE-2025-7659 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4074 | CVE-2025-54236 (Improper Input Validation in Adobe Commerce/Magento) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4075 | Abuse of Android’s Accessibility Service | critical | 8.5 | 1 | Malware (Remote Access Trojan - RAT) |
| 4076 | ThemeREX Addons (WordPress) | critical | 8.5 | 1 | Webshell Attack |
| 4077 | CVE-2026-20700 | critical | 8.5 | 1 | Exploit Kit |
| 4078 | trust in open-source dependencies | critical | 8.5 | 1 | supply-chain attack |
| 4079 | CVE-2026-12436 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4080 | Lack of Authentication (No Password Protection) | critical | 8.5 | 1 | Data Exposure / Unsecured Database |
| 4081 | Backup Database Access | critical | 8.5 | 1 | Data Breach |
| 4082 | Vulnerable API endpoint | critical | 8.5 | 1 | Data Breach |
| 4083 | Social engineering (verification code sharing) | critical | 8.5 | 1 | Phishing, Account Takeover |
| 4084 | Abuse of High-Reputation Domains (sites.google.com, docs.google.com) | critical | 8.5 | 1 | Phishing |
| 4085 | Lack of Access Controls / Unencrypted Data Storage | critical | 8.5 | 1 | Data Exposure |
| 4086 | DLL hijacking (USERENV.dll), RPC protocol manipulation, malformed parameters in spawn method | critical | 8.5 | 1 | Privilege Escalation |
| 4087 | Cross-channel authentication inconsistencies | critical | 8.5 | 1 | Data Breach |
| 4088 | Zero-Click Prompt Injection in ChatGPT's Deep Research Tool | critical | 8.5 | 1 | Data Breach |
| 4089 | Insecure Third-Party Integration (Drift-Salesforce/Google Workspace) | critical | 8.5 | 1 | Data Breach |
| 4090 | Inconsistent DLP Policy Application | critical | 8.5 | 1 | Data Breach |
| 4091 | CVE-2023-32409 (WebKit Sandbox Escape - IronLoader) | critical | 8.5 | 1 | Exploit Kit / Malware Campaign |
| 4092 | CVE-2016-5817 (Critical SQL injection in Navis WebAccess) | critical | 8.5 | 1 | cyberattack |
| 4093 | Lack of user awareness, Apple *Activation Lock* bypass tools (e.g., *FMI OFF*), iCloud Webkit phishing kits | critical | 8.5 | 1 | Phishing, Unauthorized Unlocking, Black Market Operations |
| 4094 | CVE-2026-21519 (Type Confusion - CWE-843) | critical | 8.5 | 1 | Elevation of Privilege |
| 4095 | inadequate cloud security measures | critical | 8.5 | 1 | data breach |
| 4096 | Hard-coded API Key | critical | 8.5 | 1 | Data Breach |
| 4097 | Human (Employee Susceptibility to Phishing) | critical | 8.5 | 1 | Data Breach |
| 4098 | Zoom CVE-2026-53412 (account takeover flaw) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4099 | Automatic update mechanisms in browser extensions, lack of CSP enforcement | critical | 8.5 | 1 | Malware Distribution |
| 4100 | Compromised Italian government email system | critical | 8.5 | 1 | Data Breach, Extortion |
| 4101 | Default transmission of full Git repositories without explicit user consent | critical | 8.5 | 1 | Data Exposure |
| 4102 | Incomplete cross-origin controls (Ollama Desktop) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4103 | Sensor false data injection | critical | 8.5 | 1 | Firmware-level attack |
| 4104 | Excessive account permissions | critical | 8.5 | 1 | Data Breach |
| 4105 | CVE-2026-56711 | critical | 8.5 | 1 | Heap Out-of-Bounds Write |
| 4106 | Reuse of leaked personal data, Lack of user awareness | critical | 8.5 | 1 | Phishing / Social Engineering |
| 4107 | Misconfigured database lacking proper authentication controls | critical | 8.5 | 1 | Data Breach |
| 4108 | Lack of user verification for extension authenticity and over-permissioned access | critical | 8.5 | 1 | Malware (Malicious Browser Extension) |
| 4109 | Human Error (Employee fell for phishing scam) | critical | 8.5 | 1 | Data Breach |
| 4110 | Progress Software’s MOVEit Transfer application | critical | 8.5 | 1 | Data Breach |
| 4111 | Malware on User Devices | critical | 8.5 | 1 | Credential Exposure |
| 4112 | CVE-2026-20251 (Unsafe deserialization via jsonpickle library) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4113 | Improper use of tracking technologies on authenticated pages (patient portals) without HIPAA-compliant authorizations or business associate agreements | critical | 8.5 | 1 | Data Breach |
| 4114 | Morris Worm (1988 - Buffer Overflow in `fingerd`/`sendmail`) | critical | 8.5 | 1 | Memory Corruption |
| 4115 | CVE-2026-26144 | critical | 8.5 | 1 | Vulnerability |
| 4116 | BlueHammer (Windows zero-day) | critical | 8.5 | 1 | Zero-Day Vulnerability Disclosure |
| 4117 | Improper Disposal of Sensitive Data | critical | 8.5 | 1 | Data Breach |
| 4118 | CVE-2026-27022 (Query Injection) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4119 | Microsoft Entra authentication process | critical | 8.5 | 1 | Data Breach |
| 4120 | Excessive guest user permissions, misconfigured guest access to public APIs | critical | 8.5 | 1 | Data Theft |
| 4121 | Insecure processing of untrusted input by AI agents in GitHub Actions | critical | 8.5 | 1 | Prompt Injection Attack |
| 4122 | Publicly accessible database without proper security measures | critical | 8.5 | 1 | Data Exposure |
| 4123 | CVE-2025-13915 (CWE-305: Authentication Bypass by Primary Weakness) | critical | 8.5 | 1 | Authentication Bypass |
| 4124 | Frontend Access Control | critical | 8.5 | 1 | DNS Hijacking |
| 4125 | Microsoft vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4126 | Public awareness of data breaches, lack of QR code scanning security measures | critical | 8.5 | 1 | Phishing |
| 4127 | Unauthorized internal access to law enforcement databases | critical | 8.5 | 1 | Data Breach |
| 4128 | Unencrypted data storage in an internet-accessible environment | critical | 8.5 | 1 | Data Breach |
| 4129 | Insider Access Abuse | critical | 8.5 | 1 | Data Breach |
| 4130 | Employee interaction with fraudulent link | critical | 8.5 | 1 | Data Breach |
| 4131 | CVE-2026-53410 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4132 | lack of secret scanning | critical | 8.5 | 1 | data exposure |
| 4133 | Single Sign-On (SSO) accounts (Okta and other identity platforms), MFA manipulation | critical | 8.5 | 1 | Phishing (Vishing), Data Breach, Credential Theft |
| 4134 | Static code scanners' inability to detect runtime malicious behavior | critical | 8.5 | 1 | Supply-Chain Compromise |
| 4135 | Website Setup Error | critical | 8.5 | 1 | Credential Leak |
| 4136 | Unauthorized Software Installation | critical | 8.5 | 1 | Data Breach |
| 4137 | Lack of verification for government agency impersonation | critical | 8.5 | 1 | Social Engineering / Impersonation Scam |
| 4138 | Improper Privilege Management (CWE-269) | critical | 8.5 | 1 | Privilege Escalation |
| 4139 | Improper Authentication (MongoDB instance left unsecured) | critical | 8.5 | 1 | Data Leak |
| 4140 | Lack of organizational safeguards for AI chatbot usage | critical | 8.5 | 1 | Data Breach |
| 4141 | Lack of Data Loss Prevention (DLP) Controls | critical | 8.5 | 1 | Data Breach |
| 4142 | Social Engineering (Fake App Update) | critical | 8.5 | 1 | Cyberespionage |
| 4143 | CVE-2026-23594 | critical | 8.5 | 1 | Privilege Escalation |
| 4144 | Publicly exposed Sentry DSN credentials | critical | 8.5 | 1 | AI Agent Hijacking |
| 4145 | Account verification procedure | critical | 8.5 | 1 | Data Breach |
| 4146 | RoguePilot (GitHub Codespaces/Copilot) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4147 | Employee Access Abuse | critical | 8.5 | 1 | Data Leak |
| 4148 | BitLocker bypass (CVE-2026-50661) | critical | 8.5 | 1 | ransomware |
| 4149 | CVE-2026-24228 (Deserialization of Untrusted Data) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4150 | Server Message Block (SMB) | critical | 8.5 | 1 | phishing |
| 4151 | CVE-2026-42055 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4152 | potential Oracle E-Business Suite vulnerability | critical | 8.5 | 1 | data breach |
| 4153 | FortiGate VPN vulnerabilities | critical | 8.5 | 1 | Ransomware |
| 4154 | Active session token theft | critical | 8.5 | 1 | Infostealer Malware |
| 4155 | Active Directory (CVE-2026-56155) | critical | 8.5 | 1 | ransomware |
| 4156 | Improper IAM Policies | critical | 8.5 | 1 | Cloud Security Breach |
| 4157 | Trust boundary violation in *externally_connectable* setting, lack of sender verification, DOM manipulation, approval looping | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4158 | Accellion FTA (specific CVE not mentioned) | critical | 8.5 | 1 | Data Breach |
| 4159 | weak validator key security | critical | 8.5 | 1 | blockchain exploit |
| 4160 | Unsecured APIs, shared keys | critical | 8.5 | 1 | Data Breach |
| 4161 | EngageLab SDK Vulnerability (Android) | critical | 8.5 | 1 | Data Breach |
| 4162 | CVE-2026-32635 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4163 | Improper handling and sharing of restricted voter data | critical | 8.5 | 1 | Data Breach |
| 4164 | CVE-2026-XXXX (not explicitly mentioned, but implied as a critical vulnerability) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4165 | CWE-94 (Code Injection), Shared Execution Environment Misconfiguration, VPC Service Controls Bypass, IMDS Credential Leakage | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4166 | Unspecified vulnerability in Salesloft Drift's OAuth token management | critical | 8.5 | 1 | Supply Chain Attack |
| 4167 | Exploitation of OAuth tokens via proxy interception | critical | 8.5 | 1 | Data Breach |
| 4168 | Lack of reasonable cyber security measures | critical | 8.5 | 1 | Data Breach |
| 4169 | Weak Password Reset Mechanisms | critical | 8.5 | 1 | Cyberattack |
| 4170 | Third-party mail service provider | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 4171 | CVE-2026-57221 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4172 | Human Error (Employee Clicked Malicious Link) | critical | 8.5 | 1 | Data Breach |
| 4173 | CVE-2025-54136 (MCPoison - MCP Trust Bypass) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4174 | Security misconfiguration in a non-production environment | critical | 8.5 | 1 | Data Leakage |
| 4175 | Price oracle vulnerability in DeFi protocol | critical | 8.5 | 1 | DeFi Exploit |
| 4176 | Authentication vulnerabilities in Coupang's servers | critical | 8.5 | 1 | Data Breach |
| 4177 | CVE-2025-54236 (SessionReaper - Session Data Storage on File System) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4178 | CVE-2025-9142 (JWT manipulation and directory traversal in Perimeter81 service component) | critical | 8.5 | 1 | Privilege Escalation |
| 4179 | CVE-2026-1236 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4180 | Human error, lack of phishing awareness | critical | 8.5 | 1 | Data Breach |
| 4181 | Vulnerable pull request target pattern in GitHub Actions, malicious optionalDependencies in package.json, prepare lifecycle hook execution | critical | 8.5 | 1 | Supply Chain Attack |
| 4182 | CVE-2026-14191 (Heap Overflow) | critical | 8.5 | 1 | Vulnerability |
| 4183 | Previously unknown security vulnerability in Oracle E-Business Suite | critical | 8.5 | 1 | Data Breach |
| 4184 | CVE-2021-47961 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4185 | CVE-2026-25173 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4186 | ProxyNotShell (Microsoft Exchange Server vulnerability) | critical | 8.5 | 1 | Cyber Espionage |
| 4187 | Website Migration | critical | 8.5 | 1 | Data Breach |
| 4188 | Vendor Error | critical | 8.5 | 1 | Data Breach |
| 4189 | Unsanitized parameters in database queries leading to SQL injection | critical | 8.5 | 1 | SQL Injection |
| 4190 | Use of Unlicensed Software | critical | 8.5 | 1 | Malware |
| 4191 | Absence of vendor security assessments for AI tools | critical | 8.5 | 1 | Data Leakage |
| 4192 | Illicit tactics to bypass digital rights management (DRM) | critical | 8.5 | 1 | Data Breach |
| 4193 | Import-time execution in npm packages | critical | 8.5 | 1 | Supply Chain Attack |
| 4194 | CVE-2025-9242 (Out-of-bounds write in Fireware OS ‘iked’ process) | critical | 8.5 | 1 | Vulnerability Exposure |
| 4195 | SS7/Diameter Protocol Flaws | critical | 8.5 | 1 | Data Breach |
| 4196 | Human trust in SMS-based password-recovery requests | critical | 8.5 | 1 | Phishing, Account Compromise, Identity Theft, Wire Fraud, Computer Fraud, Conspiracy |
| 4197 | Server Compromise | critical | 8.5 | 1 | Data Leak |
| 4198 | Inadequate safeguards for personal information | critical | 8.5 | 1 | Data Breach |
| 4199 | Improper handling of branch names during task execution | critical | 8.5 | 1 | Command Injection |
| 4200 | Unregulated AI Tool Integration | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 4201 | Inadequate safeguards for international data transfers | critical | 8.5 | 1 | Data Breach |
| 4202 | Compromised employees | critical | 8.5 | 1 | Extortion |
| 4203 | Unpatched vulnerability in VPN equipment | critical | 8.5 | 1 | Data Breach |
| 4204 | Unpatched React frontend application | critical | 8.5 | 1 | Data Breach |
| 4205 | Info-stealing malware infections, lack of multi-factor authentication | critical | 8.5 | 1 | Credential Stuffing |
| 4206 | Path traversal in Microsoft NLWeb (reading `/etc/passwd`, `.env`) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4207 | improper data retention | critical | 8.5 | 1 | data breach |
| 4208 | CVE-2024-38200 (MSHTML/Trident engine RCE) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4209 | Third-party vendor vulnerabilities (historical reference: Target 2013 breach) | critical | 8.5 | 1 | Data Breach |
| 4210 | ZombieAgent (prompt injection in ChatGPT Connectors/Apps feature) | critical | 8.5 | 1 | Prompt Injection |
| 4211 | Time-of-Check to Time-of-Use vulnerability in Alpitronic HYC50 EV charger | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 4212 | Undocumented API endpoints, CORS misconfigurations, pagination bypasses | critical | 8.5 | 1 | Data Exposure / Alleged Breach |
| 4213 | Third-party tracking and data sharing | critical | 8.5 | 1 | Data Breach |
| 4214 | inadequate data retention policies | critical | 8.5 | 1 | data breach |
| 4215 | Lack of multi-factor authentication (MFA), Basic security lapses (MMH) | critical | 8.5 | 1 | Data Breach |
| 4216 | Hard-coded encryption keys | critical | 8.5 | 1 | Data Breach |
| 4217 | Unknown vulnerability in CSDD system | critical | 8.5 | 1 | Data Breach |
| 4218 | CVE-2026-53362 | critical | 8.5 | 1 | Privilege Escalation |
| 4219 | CVE-2025-47934 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4220 | Legitimate authentication workflows (OAuth, MFA bypass) | critical | 8.5 | 1 | Cyber Espionage |
| 4221 | Partner system compromise leading to unauthorized API access | critical | 8.5 | 1 | Data Exposure |
| 4222 | Lack of authentication, unsecured admin portals, weak club passwords, hardcoded Stripe API keys | critical | 8.5 | 1 | Data Exposure |
| 4223 | Busy schedules of business owners | critical | 8.5 | 1 | Scam, Phishing, Fraud |
| 4224 | misconfigured AWS S3 bucket (lack of access controls) | critical | 8.5 | 1 | data exposure |
| 4225 | Unsecured API keys and poor credential hygiene | critical | 8.5 | 1 | Data Breach |
| 4226 | 46 vulnerabilities in inverters from Sungrow, Growatt, and SMA | critical | 8.5 | 1 | Firmware-level attack |
| 4227 | Outdated security protocols | critical | 8.5 | 1 | Data Breach |
| 4228 | Weak email header validation | critical | 8.5 | 1 | Data Breach |
| 4229 | CVE-2026-42824 | critical | 8.5 | 1 | Data Breach |
| 4230 | CVE-2026-0709 (Insufficient Input Validation) | critical | 8.5 | 1 | Command Execution Vulnerability |
| 4231 | CVE-2026-1340 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4232 | Lack of account management (inactive accounts not decommissioned) | critical | 8.5 | 1 | Data Breach |
| 4233 | Supply chain weakness in analytics data handling | critical | 8.5 | 1 | Data Breach |
| 4234 | Google session cookies (authentication tokens) | critical | 8.5 | 1 | Malware |
| 4235 | Weak authentication in verification APIs | critical | 8.5 | 1 | Data Breach Risk |
| 4236 | CVE-2026-24155 (Code Injection) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4237 | Abandoned domain takeover, lack of runtime URL validation in Microsoft add-ins | critical | 8.5 | 1 | Phishing |
| 4238 | Coding error in PayPal Working Capital (PPWC) loan application | critical | 8.5 | 1 | Data Breach |
| 4239 | Accellion File Transfer Appliance vulnerability | critical | 8.5 | 1 | Data Breach |
| 4240 | CVE-2026-17583 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4241 | MOVEit Server | critical | 8.5 | 1 | Data Breach |
| 4242 | CVE-2026-50458 (Use-after-free in Brokering File System) | critical | 8.5 | 1 | Local Privilege Escalation |
| 4243 | CVE-2026-65400 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4244 | Unspecified vulnerability in OT security solutions | critical | 8.5 | 1 | Data Breach |
| 4245 | Improper scoping of OAuth permissions in Salesloft Drift (Salesforce-integrated tool) | critical | 8.5 | 1 | Data Breach |
| 4246 | CVE-2025-71259 | critical | 8.5 | 1 | Malware Distribution |
| 4247 | Weakness in RubyDoc.info allowing code execution and data exfiltration | critical | 8.5 | 1 | Supply Chain Attack |
| 4248 | Theft of banking credentials and sensitive financial data | critical | 8.5 | 1 | Malware |
| 4249 | GitHub Account Security Weakness | critical | 8.5 | 1 | Data Breach |
| 4250 | Publicly Accessible .env Files | critical | 8.5 | 1 | Data Exposure |
| 4251 | Unpatched vulnerability in Apple’s *Hide My Email* feature | critical | 8.5 | 1 | Privacy Vulnerability |
| 4252 | Critical vulnerability in VIGI camera series | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4253 | Known security flaw (back door) in License Express system | critical | 8.5 | 1 | Data Exposure |
| 4254 | CVE-2026-8933 (Race condition in *snap-confine* component) | critical | 8.5 | 1 | Privilege Escalation |
| 4255 | limited_cybersecurity_resources | critical | 8.5 | 1 | data_breach |
| 4256 | KNX Association protocol flaw (Connection Authorization Option 1) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4257 | absence d’authentification multifactorielle | critical | 8.5 | 1 | Cyberattaque |
| 4258 | CVE-2026-87491 (WebAssembly sandbox-escape) | critical | 8.5 | 1 | Espionage, Cyber Attack |
| 4259 | Weak Authentication in AI Hiring System (Password '123456') | critical | 8.5 | 1 | Data Exposure |
| 4260 | Cloaking | critical | 8.5 | 1 | Phishing |
| 4261 | CVE-2025-54113 (Windows RRAS RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4262 | Mobile Application Vulnerability | critical | 8.5 | 1 | Data Breach |
| 4263 | Log4Shell | critical | 8.5 | 1 | Ransomware |
| 4264 | CVE-2026-25921 (CWE-345: Insufficient Verification of Data Authenticity) | critical | 8.5 | 1 | Supply-Chain Attack |
| 4265 | Citrix Software Vulnerability (specific CVE unidentified) | critical | 8.5 | 1 | Data Breach |
| 4266 | CVE-2025-7399 (Unauthenticated RCE in Samsung MagicINFO 9 Server) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4267 | Incorrect access settings | critical | 8.5 | 1 | Data Breach |
| 4268 | Java | critical | 8.5 | 1 | Cyber Attack |
| 4269 | no encryption | critical | 8.5 | 1 | data breach |
| 4270 | Mistake that exposed personal and financial information | critical | 8.5 | 1 | Data Breach |
| 4271 | eForms System Vulnerability | critical | 8.5 | 1 | Data Breach |
| 4272 | Phase-locked loops (PLLs) compromise | critical | 8.5 | 1 | Firmware-level attack |
| 4273 | Inadequate security measures for femtocell authentication certificates | critical | 8.5 | 1 | Data Breach |
| 4274 | CVE-2026-87886 (CWE-276 - Incorrect Default Permissions) | critical | 8.5 | 1 | Privilege Escalation |
| 4275 | CVE-2026-48710 (BadHost) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4276 | Compromised LiteLLM AI API tool versions | critical | 8.5 | 1 | Data Breach |
| 4277 | CVE-2026-2286 | critical | 8.5 | 1 | Remote Code Execution |
| 4278 | improper data retention practices (government IDs) | critical | 8.5 | 1 | data breach |
| 4279 | Progress Software MOVEit file transfer application vulnerability | critical | 8.5 | 1 | Data Breach |
| 4280 | lack of credential rotation | critical | 8.5 | 1 | data breach |
| 4281 | Unconstrained CI/CD Service Accounts | critical | 8.5 | 1 | Identity Compromise |
| 4282 | n8n flaws | critical | 8.5 | 1 | ransomware |
| 4283 | Missing *noindex* tags on shared pages | critical | 8.5 | 1 | Data Exposure |
| 4284 | Undocumented 'autorun=1' parameter, lack of separation between data and system instructions in LLMs | critical | 8.5 | 1 | AI Vulnerability Exploitation |
| 4285 | Lack of secure credential storage for AI agents | critical | 8.5 | 1 | Infostealer Malware |
| 4286 | Stolen session tokens (cookies) | critical | 8.5 | 1 | Account Hijacking |
| 4287 | Failure to Follow Standard Operating Procedures | critical | 8.5 | 1 | Data Breach |
| 4288 | weak password practices | critical | 8.5 | 1 | data breach |
| 4289 | Stolen credentials (PIN and government-issued ID) | critical | 8.5 | 1 | Fraud Scheme |
| 4290 | No Authentication by Default | critical | 8.5 | 1 | Misconfiguration |
| 4291 | WebKit memory-related errors | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4292 | Oracle E-Business Suite (versions 12.2.3 to 12.2.14) | critical | 8.5 | 1 | Data Breach |
| 4293 | CVE-2026-44413 | critical | 8.5 | 1 | Privilege Escalation |
| 4294 | Unrestricted access to AWS buckets | critical | 8.5 | 1 | Data Exposure |
| 4295 | Social engineering, lack of multi-factor authentication | critical | 8.5 | 1 | Phishing Campaign |
| 4296 | Lack of encryption/authentication in SunSpec Modbus | critical | 8.5 | 1 | Firmware-level attack |
| 4297 | Unpatched 'n-day' vulnerability in end-of-life software | critical | 8.5 | 1 | Data Breach |
| 4298 | Progress MOVEit Transfer | critical | 8.5 | 1 | Data Breach |
| 4299 | Supply-chain risks | critical | 8.5 | 1 | Third-party data exploitation |
| 4300 | CVE-2026-3298 | critical | 8.5 | 1 | Memory Corruption |
| 4301 | High-severity CVEs (FortiWeb, React2Shell, Ivanti Sentry, PAN-OS, CheckPoint VPN) | critical | 8.5 | 1 | Supply-Chain Attack |
| 4302 | Lack of transparency in AI decision-making | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 4303 | Stolen authentication tokens | critical | 8.5 | 1 | Data Breach |
| 4304 | Centralized Points of Failure in Hybrid Platforms | critical | 8.5 | 1 | Privacy Violation |
| 4305 | VPN appliances | critical | 8.5 | 1 | Credential Theft |
| 4306 | Over-Permissive Access to CRM/Donor Data | critical | 8.5 | 1 | Data Breach |
| 4307 | Bias and Unverified Data Propagation | critical | 8.5 | 1 | Data Privacy Issue |
| 4308 | Unsecured admin panel, IDOR vulnerability | critical | 8.5 | 1 | Data Exposure |
| 4309 | Insecure 'super admin' APIs allowing unauthenticated high-privilege account creation | critical | 8.5 | 1 | Data Exposure |
| 4310 | Prolonged Email Retention (6+ years) | critical | 8.5 | 1 | Data Breach |
| 4311 | CVE-2026-3062 (Out-of-bounds read/write in Tint shader engine) | critical | 8.5 | 1 | Vulnerability Patch |
| 4312 | Compromised OAuth tokens in Gainsight-published applications (no vulnerability in Salesforce platform itself) | critical | 8.5 | 1 | Data Breach |
| 4313 | CVE-2026-20817 (CWE-280: Improper Handling of Insufficient Permissions) | critical | 8.5 | 1 | Privilege Escalation |
| 4314 | Claude Code flaws | critical | 8.5 | 1 | APT Activity |
| 4315 | Simple File List (WordPress) | critical | 8.5 | 1 | Webshell Attack |
| 4316 | abuse of LaunchAgents for persistence | critical | 8.5 | 1 | malware |
| 4317 | Misuse of legitimate access credentials post-employment | critical | 8.5 | 1 | Data Breach |
| 4318 | Compromise of private keys | critical | 8.5 | 1 | Security Breach |
| 4319 | Cloud Vendor Compromise | critical | 8.5 | 1 | Data Breach |
| 4320 | CVE-2026-0958 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4321 | CVE-2026-39987 (Marimo RCE) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4322 | Misconfigured Salesforce Experience Cloud guest user access controls | critical | 8.5 | 1 | Data Breach |
| 4323 | Vendor Software | critical | 8.5 | 1 | Data Breach |
| 4324 | Fragmented Data Access Controls | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 4325 | SSO Credentials (Okta) | critical | 8.5 | 1 | Data Breach |
| 4326 | Dormant but active credential from a prototype integration | critical | 8.5 | 1 | Data Breach, Extortion |
| 4327 | Oracle WebLogic Server vulnerability | critical | 8.5 | 1 | Data Breach |
| 4328 | CVE-2026-2275 | critical | 8.5 | 1 | Remote Code Execution |
| 4329 | Integer Overflow | critical | 8.5 | 1 | Privilege Escalation |
| 4330 | Weak IT Help Desk Authentication Protocols | critical | 8.5 | 1 | Data Breach |
| 4331 | Lack of least-privilege access controls | critical | 8.5 | 1 | Data Breach |
| 4332 | Gemini Cloud Assist (Log Summarization Flaw) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4333 | Social Engineering, macOS TCC Bypass (SQL Injection into Privacy Database) | critical | 8.5 | 1 | Phishing, Malware |
| 4334 | MFA bypass via session replay, exploitation of legitimate JavaScript library (rrweb) | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 4335 | CVE-2026-13385 (Improper input validation in router management components) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4336 | CVE-2026-84388 (CVSS 9.1) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4337 | FortiOS 7.4.x | critical | 8.5 | 1 | Exploit Sale |
| 4338 | Unsafe workspace trust handling | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4339 | Vertex AI Agent Engine Service Agent Hijacking | critical | 8.5 | 1 | Privilege Escalation |
| 4340 | Inappropriate access controls and staff misconduct | critical | 8.5 | 1 | Unauthorised Access |
| 4341 | Lack of AI Governance Policies | critical | 8.5 | 1 | Data Leakage |
| 4342 | CVE-2025-30248 (CWE-427: Uncontrolled Search Path Element) | critical | 8.5 | 1 | DLL Hijacking |
| 4343 | SharePoint auth bypass (CVE-2026-55040) | critical | 8.5 | 1 | ransomware |
| 4344 | Passkey phishing | critical | 8.5 | 1 | Data Breach |
| 4345 | Reused third-party passwords, credential theft | critical | 8.5 | 1 | Data Breach |
| 4346 | Weak KYC processes, Fast account opening, SEPA transfer infrastructure | critical | 8.5 | 1 | Fraud, Money Laundering |
| 4347 | Insufficient access controls and monitoring for employee data handling | critical | 8.5 | 1 | Unauthorized Data Transfer |
| 4348 | GitHub Actions pull_request_target trigger | critical | 8.5 | 1 | Supply Chain Attack |
| 4349 | COM-elevation technique | critical | 8.5 | 1 | Malware (RAT) |
| 4350 | Improper Token Management | critical | 8.5 | 1 | Data Breach |
| 4351 | Unprotected GPRS gateway | critical | 8.5 | 1 | Data Breach |
| 4352 | Google Analytics and Google Ads misconfiguration | critical | 8.5 | 1 | Data Breach |
| 4353 | Insider Knowledge (Ethan Lipnik's Willingness to Share) | critical | 8.5 | 1 | Trade Secret Theft |
| 4354 | Phishing or Credential Compromise | critical | 8.5 | 1 | Data Breach |
| 4355 | Legislative gap in privacy protections for political parties | critical | 8.5 | 1 | Data Breach |
| 4356 | CVE-2026-5721 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4357 | Misconfigured Ollama endpoints (port 11434) | critical | 8.5 | 1 | LLMjacking |
| 4358 | shared CDN resources | critical | 8.5 | 1 | ransomware |
| 4359 | Exclusion from routine security checks | critical | 8.5 | 1 | Data Breach |
| 4360 | Open WebUI flaws | critical | 8.5 | 1 | ransomware |
| 4361 | Cross-border data storage without GDPR-equivalent protections | critical | 8.5 | 1 | Data Breach Risk |
| 4362 | persistent background execution via detached screen sessions | critical | 8.5 | 1 | malware |
| 4363 | Lack of Input Validation | critical | 8.5 | 1 | Data Breach |
| 4364 | Exposed Elasticsearch Database | critical | 8.5 | 1 | Data Leak |
| 4365 | Deceptive chats impersonating Signal Support chatbot | critical | 8.5 | 1 | Cyber Espionage |
| 4366 | Human error, Social engineering, Internal leaks | critical | 8.5 | 1 | Data Breach |
| 4367 | Weaknesses in vendor credential management | critical | 8.5 | 1 | Data Breach |
| 4368 | CVE-2025-43510 | critical | 8.5 | 1 | Exploit Kit |
| 4369 | CVE-2025-53770 (Microsoft SharePoint 'ToolShell') | critical | 8.5 | 1 | Ransomware |
| 4370 | Social engineering, in-memory execution, process hollowing, AMSI/ETW bypass | critical | 8.5 | 1 | Spear-Phishing, Malware (Keylogger), Credential Theft |
| 4371 | Unencrypted data at rest in shared app containers, macOS sandbox bypass (CVE-2026-28910) | critical | 8.5 | 1 | Data Exposure |
| 4372 | Known flaw in Metabase (disclosed on August 6, 2026) | critical | 8.5 | 1 | Data Breach |
| 4373 | Authorization control bypass in Google Gemini | critical | 8.5 | 1 | Indirect Prompt Injection |
| 4374 | Compromised remote access credentials from third-party service providers | critical | 8.5 | 1 | Data Breach |
| 4375 | Obscured opt-out tools, 'no index' instructions, and dark patterns | critical | 8.5 | 1 | Data Breach |
| 4376 | absence of suspicious login alerts | critical | 8.5 | 1 | data breach |
| 4377 | CVE-2026-1234 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4378 | Storage and transmission of device-specific data (e.g., precise geolocation, browsing history, search queries) | critical | 8.5 | 1 | Data Exposure |
| 4379 | CVE-2026-26268 (CVSS 8.1) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4380 | CVE-2025-9289 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4381 | Design bug in the FOIA request search feature | critical | 8.5 | 1 | Data Exposure |
| 4382 | CVE-2026-48282 (Path Traversal) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4383 | CVE-2025-43520 | critical | 8.5 | 1 | Exploit Kit |
| 4384 | Social engineering, obfuscated curl command execution, Full Disk Access deception | critical | 8.5 | 1 | Malware Campaign |
| 4385 | Lack of Authentication on Cloud Storage | critical | 8.5 | 1 | Data Exposure |
| 4386 | Gatekeeper bypass via notarized malware | critical | 8.5 | 1 | Infostealer |
| 4387 | SharePoint and Defender Zero-Days (Microsoft) | critical | 8.5 | 1 | Data Breach |
| 4388 | TrueConf Client Flaw | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4389 | Static Credentials in Setup Files | critical | 8.5 | 1 | Misconfiguration |
| 4390 | Lack of password encryption | critical | 8.5 | 1 | Unauthorized Access |
| 4391 | Weak authentication measures in Fast Pair protocol | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4392 | Salesforce Environments | critical | 8.5 | 1 | Data Breach |
| 4393 | WebSocket auth bypass (CVE-2025-52882, CVSS: 8.8) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4394 | Insufficient input sanitization in Drupal’s database API | critical | 8.5 | 1 | SQL Injection |
| 4395 | resource constraints | critical | 8.5 | 1 | data breach |
| 4396 | CVE-2026-19650 | critical | 8.5 | 1 | Code Injection |
| 4397 | CVE-2026-0257 | critical | 8.5 | 1 | Authentication Bypass |
| 4398 | AI model memory and data reconstruction capabilities | critical | 8.5 | 1 | AI Inference Attack |
| 4399 | Use of bare-metal servers without additional security layers like cloud-based services | critical | 8.5 | 1 | Data Breach |
| 4400 | Intent redirection vulnerability in EngageLab SDK (version 4.5.4) | critical | 8.5 | 1 | Supply Chain Vulnerability |
| 4401 | ProxyLogon/ProxyShell/ProxyNotShell (Microsoft Exchange) | critical | 8.5 | 1 | Exploit Trends |
| 4402 | N-central platform vulnerability (versions prior to 2026.2) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4403 | Technical failure in recognizing court updates | critical | 8.5 | 1 | Data Leak |
| 4404 | Human Manipulation (Social Engineering) | critical | 8.5 | 1 | Phishing (Vishing) |
| 4405 | CVE-2026-6688 (Long filename overflow) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4406 | Preventable authorization flaw, path manipulation in web address | critical | 8.5 | 1 | Data Breach |
| 4407 | CVE-2026-6686 (Uninitialized cluster exposure) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4408 | CVE-2026-1235 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4409 | CWE-20: Improper Input Validation (lack of server-side checks) | critical | 8.5 | 1 | Data Breach |
| 4410 | Unknown zero-day vulnerability in Metabase | critical | 8.5 | 1 | Data Breach |
| 4411 | BeyondTrust (CVE-2026-1731) | critical | 8.5 | 1 | APT Activity |
| 4412 | CVE-2025-7776 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4413 | Inadequate access controls in AI system for privileged actions | critical | 8.5 | 1 | Account Hijacking |
| 4414 | Unauthorized access via automated script | critical | 8.5 | 1 | Data Breach |
| 4415 | Microsoft 365 Android app flaw | critical | 8.5 | 1 | phishing |
| 4416 | AI-driven system access, credential exploitation, and unsecured testing environments | critical | 8.5 | 1 | Data Breach |
| 4417 | CVE-2023-50224 (TP-Link WR841N routers) | critical | 8.5 | 1 | Cyberespionage |
| 4418 | Unspecified coding error in SchoolMessenger application | critical | 8.5 | 1 | Data Breach |
| 4419 | ATM switch server compromise | critical | 8.5 | 1 | ATM cash-out fraud |
| 4420 | Publicly accessible production chatbots | critical | 8.5 | 1 | LLMjacking |
| 4421 | Inadequate cloud storage security | critical | 8.5 | 1 | Data Breach |
| 4422 | Insufficient Agent Permission Controls | critical | 8.5 | 1 | AI Security Vulnerabilities |
| 4423 | CVE-2025-59452 (Cleartext Transmission) | critical | 8.5 | 1 | Denial-of-Service |
| 4424 | CVE-2026-17059 (CWE-639: Broken Object-Level Authorization) | critical | 8.5 | 1 | Broken Access Control |
| 4425 | Infostealer malware distributed via compromised npm package (TanStack) | critical | 8.5 | 1 | Data Breach |
| 4426 | Weak User Authentication | critical | 8.5 | 1 | Data Breach |
| 4427 | CWE-798: Hard-coded Credentials | critical | 8.5 | 1 | Data Exposure |
| 4428 | Vendor's security shortcomings (unspecified) | critical | 8.5 | 1 | Data Breach (Third-Party Vendor) |
| 4429 | Adobe Reader | critical | 8.5 | 1 | Cyber Attack |
| 4430 | Unknown vulnerability in warehouse management system | critical | 8.5 | 1 | Data Breach |
| 4431 | Weak DMARC/SPF policies, Missing MTA-STS, Unvalidated/Expired Server Certificates, Misconfigured Microsoft 365 Security Tools | critical | 8.5 | 1 | Data Breach |
| 4432 | CVE-2026-34040 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4433 | Autofill Functionality Abuse | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4434 | Stolen credentials (password reuse, leaked credentials) | critical | 8.5 | 1 | Credential Theft |
| 4435 | Microsoft Teams default external messaging settings | critical | 8.5 | 1 | Phishing |
| 4436 | Human access points, Infected endpoints | critical | 8.5 | 1 | Data Breach, Financial Theft, Ransomware (Suspected) |
| 4437 | unsecured Azure Blob Storage | critical | 8.5 | 1 | data breach |
| 4438 | Lack of centralized oversight, inadequate vendor vetting, uncoordinated technology adoption | critical | 8.5 | 1 | Data Breach |
| 4439 | Unsecured System | critical | 8.5 | 1 | Data Breach |
| 4440 | AI Supply Chain Weaknesses | critical | 8.5 | 1 | Supply Chain Attack |
| 4441 | CVE-2026-24252 (OS Command Injection) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4442 | poorly secured AI tools | critical | 8.5 | 1 | ransomware |
| 4443 | missing server-side encryption | critical | 8.5 | 1 | data breach |
| 4444 | Unmonitored legacy credential (4-year-old OAuth token) | critical | 8.5 | 1 | Data Breach |
| 4445 | Weak point in the network | critical | 8.5 | 1 | Data Breach |
| 4446 | Ruby on Rails Active Storage flaw | critical | 8.5 | 1 | Data Breach |
| 4447 | CVE-2025-9292 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4448 | Personal information-based passwords | critical | 8.5 | 1 | Sextortion |
| 4449 | Inconsistent SPF/DKIM parsing | critical | 8.5 | 1 | Data Breach |
| 4450 | Email address normalization flaws | critical | 8.5 | 1 | Data Breach |
| 4451 | CVE-2025-67644 (SQL Injection) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4452 | misconfigured data visualization tool | critical | 8.5 | 1 | data exposure |
| 4453 | Unapplied security patches to its software | critical | 8.5 | 1 | Data Breach |
| 4454 | vBulletin security hole | critical | 8.5 | 1 | Data Breach |
| 4455 | Windows Script Host | critical | 8.5 | 1 | Malware Campaign |
| 4456 | Unknown (patched on detection) | critical | 8.5 | 1 | Data Breach |
| 4457 | Trust-boundary failure in Grok’s environment, PBKDF2 key derivation and AES-256-GCM encryption resistance to detection | critical | 8.5 | 1 | Prompt-Injection Attack |
| 4458 | Weaknesses in SHA pinning verification for plugins; Git branch naming flaw (Claude Code, Codex, GitHub Copilot); commit-fetching process flaw (Gemini CLI) | critical | 8.5 | 1 | Zero-Click Remote Code Execution (RCE) |
| 4459 | Lack of Data Minimization | critical | 8.5 | 1 | Data Breach |
| 4460 | Inadequate AI governance and security oversight | critical | 8.5 | 1 | Data Breach |
| 4461 | Coding Transmission Error | critical | 8.5 | 1 | Data Breach |
| 4462 | policy gaps | critical | 8.5 | 1 | data breach |
| 4463 | Lack of Visibility into AI Data Flows | critical | 8.5 | 1 | AI Security Vulnerabilities |
| 4464 | Incorrect System Settings | critical | 8.5 | 1 | Data Leak |
| 4465 | Unprotected Cloud Repository | critical | 8.5 | 1 | Data Leak |
| 4466 | Third-party secure file transfer tool vulnerability | critical | 8.5 | 1 | Data Breach |
| 4467 | CVE-2026-50656 (RoguePlanet) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 4468 | Lack of End-to-End Encryption | critical | 8.5 | 1 | Data Collection |
| 4469 | Critical vulnerabilities from CISA’s Known Exploited Vulnerabilities (KEV) catalog | critical | 8.5 | 1 | Insider Threat |
| 4470 | Authentication bypass via insecure API | critical | 8.5 | 1 | Data Breach |
| 4471 | CVE-2025-59449 (Incorrect Authorization) | critical | 8.5 | 1 | Denial-of-Service |
| 4472 | template-injection flaw in dataset configurations | critical | 8.5 | 1 | AI-driven intrusion |
| 4473 | Social Engineering (Tax-Season Lures), Spoofed Login Pages, Trusted RMM Tools Abuse | critical | 8.5 | 1 | Phishing, Credential Harvesting, Malware Deployment |
| 4474 | AWS Bedrock’s AgentCore Code Interpreter Sandbox Bypass | critical | 8.5 | 1 | Data Exfiltration |
| 4475 | Unauthorized access to INEC portal and improper data handling protocols | critical | 8.5 | 1 | Data Breach |
| 4476 | CVE-2025-48927 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4477 | Sequentially numbered and guessable URLs | critical | 8.5 | 1 | Data Exposure |
| 4478 | Over-Permissive Third-Party Access | critical | 8.5 | 1 | Data Breach |
| 4479 | CVE-2026-25592 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4480 | Insufficient Bot Detection/Prevention | critical | 8.5 | 1 | Cyberattack |
| 4481 | API linked to consultation records | critical | 8.5 | 1 | Data Breach |
| 4482 | compromised Booking.com accounts | critical | 8.5 | 1 | phishing |
| 4483 | Human vulnerability (bribery of overseas support agents) | critical | 8.5 | 1 | Data Breach |
| 4484 | Improperly secured database | critical | 8.5 | 1 | Data Exposure |
| 4485 | Unauthenticated DNS modification | critical | 8.5 | 1 | DNS Hijacking |
| 4486 | Zero-day vulnerability in Metabase’s cloud services | critical | 8.5 | 1 | Data Breach |
| 4487 | MOVEit file transfer service vulnerability | critical | 8.5 | 1 | Data Breach |
| 4488 | CVE-2025-61882 (CVSS 9.8 - Remote Code Execution in BI Publisher Integration/Concurrent Processing) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4489 | Weak or Stolen Employee Credentials | critical | 8.5 | 1 | Data Breach |
| 4490 | Flawed eagerParseCliFlag function in main.tsx, improper CLI flag parsing, and workspace trust dialog bypass | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4491 | Human Error (Publicly Accessible Database) | critical | 8.5 | 1 | Data Breach |
| 4492 | Private Code Repositories (GitLab, Visual Studio Code) | critical | 8.5 | 1 | Malware Deployment |
| 4493 | CVE-2026-20435 (MediaTek chipset boot chain weakness) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4494 | Weak encryption | critical | 8.5 | 1 | Data Breach |
| 4495 | Unmaintained VPN remote access server, inadequate network monitoring, ambiguous division of responsibilities, accumulation of unmanaged data on network drives | critical | 8.5 | 1 | Data Breach |
| 4496 | Lack of dedicated cybersecurity personnel | critical | 8.5 | 1 | Data exfiltration |
| 4497 | Human Vulnerability (Insider Recruitment) | critical | 8.5 | 1 | Insider Threat, Extortion |
| 4498 | HTTP 401 Unauthorized bypass via cloud-based path | critical | 8.5 | 1 | Data Exposure |
| 4499 | CVE-2026-1603 | critical | 8.5 | 1 | Authentication Bypass |
| 4500 | Unknown flaw in RubyGems’ servers | critical | 8.5 | 1 | Supply Chain Attack |
| 4501 | Oracle’s eBusiness Suite software vulnerability | critical | 8.5 | 1 | Data Breach |
| 4502 | Weak identity verification | critical | 8.5 | 1 | Identity Theft |
| 4503 | Human Error (Inadvertent Publication of Sensitive Data) | critical | 8.5 | 1 | Data Breach (Inadvertent Disclosure) |
| 4504 | CVE-2026-42897 | critical | 8.5 | 1 | Spoofing Vulnerability |
| 4505 | SonicWall SMA 1000 zero-day vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4506 | Hardcoded credentials in client-side code | critical | 8.5 | 1 | Credential Theft |
| 4507 | CVE-2026-23550 (CVSS 10.0) | critical | 8.5 | 1 | Privilege Escalation |
| 4508 | Insufficient internal access controls | critical | 8.5 | 1 | Data Breach |
| 4509 | Server-side request forgery (SSRF) (14.5%) | critical | 8.5 | 1 | API Security Breach |
| 4510 | CVE-2026-40372 | critical | 8.5 | 1 | Privilege Escalation |
| 4511 | Obfuscated Payloads | critical | 8.5 | 1 | Phishing |
| 4512 | Static XOR encryption key | critical | 8.5 | 1 | Data Breach |
| 4513 | Failure to mask sensitive contact details during password reset requests | critical | 8.5 | 1 | Data Exposure |
| 4514 | macOS Screen Sharing Flaw | critical | 8.5 | 1 | Data Breach |
| 4515 | Unauthorized access to Microsoft Office 365 email account | critical | 8.5 | 1 | Data Breach |
| 4516 | Unsecured Amazon cloud storage without password protection | critical | 8.5 | 1 | Data Breach |
| 4517 | CVE-2025-XXXX (WebKit Zero-Day 2) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4518 | third-party_file_transfer_solutions | critical | 8.5 | 1 | data_breach |
| 4519 | Systemic weaknesses in cybersecurity infrastructure | critical | 8.5 | 1 | Data Breach |
| 4520 | faiblesse des mots de passe utilisateurs | critical | 8.5 | 1 | cyberattaque |
| 4521 | CVE-2026-41651 (PackageKit authorization bypass) | critical | 8.5 | 1 | Privilege Escalation |
| 4522 | Open-source web administration tool (undisclosed) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4523 | Weak Authentication Credentials / Use of Non-Corporate Devices | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 4524 | Application misconfiguration | critical | 8.5 | 1 | Data Breach |
| 4525 | Long-lived femtocell certificates, absence of IP address restrictions, BPFDoor malware | critical | 8.5 | 1 | Data Breach |
| 4526 | Unauthorized data sharing via embedded tracking tools | critical | 8.5 | 1 | Data Breach |
| 4527 | CVE-2026-15315 (TP-Link Tapo C200) | critical | 8.5 | 1 | AI-driven attack |
| 4528 | Inadequate safeguards for 'Image ID' verification systems | critical | 8.5 | 1 | Data Breach |
| 4529 | Human error (tricked employees into handing over login credentials for internal Salesforce software) | critical | 8.5 | 1 | Data Breach |
| 4530 | MOVEit Secure File Transfer server | critical | 8.5 | 1 | Data Breach |
| 4531 | Lack of rate limiting | critical | 8.5 | 1 | Data Breach |
| 4532 | Intermediate Data Leakage (Predictions, Losses) | critical | 8.5 | 1 | Privacy Breach |
| 4533 | CWE-319: Cleartext Transmission of Sensitive Information (weak AES encryption) | critical | 8.5 | 1 | Data Breach |
| 4534 | Insufficient data filtering in AI screenshot feature | critical | 8.5 | 1 | Data Breach |
| 4535 | Android Accessibility Services, lack of user awareness | critical | 8.5 | 1 | Banking Trojan |
| 4536 | Reused credentials, lack of multifactor authentication | critical | 8.5 | 1 | Data Breach |
| 4537 | Discord's API | critical | 8.5 | 1 | Phishing |
| 4538 | Online customer service system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4539 | Unknown (zero-day) vulnerability in Oracle E-Business Suite (EBS) | critical | 8.5 | 1 | Data Breach |
| 4540 | Now-patched vulnerability in Instructure’s systems | critical | 8.5 | 1 | Data Breach |
| 4541 | CVE-2025-54253 (Misconfiguration in AEM Forms - Apache Struts 'devMode' enabled + Authentication Bypass) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4542 | Broad permissions granted to browser extensions | critical | 8.5 | 1 | Data Theft |
| 4543 | Unencrypted and non-password-protected database | critical | 8.5 | 1 | Data Leak |
| 4544 | Misconfigured Docker Setups | critical | 8.5 | 1 | Misconfiguration |
| 4545 | Fragmented Token Extraction via Optical/Transcription Methods | critical | 8.5 | 1 | Prompt Extraction |
| 4546 | Poor Cybersecurity Practices | critical | 8.5 | 1 | Data Breach |
| 4547 | CVE-2026-85046 (Chrome V8 type-confusion) | critical | 8.5 | 1 | Espionage, Cyber Attack |
| 4548 | Exposed configuration files | critical | 8.5 | 1 | Credential Theft |
| 4549 | Human Error (Impersonation) | critical | 8.5 | 1 | Data Breach |
| 4550 | Back-end system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4551 | Lack of multi-factor authentication, Human error (victims sharing access codes) | critical | 8.5 | 1 | Phishing, Social Engineering, Identity Theft, Data Theft |
| 4552 | CVE-2025-10547 (Uninitialized Stack Value Leading to Arbitrary Free) | critical | 8.5 | 1 | Vulnerability |
| 4553 | Auto-execution of URL parameters in Microsoft Copilot Personal sessions | critical | 8.5 | 1 | Prompt Injection Attack |
| 4554 | App cloning, Reverse engineering, Bypassing App Store security (iOS), JavaScript bundle interception, RSA-encrypted payload exfiltration | critical | 8.5 | 1 | Backdoor Attack, Cryptocurrency Wallet Hack |
| 4555 | Inconsistent Compliance Practices | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 4556 | CVE-2026-32996 | critical | 8.5 | 1 | Privilege Escalation |
| 4557 | Inadequate cybersecurity protocols, weak security controls | critical | 8.5 | 1 | Data Breach |
| 4558 | CVE-2026-6684 (GPT partition scan loop) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4559 | CVE-2026-21262 (Improper Access Control - CWE-284) | critical | 8.5 | 1 | Privilege Escalation |
| 4560 | Unauthorized access to cloud platforms | critical | 8.5 | 1 | Data Breach |
| 4561 | CVE-2026-89049 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4562 | Progress Software | critical | 8.5 | 1 | Data Breach |
| 4563 | improper access controls (configuration gap in S3 bucket permissions) | critical | 8.5 | 1 | data breach |
| 4564 | Auto-execution of `runOptions.runOn: 'folderOpen'` in tasks | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4565 | Vulnerability in third-party service provider | critical | 8.5 | 1 | Data Breach |
| 4566 | Composer’s regex validation failure due to GitHub’s new token format | critical | 8.5 | 1 | Data Exposure |
| 4567 | Poor Internal Access Controls | critical | 8.5 | 1 | Data Breach |
| 4568 | MOVEit file transfer platform vulnerability | critical | 8.5 | 1 | Data Breach |
| 4569 | CVE-2026-20046 | critical | 8.5 | 1 | Privilege Escalation |
| 4570 | CVE-2026-34621 (Prototype pollution vulnerability) | critical | 8.5 | 1 | Zero-day Exploitation |
| 4571 | Remote Access to Car Functions | critical | 8.5 | 1 | Vulnerability Exploit |
| 4572 | Weaknesses in Almaviva’s infrastructure | critical | 8.5 | 1 | Data Breach |
| 4573 | Incomplete redaction of sensitive documents | critical | 8.5 | 1 | Data Exposure |
| 4574 | Improper Token Management (Unrotated API Tokens) | critical | 8.5 | 1 | Data Breach |
| 4575 | CVE-2025-33206 (Improper Input Validation - CWE-78) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4576 | MOVEit® Transfer application | critical | 8.5 | 1 | Data Breach |
| 4577 | Lack of Monitoring for Existing Threats | critical | 8.5 | 1 | Data Breach |
| 4578 | compromised personal data | critical | 8.5 | 1 | fraud |
| 4579 | Zcash’s privacy layer vulnerability (4-year-old) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4580 | CVE-2026-46333 (Race condition in __ptrace_may_access()) | critical | 8.5 | 1 | Privilege Escalation |
| 4581 | Misconfigured AWS Storage Bucket | critical | 8.5 | 1 | Data Exposure |
| 4582 | Ivanti Endpoint Manager Mobile flaw | critical | 8.5 | 1 | Data Breach |
| 4583 | Social Engineering (Fake Windows Update) | critical | 8.5 | 1 | Session Hijacking |
| 4584 | CVE-2024-38197 | critical | 8.5 | 1 | Identity Spoofing |
| 4585 | CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-41099 (CWE-284: Improper Access Control) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4586 | Improperly configured Amazon S3 bucket | critical | 8.5 | 1 | Data Exposure |
| 4587 | Unauthorized Access to Personal Information | critical | 8.5 | 1 | Data Theft |
| 4588 | delayed_software_patches | critical | 8.5 | 1 | data_breach |
| 4589 | VMware Vulnerabilities | critical | 8.5 | 1 | Ransomware |
| 4590 | CVE-2025-3155 | critical | 8.5 | 1 | Vulnerability Exploit |
| 4591 | Stolen credentials (Okta SSO account of a support agent) | critical | 8.5 | 1 | Data Breach |
| 4592 | CVE-2025-5806 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4593 | Improper CSV processing allowing unauthenticated file reads | critical | 8.5 | 1 | SQL Injection |
| 4594 | CVE-2013-4786 (IPMI 2.0 HMAC-SHA1 handshake flaw) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4595 | Insufficient credential security | critical | 8.5 | 1 | Data Breach |
| 4596 | Third-Party Tracking Tools | critical | 8.5 | 1 | Data Collection |
| 4597 | CVE-2026-45585 (Windows BitLocker Zero-Day in WinRE) | critical | 8.5 | 1 | Security Feature Bypass |
| 4598 | Lack of user vigilance, Newly registered malicious domains | critical | 8.5 | 1 | Spoofing, Phishing, Brand Impersonation |
| 4599 | CVE-2025-54254 (Improper Restriction of XML External Entity Reference) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4600 | API scraping via automated harvesting of user profiles | critical | 8.5 | 1 | Data Breach |
| 4601 | improper access controls / lack of authentication for cloud storage | critical | 8.5 | 1 | data breach |
| 4602 | Spree IDOR Flaws (CVE-2026-22588/22589) | critical | 8.5 | 1 | Supply Chain Attack |
| 4603 | CVE-2026-60004 (CWE-94) | critical | 8.5 | 1 | Code Injection |
| 4604 | Hardcoded LDAP credentials | critical | 8.5 | 1 | Data Breach |
| 4605 | Lack of Input Sanitization for Hidden Commands | critical | 8.5 | 1 | Data Breach |
| 4606 | Improper packaging oversight | critical | 8.5 | 1 | Source Code Leak |
| 4607 | Publicly accessible, unsecured links | critical | 8.5 | 1 | Data Leak |
| 4608 | Failure to delete customer order data | critical | 8.5 | 1 | Data Breach |
| 4609 | Physical Security Gaps | critical | 8.5 | 1 | Data Leak |
| 4610 | Data Corruption | critical | 8.5 | 1 | Data Leak |
| 4611 | Misconfigured IAM policies, excessive permissions, lack of context-aware monitoring | critical | 8.5 | 1 | Credential Compromise, Data Exfiltration, Privilege Escalation |
| 4612 | CVE-2026-12473 | critical | 8.5 | 1 | Server-Side Request Forgery (SSRF) |
| 4613 | Misconfigured Redis Services | critical | 8.5 | 1 | Botnet Infection |
| 4614 | CVE-2026-3336 | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 4615 | lack of identity response integration | critical | 8.5 | 1 | phishing |
| 4616 | CVE-2025-41244 (VMware Aria Operations and VMware Tools Privilege Escalation) | critical | 8.5 | 1 | Privilege Escalation |
| 4617 | CVE-2026-23818 (Open Redirect in GUI Login Workflow) | critical | 8.5 | 1 | Phishing-Style Exploit |
| 4618 | CVE-2026-48019 (CWE-93 - CRLF Injection) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4619 | CVE-2026-31790 | critical | 8.5 | 1 | Data Leak |
| 4620 | Human Error (Compromised Employee Email Account) | critical | 8.5 | 1 | Data Breach |
| 4621 | zero-day_vulnerabilities | critical | 8.5 | 1 | data_breach |
| 4622 | Decentralized Security Coordination | critical | 8.5 | 1 | Data Breach |
| 4623 | Node.js workflows | critical | 8.5 | 1 | Supply Chain Attack |
| 4624 | Improper permission handling in Windows Error Reporting Service (wersvc.dll) | critical | 8.5 | 1 | Privilege Escalation |
| 4625 | MOVEit file transfer tool (global exploit) | critical | 8.5 | 1 | Data Breach |
| 4626 | CVE-2025-49844 | critical | 8.5 | 1 | Botnet Infection |
| 4627 | Lack of Multi-Layered Authentication for Integrations | critical | 8.5 | 1 | Data Breach |
| 4628 | Unauthorized access to medical records | critical | 8.5 | 1 | Data Breach |
| 4629 | CVE-2026-50107 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4630 | CVE-2026-20098 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4631 | Lack of basic safeguards on the targeted domain, credential exploitation | critical | 8.5 | 1 | AI Model Escape and Unauthorized Access |
| 4632 | Unaddressed vulnerabilities from a 2020 penetration test | critical | 8.5 | 1 | Data Breach |
| 4633 | Default credentials and internet-facing Elasticsearch endpoint | critical | 8.5 | 1 | Data Exposure |
| 4634 | Third-party vendor access to API | critical | 8.5 | 1 | Data Breach |
| 4635 | Improper Access Controls (Publicly Accessible Folder) | critical | 8.5 | 1 | Data Breach |
| 4636 | Unverified Assessment Domains | critical | 8.5 | 1 | APT (Advanced Persistent Threat) |
| 4637 | Abuse of Shared Access Signature (SAS) tokens and trusted cloud tools | critical | 8.5 | 1 | Ransomware |
| 4638 | Account Credentials | critical | 8.5 | 1 | Data Breach |
| 4639 | Lack of sandboxing in AI-generated test cases (Claude Code) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4640 | Potential Weak Email Security Controls | critical | 8.5 | 1 | Phishing |
| 4641 | Insufficient verification of government data requests; reliance on email domain authentication (SPF, DKIM, DMARC) alone | critical | 8.5 | 1 | Data Breach |
| 4642 | CVE-2026-25108 (OS Command Injection - CWE-78) | critical | 8.5 | 1 | Command Injection |
| 4643 | CVE-2026-27540 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4644 | CVE-2026-42167 | critical | 8.5 | 1 | SQL Injection |
| 4645 | remote-code dataset loader vulnerability | critical | 8.5 | 1 | AI-driven intrusion |
| 4646 | CVE-2026-76460 (Cisco ISE) | critical | 8.5 | 1 | AI-driven cyberattack |
| 4647 | Improper Firebase security rules (publicly accessible database) | critical | 8.5 | 1 | Data Breach |
| 4648 | Windows 11 Security Bypass | critical | 8.5 | 1 | Data Breach |
| 4649 | Double-free flaw in `rds_message_zcopy_from_user()` function (CVE pending) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 4650 | Chrome’s App-Bound Encryption (ABE) Bypass | critical | 8.5 | 1 | Infostealer Attack |
| 4651 | GX Mods automatic installation and CSS injection | critical | 8.5 | 1 | Data Exfiltration |
| 4652 | Lack of proper access controls or oversight during training | critical | 8.5 | 1 | Data Breach / Espionage |
| 4653 | CVE-2026-58704 (Elevation-of-Privilege in Cellular Modem) | critical | 8.5 | 1 | Zero-Day Exploitation |
| 4654 | Fragmented policies for data in motion | critical | 8.5 | 1 | Data Governance Blind Spot |
| 4655 | MOVEit Transfer Vulnerability (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 4656 | Human vulnerability (bribery of customer support agents) | critical | 8.5 | 1 | Data Breach |
| 4657 | Prompt Injection (AI agent misinterprets embedded commands in untrusted data as legitimate instructions) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4658 | System misconfiguration reactivating disabled feature | critical | 8.5 | 1 | Data Breach |
| 4659 | Malicious npm packages impersonating legitimate libraries | critical | 8.5 | 1 | Supply Chain Attack |
| 4660 | Vulnerability in UpdraftPlus plugin | critical | 8.5 | 1 | Supply Chain Attack |
| 4661 | Vulnerabilities in dataset processing, code execution on worker nodes | critical | 8.5 | 1 | Data Breach |
| 4662 | Mirasvit Full Page Cache Warmer flaw | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4663 | OAuth 2.0 protocol behavior (RFC 6749/9700) | critical | 8.5 | 1 | Phishing |
| 4664 | Wireless Debugging | critical | 8.5 | 1 | Banking Malware |
| 4665 | SVG File Abuse | critical | 8.5 | 1 | AI Security Breach |
| 4666 | CWE-798: Use of Hard-coded Credentials | critical | 8.5 | 1 | Data Breach |
| 4667 | CWE-287: Improper Authentication (Authentication Bypass) | critical | 8.5 | 1 | Data Breach |
| 4668 | lack of multi-factor authentication (MFA) enforcement on phishing sites | critical | 8.5 | 1 | phishing |
| 4669 | Hardcoded login credentials in the source code | critical | 8.5 | 1 | Data Breach |
| 4670 | Implicit trust in AI-generated summaries, unchecked trust in retrieved data by AI tools | critical | 8.5 | 1 | Phishing |
| 4671 | Insufficient de-identification | critical | 8.5 | 1 | Data Breach |
| 4672 | Lack of software updates for gear shifters | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4673 | Data security lapse | critical | 8.5 | 1 | Data Breach |
| 4674 | Unsecured Microsoft Azure cloud server | critical | 8.5 | 1 | Data exfiltration |
| 4675 | Misrepresentation of data handling practices | critical | 8.5 | 1 | Data Breach |
| 4676 | Misconfigured Database Access Controls | critical | 8.5 | 1 | Data Exposure |
| 4677 | CVE-2026-54433 | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 4678 | CVE-2026-25049 | critical | 8.5 | 1 | Supply Chain Attack |
| 4679 | Weak Authentication (SSO) | critical | 8.5 | 1 | Data Breach |
| 4680 | Microsoft Entra SSO Code | critical | 8.5 | 1 | Data Breach |
| 4681 | CVE-2025-54136 (MCPoison) - Trust Model Flaw in MCP Configuration Handling | critical | 8.5 | 1 | Vulnerability |
| 4682 | Lack of access controls / improper employee oversight | critical | 8.5 | 1 | Unauthorized Access / Insider Threat |
| 4683 | Hardcoded file path in OpenSSL integration (CVE-2026-3991) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 4684 | Credential harvesting via fake Zimbra login portal | critical | 8.5 | 1 | Phishing |
| 4685 | Flaw in 'Image ID' parameter allowing URL manipulation | critical | 8.5 | 1 | Data Breach |
| 4686 | Android and Linux Kernel vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4687 | compromised signed access token | critical | 8.5 | 1 | data breach |
| 4688 | E-commerce Site Vulnerability | critical | 8.5 | 1 | Data Breach |
| 4689 | CVE-2023-28771 | critical | 8.5 | 1 | Remote Code Execution |
| 4690 | Design flaws in consent enforcement mechanism | critical | 8.5 | 1 | Consent Mechanism Exploit |
| 4691 | Inadequate access controls, lack of data encryption | critical | 8.5 | 1 | Data Breach |
| 4692 | CVE-2025-55227 (SQL Server Privilege Escalation) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4693 | CVE-2026-23596 | critical | 8.5 | 1 | Privilege Escalation |
| 4694 | Parameter-to-Prompt (P2P) weakness in Atlassian Rovo AI assistant (rovoChatPrompt parameter) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4695 | CVE-2025-54135 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4696 | systèmes obsolètes | critical | 8.5 | 1 | Cyberattaque |
| 4697 | Unsecured LLM infrastructure | critical | 8.5 | 1 | Security Vulnerability |
| 4698 | Improper data handling and lack of safeguards | critical | 8.5 | 1 | Data Breach |
| 4699 | Leaked customer data | critical | 8.5 | 1 | Phishing |
| 4700 | Shared infrastructure vulnerabilities | critical | 8.5 | 1 | AI-driven attack |
| 4701 | Android’s restricted settings and Accessibility Service controls | critical | 8.5 | 1 | Malware |
| 4702 | MITRE T1555 (Credential Harvesting) | critical | 8.5 | 1 | Data Breach |
| 4703 | Special query interface allowing unauthorized searches using Turkish national ID numbers | critical | 8.5 | 1 | Data Breach |
| 4704 | Lack of security audits for employee-facing ecommerce platforms | critical | 8.5 | 1 | Keylogger Attack |
| 4705 | Unknown vulnerability (zero-day) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4706 | Phishing-susceptible MFA methods | critical | 8.5 | 1 | Data Breach |
| 4707 | Social engineering (fake software downloads) | critical | 8.5 | 1 | Infostealer Campaign |
| 4708 | Name-squatting and postinstall script execution | critical | 8.5 | 1 | Supply Chain Attack |
| 4709 | Model Context Protocol (MCP) flaws | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4710 | Human Factor (Social Engineering) | critical | 8.5 | 1 | Data Breach |
| 4711 | Lack of end-to-end encryption for ID uploads | critical | 8.5 | 1 | Data Breach Risk |
| 4712 | Unlimited Coupon Redemptions (CosMc’s App) | critical | 8.5 | 1 | Data Exposure |
| 4713 | CVE-2026-21509 (Microsoft Office Security Feature Bypass) | critical | 8.5 | 1 | Cyber-Espionage |
| 4714 | CVE-2025-54820 (Stack-based buffer overflow in *fgtupdates* service) | critical | 8.5 | 1 | Vulnerability |
| 4715 | CVE-2026-21513 (Security Feature Bypass - CWE-693) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4716 | Insufficient Authentication/Authorization Controls for Reimbursement Account Access | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 4717 | SQL injection (20.0%) | critical | 8.5 | 1 | API Security Breach |
| 4718 | CVE-2025-59489 (Unity Editor Command-Line Argument Injection) | critical | 8.5 | 1 | Vulnerability |
| 4719 | Employee Access | critical | 8.5 | 1 | Data Breach |
| 4720 | Insufficient monitoring and control over non-human credentials | critical | 8.5 | 1 | Data Breach / Lateral Movement |
| 4721 | CVE-2026-1281 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4722 | Excessive Data Access Permissions | critical | 8.5 | 1 | Data Breach |
| 4723 | Light-touch KYC, Instant SEPA transfers, Gaps in point-in-time checks | critical | 8.5 | 1 | Money Laundering, Fraud, Account Takeover |
| 4724 | Side API compromise | critical | 8.5 | 1 | Supply Chain Attack |
| 4725 | Human Error / Social Engineering | critical | 8.5 | 1 | Phishing Attack |
| 4726 | Confused Deputy (CWE-441) | critical | 8.5 | 1 | Privilege Escalation |
| 4727 | Unauthenticated access via installed apps on streaming devices | critical | 8.5 | 1 | Unauthorized Proxy Network |
| 4728 | CVE-2026-11645 (Out-of-bounds read and write in V8 JavaScript engine) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 4729 | Unauthenticated Access to TRT Tool (Employee Data) | critical | 8.5 | 1 | Data Exposure |
| 4730 | Typosquatting, impersonation, and automatic execution of post-install scripts | critical | 8.5 | 1 | Supply Chain Attack |
| 4731 | CVE-2026-23631 (DarkReplica) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4732 | GoAnywhere MFT (specific CVE not mentioned) | critical | 8.5 | 1 | Data Breach |
| 4733 | weak MFA implementations | critical | 8.5 | 1 | phishing |
| 4734 | Net-NTLMv1 Authentication Protocol | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4735 | AI guardrail bypass via social engineering (framing requests as legitimate research) | critical | 8.5 | 1 | AI-Powered Cyberattack |
| 4736 | Leaked email addresses from previous data breaches | critical | 8.5 | 1 | Sextortion Scam |
| 4737 | Misconfigured data-sharing practices | critical | 8.5 | 1 | Data Breach |
| 4738 | Unpatched vulnerabilities in third-party applications | critical | 8.5 | 1 | Third-party data exploitation |
| 4739 | Login and Sign-up Service | critical | 8.5 | 1 | Data Breach |
| 4740 | shadow_AI | critical | 8.5 | 1 | data_breach |
| 4741 | Lack of clear user consent | critical | 8.5 | 1 | Privacy Violation |
| 4742 | Exposed Personal Data | critical | 8.5 | 1 | Data Breach |
| 4743 | Publicly Accessible Files | critical | 8.5 | 1 | Data Leak |
| 4744 | CWE-284: Improper Access Control | critical | 8.5 | 1 | Data Exposure |
| 4745 | Unmonitored Data Exfiltration via AI Prompts | critical | 8.5 | 1 | Data Leakage |
| 4746 | Inadequate IT security measures | critical | 8.5 | 1 | Data Breach |
| 4747 | Progress MOVEit platform | critical | 8.5 | 1 | Data Breach |
| 4748 | CVE-2026-21992 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4749 | No lockout after repeated failed login attempts, weak encryption algorithms, unlawful data collection and storage, retention of outdated records | critical | 8.5 | 1 | Data Breach |
| 4750 | CVE-2026-52824 (GHSA-jr9p-4h4j-6c58), CWE-1188 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4751 | Unauthorized access to third-party system storing customer data | critical | 8.5 | 1 | Data Breach |
| 4752 | Unpatched SQL injection flaw in GeoServer | critical | 8.5 | 1 | SQL Injection |
| 4753 | CVE-2026-19490 (Citrix NetScaler) | critical | 8.5 | 1 | Data Breach |
| 4754 | Weak security controls, lack of abnormal activity detection | critical | 8.5 | 1 | Data Breach |
| 4755 | Improper authorization in project imports | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4756 | Steganography (hidden JavaScript in PNG files), lack of strict extension vetting | critical | 8.5 | 1 | Malware Campaign |
| 4757 | Software Vulnerability in InvestorCOM’s systems | critical | 8.5 | 1 | Data Breach |
| 4758 | Contact-importing features | critical | 8.5 | 1 | Data Leak |
| 4759 | CVE-2026-20191 (Path Traversal - CWE-22) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4760 | Stolen credentials via social engineering | critical | 8.5 | 1 | Data Breach |
| 4761 | Overpermissioned OAuth grants, lack of contextual awareness in AI agents | critical | 8.5 | 1 | OAuth token abuse |
| 4762 | Remote Code Execution Vulnerability in DS-2105 Pro DVRs | critical | 8.5 | 1 | Botnet |
| 4763 | SQL Injection in public-facing application, privilege escalation to SYSTEM-level access in Oracle Database, abuse of Oracle’s CREATE JAVA SOURCE functionality | critical | 8.5 | 1 | Malware Deployment |
| 4764 | CVE (3 high-severity with publicly available exploit code) | critical | 8.5 | 1 | Misconfiguration |
| 4765 | Unsecured Public LLM Interactions | critical | 8.5 | 1 | Data Leakage |
| 4766 | CVE-2026-68820 (Use-after-free in Windows Ancillary Function Driver for WinSock - afd.sys) | critical | 8.5 | 1 | Privilege Escalation |
| 4767 | Sophisticated hacking attempts | critical | 8.5 | 1 | Data Breach |
| 4768 | Weak signing secrets | critical | 8.5 | 1 | Credential Theft |
| 4769 | Improper input sanitization (CWE-74) | critical | 8.5 | 1 | Information Disclosure |
| 4770 | Authorization flaw, configuration error leading to prolonged data retention | critical | 8.5 | 1 | Data Breach |
| 4771 | CVE-2025-8088 (WinRAR path traversal flaw in Windows versions < 7.13) | critical | 8.5 | 1 | Zero-day exploit |
| 4772 | Oracle E-Business Suite vulnerabilities | critical | 8.5 | 1 | Cyberattack |
| 4773 | CVE-2025-12057 (WavePlayer) | critical | 8.5 | 1 | Exploitation Campaign |
| 4774 | Password plugin session-injection flaws | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 4775 | Architectural flaw in GitHub MCP server allowing AI agents to access and exfiltrate data from private repositories | critical | 8.5 | 1 | Prompt Injection |
| 4776 | Employee Impersonation | critical | 8.5 | 1 | Data Breach |
| 4777 | Accellion File Transfer Appliance (FTA) software vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4778 | OpenSSH 10.5 Flaw | critical | 8.5 | 1 | Data Breach |
| 4779 | Human error (deception of individuals into disclosing confidential information) | critical | 8.5 | 1 | Data Breach |
| 4780 | Insufficient data encryption | critical | 8.5 | 1 | Data Breach |
| 4781 | LLM safety guardrails bypass via iterative dialogue | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4782 | CVE-2026-9614 (CWE-284: Improper Access Control) | critical | 8.5 | 1 | Privilege Escalation |
| 4783 | Two-Factor Authentication (2FA) Bypass | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 4784 | Weak security measures in credit card terminals | critical | 8.5 | 1 | Cyber Crime |
| 4785 | CVE-2026-14898 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) | critical | 8.5 | 1 | Data Exfiltration |
| 4786 | DirtyClone (CVE-2026-43503) | critical | 8.5 | 1 | Local Privilege Escalation |
| 4787 | Arbitrary Order Data Injection (CosMc’s App) | critical | 8.5 | 1 | Data Exposure |
| 4788 | Unsecured database, malware infection via phishing emails/malicious websites/cracked software | critical | 8.5 | 1 | Data Exposure |
| 4789 | CVE-2026-26123 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4790 | Hardcoded Supabase API key in client-side JavaScript with no Row Level Security (RLS) policies | critical | 8.5 | 1 | Data Breach |
| 4791 | Lack of person-of-interest threat profiling, limited protective measures for non-executive employees, absence of automated defenses against AI agents | critical | 8.5 | 1 | AI-driven impersonation attack |
| 4792 | Inadequate Audit Logs | critical | 8.5 | 1 | Data Breach |
| 4793 | Compromised maintainer credentials or system, typosquatting, dependency injection | critical | 8.5 | 1 | Supply Chain Attack |
| 4794 | Misconfigured Remote Access Systems | critical | 8.5 | 1 | Data Breach |
| 4795 | human error (employee tricked into clicking malicious link) | critical | 8.5 | 1 | phishing |
| 4796 | Unverified third-party package installation | critical | 8.5 | 1 | Supply Chain Attack |
| 4797 | CVE-2024-12847 (Netgear DGN1000/DGN2000) | critical | 8.5 | 1 | Exploit Trends |
| 4798 | Lack of Cybersecurity Leadership | critical | 8.5 | 1 | Potential Data Breach |
| 4799 | Token Sprawl | critical | 8.5 | 1 | Data Breach |
| 4800 | Abuse of Google services (redirects, tracking infrastructure), URL hash fragments, lack of real-time URL scanning | critical | 8.5 | 1 | Phishing |
| 4801 | Unverified GitHub repositories | critical | 8.5 | 1 | Malware Campaign |
| 4802 | Asymmetric messaging (HTML vs. plain-text) | critical | 8.5 | 1 | Data Breach |
| 4803 | Inadequate physical access controls | critical | 8.5 | 1 | Data Breach |
| 4804 | VPN device vulnerability | critical | 8.5 | 1 | Data Breach |
| 4805 | Plain text storage of login details | critical | 8.5 | 1 | Data Breach |
| 4806 | Credential-based attack | critical | 8.5 | 1 | Data Breach |
| 4807 | Poor credential hygiene (hard-coded/exposed credentials) | critical | 8.5 | 1 | Data Breach |
| 4808 | Vulnerability with technology vendor | critical | 8.5 | 1 | Data Breach |
| 4809 | CVE-2025-13834 | critical | 8.5 | 1 | Information Leak |
| 4810 | gaps in business associate oversight | critical | 8.5 | 1 | ransomware |
| 4811 | AI_GENERATE_EMBEDDINGS (covert C2 channels) | critical | 8.5 | 1 | Data Exfiltration |
| 4812 | CVE-2025-4632 (Improper Pathname Limitation Leading to Arbitrary File Write) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4813 | CVE-2026-20131 | critical | 8.5 | 1 | Cyberespionage |
| 4814 | Unencrypted data stored in an internet-accessible environment | critical | 8.5 | 1 | Data Breach |
| 4815 | Adobe ColdFusion zero-days | critical | 8.5 | 1 | ransomware |
| 4816 | Weak encryption (unsalted MD5 password hashes) | critical | 8.5 | 1 | Data Breach |
| 4817 | Valid Log-in Credentials | critical | 8.5 | 1 | Data Breach |
| 4818 | Opportunistic scanning for sensitive file extensions (e.g., `.openclaw`) | critical | 8.5 | 1 | Infostealer Attack |
| 4819 | Malicious package versions (PyTorch Lightning 2.6.2, 2.6.3; intercom-client 7.0.4) | critical | 8.5 | 1 | Supply Chain Attack |
| 4820 | Limited-access function in internal support portal (proxy access to customer accounts) | critical | 8.5 | 1 | Cyberattack |
| 4821 | Reused passwords from data leaks | critical | 8.5 | 1 | Fraud/Scam |
| 4822 | Poor security practices, shared credentials or third-party tool managing access | critical | 8.5 | 1 | Account Takeover |
| 4823 | Lack of Privacy Controls | critical | 8.5 | 1 | Surveillance |
| 4824 | failure to deactivate former employee accounts | critical | 8.5 | 1 | data breach |
| 4825 | AI Agents Bypassing Human Oversight | critical | 8.5 | 1 | Data Breach |
| 4826 | DockerDash | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4827 | Image-set() fallback in Gmail | critical | 8.5 | 1 | Data Breach |
| 4828 | CBC encryption padding oracle | critical | 8.5 | 1 | Data Breach |
| 4829 | Incomplete measured-boot policy in HP ThinPro (failure to measure Linux kernel and initramfs) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4830 | CVE-2026-0073 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4831 | Weak Wi-Fi Network Security | critical | 8.5 | 1 | Data Breach |
| 4832 | Disabled security tools, outdated cyber hygiene practices | critical | 8.5 | 1 | Cyber Intrusion |
| 4833 | Insider access to patient records | critical | 8.5 | 1 | Data Breach |
| 4834 | Leak of User Emails | critical | 8.5 | 1 | Data Breach |
| 4835 | open-source_software_vulnerabilities | critical | 8.5 | 1 | data_breach |
| 4836 | Zero-day flaw in Oracle E-Business Suite (EBS) | critical | 8.5 | 1 | Data Breach |
| 4837 | Cisco SD-WAN flaws | critical | 8.5 | 1 | APT Activity |
| 4838 | CVE-2026-5281 (Use-After-Free in Google Dawn/WebGPU) | critical | 8.5 | 1 | Zero-Day Vulnerability Exploitation |
| 4839 | Lack of user awareness, 2FA bypass via fake prompts | critical | 8.5 | 1 | Phishing (AiTM - Adversary-in-the-Middle) |
| 4840 | Unrestricted Femtocell Certificates | critical | 8.5 | 1 | Data Breach |
| 4841 | CVE-2025-7851 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4842 | CVE-2026-62911 (CWE-294) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4843 | Insufficient Access Controls / Lack of Monitoring | critical | 8.5 | 1 | Unauthorized Access / Data Breach |
| 4844 | CVE-2026-5509 | critical | 8.5 | 1 | Command Injection |
| 4845 | CVE-2026-3102 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4846 | CVE-2025-71258 | critical | 8.5 | 1 | Malware Distribution |
| 4847 | Social Engineering, Native Messaging Manifest Bypass | critical | 8.5 | 1 | Phishing, Backdoor Deployment, Malicious Browser Extension |
| 4848 | Windows automatic DLL loading | critical | 8.5 | 1 | Malware Campaign |
| 4849 | Lack of phishing-resistant MFA, human error (trust in fake IT support) | critical | 8.5 | 1 | Phishing |
| 4850 | CVE-2026-31431 | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 4851 | Misconfigured Amazon Web Services S3 buckets | critical | 8.5 | 1 | Data Leak |
| 4852 | Malware deployment on third-party vendor employee device | critical | 8.5 | 1 | Data Breach |
| 4853 | SOHO devices | critical | 8.5 | 1 | Credential Theft |
| 4854 | CVE-2025-20352 (SNMP RCE in Cisco IOS/IOS XE) | critical | 8.5 | 1 | unauthorized access |
| 4855 | Credentials exploitation | critical | 8.5 | 1 | Data Breach |
| 4856 | Biometric authentication exploitation | critical | 8.5 | 1 | Data Breach |
| 4857 | Microsoft Graph API abuse | critical | 8.5 | 1 | Malware |
| 4858 | publicly accessible repositories | critical | 8.5 | 1 | data exposure |
| 4859 | Improper use of private email account | critical | 8.5 | 1 | Data Breach |
| 4860 | CVE-2025-32896 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4861 | CVE-2026-34500 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4862 | Lateral Movement within Internal Systems | critical | 8.5 | 1 | Data Breach |
| 4863 | Unprotected Elasticsearch instance | critical | 8.5 | 1 | Data Exposure |
| 4864 | Misconfigured Salesforce instances | critical | 8.5 | 1 | Data Breach |
| 4865 | Lack of AI Governance Frameworks | critical | 8.5 | 1 | Data Leakage |
| 4866 | Shared AWS infrastructure misconfiguration | critical | 8.5 | 1 | Data Breach |
| 4867 | Arbitrary file read flaw | critical | 8.5 | 1 | Autonomous Hacking Campaign |
| 4868 | Insider Threat / Unauthorized Access | critical | 8.5 | 1 | Data Breach |
| 4869 | Outdated Security Protocols (vendor) | critical | 8.5 | 1 | Data Breach |
| 4870 | Inadequate security measures (unspecified) | critical | 8.5 | 1 | Data Breach |
| 4871 | Human Error (Credential Theft via Smishing) | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 4872 | PTC Windchill and FlexPLM flaw | critical | 8.5 | 1 | data_breach |
| 4873 | Unauthorized AI Data Access | critical | 8.5 | 1 | Data Breach |
| 4874 | CVE-2026-58443 (CWE-863: Incorrect Authorization) | critical | 8.5 | 1 | Authorization Bypass |
| 4875 | CVE-2026-52830 (GHSA-rxw2-pc8j-vxwm) | critical | 8.5 | 1 | Authentication Bypass |
| 4876 | CVE-2026-7313 (CVSS 8.7) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4877 | Metabase Zero-Day | critical | 8.5 | 1 | Data Breach |
| 4878 | Captive portal equipment misconfiguration, Microsoft Entra ID authentication abuse | critical | 8.5 | 1 | Cyber Espionage, Credential Theft, Malware Deployment |
| 4879 | lack of encryption for stored data | critical | 8.5 | 1 | data breach |
| 4880 | CVE-2026-21385 | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 4881 | Delayed Incident Reporting | critical | 8.5 | 1 | Data Breach |
| 4882 | Unauthenticated file upload flaw in Magento Open Source, Magento Enterprise, Adobe Commerce, and Adobe Commerce with the B2B module | critical | 8.5 | 1 | Defacement, Unauthorized File Upload |
| 4883 | SSH authentication bypass (exact vulnerability undisclosed) | critical | 8.5 | 1 | Unauthorized Access |
| 4884 | Insecure storage of sensitive documents by identity verification vendors | critical | 8.5 | 1 | Data Breach |
| 4885 | Unpatched RCE vulnerabilities | critical | 8.5 | 1 | Botnet |
| 4886 | Egress path in CTF task environment | critical | 8.5 | 1 | Unauthorized AI Model Access |
| 4887 | Argument injection in MicrositeURL and CloudPages | critical | 8.5 | 1 | Data Breach |
| 4888 | Lack of Security Reviews | critical | 8.5 | 1 | Security Oversight |
| 4889 | Lack of default sandboxing, Ineffective filtering of untrusted content, Plaintext storage of API keys and session tokens, Reliance on language models for critical security decisions, Execution of tool calls without explicit user approval | critical | 8.5 | 1 | Malware Distribution, Data Exfiltration, Prompt Injection, Backdoor Installation |
| 4890 | Publicly Exposed API Token | critical | 8.5 | 1 | Data Breach (OAuth Token Compromise) |
| 4891 | AI-driven systems and expanded attack surfaces | critical | 8.5 | 1 | Data Breach |
| 4892 | Impersonation of legitimate app, lack of App Store vetting for enterprise distribution certificates | critical | 8.5 | 1 | Scam / Fraudulent App |
| 4893 | Human Error (Failure to redact sensitive information, improper email handling) | critical | 8.5 | 1 | Data Breach |
| 4894 | Flaw in order-tracking system plug-in allowing unauthorized access via order number manipulation | critical | 8.5 | 1 | Data Breach |
| 4895 | Prompt Injection Vulnerabilities | critical | 8.5 | 1 | AI Security Vulnerabilities |
| 4896 | CVE-2025-54897 (SharePoint RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4897 | Insecure data transmission by browser extensions | critical | 8.5 | 1 | Data Leakage |
| 4898 | CVE-2026-11311 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4899 | Windows User Profile Service Registry Hive Loading | critical | 8.5 | 1 | Privilege Escalation |
| 4900 | Improper key management, lack of automated key rotation | critical | 8.5 | 1 | Data Leak |
| 4901 | Exploitation of health information exchange systems, fake NPI numbers, and shell companies | critical | 8.5 | 1 | Data Breach |
| 4902 | Progress MOVEit Transfer tool | critical | 8.5 | 1 | Data Breach |
| 4903 | CVE-2026-57239 | critical | 8.5 | 1 | Privilege Escalation |
| 4904 | Lack of Encryption on Laptop | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 4905 | Lack of DNS query monitoring in ChatGPT's execution environment | critical | 8.5 | 1 | Data Exfiltration |
| 4906 | active former employee credentials | critical | 8.5 | 1 | data breach |
| 4907 | Bug in secondary code path failing to confirm email address match during password reset | critical | 8.5 | 1 | Account Takeover |
| 4908 | Unauthorized Cloudflare configuration modifications, Terraform module caching disabled | critical | 8.5 | 1 | Supply-Chain Attack |
| 4909 | Plug-in on e-commerce platform | critical | 8.5 | 1 | Data Breach |
| 4910 | Unencrypted data storage on DJI servers | critical | 8.5 | 1 | Data Exposure |
| 4911 | Paste race condition in Yahoo/AOL | critical | 8.5 | 1 | Data Breach |
| 4912 | IDOR | critical | 8.5 | 1 | Data Breach |
| 4913 | Error in server configuration change | critical | 8.5 | 1 | Data Breach |
| 4914 | Oracle E-Business Suite (Zero-Day) | critical | 8.5 | 1 | Cyberattack (Data Breach) |
| 4915 | CVE-2025-33228 | critical | 8.5 | 1 | Vulnerability |
| 4916 | Excessive OAuth permissions (Mail.Read, offline_access, profile/openid) | critical | 8.5 | 1 | OAuth Abuse |
| 4917 | Broken Object Level Authorization (BOLA) | critical | 8.5 | 1 | Data Breach |
| 4918 | Human Trust and Error (Bypassed Security Awareness Training) | critical | 8.5 | 1 | Data Breach |
| 4919 | Multi-tenant SaaS identity platform vulnerabilities | critical | 8.5 | 1 | AI-related identity breach |
| 4920 | Vulnerability identified and patched | critical | 8.5 | 1 | Data Breach |
| 4921 | Hardcoded authentication key | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4922 | CVE-2026-0251 | critical | 8.5 | 1 | Privilege Escalation |
| 4923 | Lack of authentication controls, Aftermarket modifications, Unrestricted AI-driven data collection, Subcontractor access to sensitive data | critical | 8.5 | 1 | Data Breach, Compliance Violation, Privacy Violation |
| 4924 | CVE-2026-85061 (GHSA-jrc7-96c5-q579) | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4925 | Lack of encryption for sensitive data | critical | 8.5 | 1 | Data Breach |
| 4926 | Security lapses | critical | 8.5 | 1 | Data Breach |
| 4927 | CVE-2025-52436 (Improper Neutralization of Input During Web Page Generation - CWE-79) | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4928 | Software Vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4929 | Trusted Hiring Pipelines | critical | 8.5 | 1 | Malware Deployment |
| 4930 | CVE-2026-6685 (Unsigned subtraction wrap) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4931 | weak threat-detection system | critical | 8.5 | 1 | data breach |
| 4932 | credential and secret exposure | critical | 8.5 | 1 | identity-based attack |
| 4933 | Unauthorized data collection via embedded tracking tool | critical | 8.5 | 1 | Data Harvesting |
| 4934 | Open Registration Endpoint (Design Hub) | critical | 8.5 | 1 | Data Exposure |
| 4935 | Weak Authentication Mechanisms (e.g., no 2FA) | critical | 8.5 | 1 | Privacy Violation |
| 4936 | excessive standing privileges | critical | 8.5 | 1 | identity-based attack |
| 4937 | CVE-2025-54910 (Office RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4938 | Inadequate internal controls and monitoring mechanisms | critical | 8.5 | 1 | Unauthorized Data Access |
| 4939 | Trusted domain abuse (googletagmanager.com, api.stripe.com), lack of strict content security policies (CSP) | critical | 8.5 | 1 | Magecart (Digital Skimming) |
| 4940 | CVE-2026-9770 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4941 | Inactive user accounts not deactivated | critical | 8.5 | 1 | Data Breach |
| 4942 | lack of code signing verification for replaced applications | critical | 8.5 | 1 | malware |
| 4943 | delayed breach notifications | critical | 8.5 | 1 | ransomware |
| 4944 | Security flaw | critical | 8.5 | 1 | Data Breach |
| 4945 | CVE-2026-3888 | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 4946 | Human error in file-sharing settings (Google Workspace for Education/Microsoft Education) | critical | 8.5 | 1 | Data Exposure |
| 4947 | Human Error (Inadvertent Upload to External AI Platform) | critical | 8.5 | 1 | Data Breach |
| 4948 | AI-Specific Attack Vectors (Prompt Injection, Model Poisoning) | critical | 8.5 | 1 | Supply Chain Attack |
| 4949 | Progress Software's MOVEit Transfer application | critical | 8.5 | 1 | Data Breach |
| 4950 | Improper Access Control (routerd.passwd_set method) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4951 | GrafanaGhost (flaw in URL validation for AI components) | critical | 8.5 | 1 | Data Exfiltration |
| 4952 | Human Weakness in Customer Service | critical | 8.5 | 1 | Data Breach |
| 4953 | API key and access token theft | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4954 | Trust-based Social Engineering | critical | 8.5 | 1 | Malware Distribution |
| 4955 | CVE-2026-3844 (Breeze caching plugin) | critical | 8.5 | 1 | Webshell Attack |
| 4956 | Insufficient network monitoring for suspicious activity | critical | 8.5 | 1 | Data Breach |
| 4957 | CVE-2026-22219 (SSRF) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4958 | VS Code zero-day | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4959 | Lack of domain verification during account creation | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 4960 | Inadequate security on WordPress-hosted infrastructure | critical | 8.5 | 1 | Data Breach |
| 4961 | Misunderstandings over Data Ownership | critical | 8.5 | 1 | Insider Threat |
| 4962 | Improper third-party access to confidential records | critical | 8.5 | 1 | Data Breach |
| 4963 | Undisclosed file-transfer vulnerability | critical | 8.5 | 1 | Vulnerability |
| 4964 | Glitch in License Express website | critical | 8.5 | 1 | Data Exposure |
| 4965 | Reused credentials from older data breaches | critical | 8.5 | 1 | Data Breach |
| 4966 | Compromised Administrator Account | critical | 8.5 | 1 | Ransomware |
| 4967 | Vulnerabilities in Salesforce-hosted databases | critical | 8.5 | 1 | Data Breach |
| 4968 | Poor Staff Awareness of Insider Threats | critical | 8.5 | 1 | Unauthorized Access |
| 4969 | Lack of Authentication or Access Restrictions | critical | 8.5 | 1 | Data Leak |
| 4970 | Lack of Access Controls / Insider Threat | critical | 8.5 | 1 | Data Breach |
| 4971 | OpenAI-compatible APIs (port 8000) | critical | 8.5 | 1 | LLMjacking |
| 4972 | Credential Reuse | critical | 8.5 | 1 | Credential Exposure |
| 4973 | DoS in compressed-RTF attachments | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 4974 | MFA bypass via Evilginx-style reverse proxies, Device Code Flow abuse, session token interception | critical | 8.5 | 1 | Phishing |
| 4975 | Server Security Issue | critical | 8.5 | 1 | Data Breach |
| 4976 | Improper Access by Employee | critical | 8.5 | 1 | Data Breach |
| 4977 | Human Error (Social Engineering via Phone Calls) | critical | 8.5 | 1 | Data Breach |
| 4978 | CVE-2025-53652 | critical | 8.5 | 1 | Command Injection |
| 4979 | CVE-2026-7198 (CVSS 9.8) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4980 | Lack of Command-Line Execution Awareness | critical | 8.5 | 1 | APT (Advanced Persistent Threat) |
| 4981 | CVE-2026-25750 (Insecure `baseUrl` parameter in LangSmith Studio) | critical | 8.5 | 1 | API Misconfiguration |
| 4982 | Session token hijacking | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 4983 | Legacy email protections | critical | 8.5 | 1 | Phishing |
| 4984 | Inadequate security awareness training | critical | 8.5 | 1 | Phishing |
| 4985 | Employee Bypass of Sanctioned Tools | critical | 8.5 | 1 | Data Leakage |
| 4986 | CVE-2025-5777 (CitrixBleed 2) | critical | 8.5 | 1 | Reconnaissance |
| 4987 | User Privacy | critical | 8.5 | 1 | Privacy Breach |
| 4988 | CVE-2026-3063 (Improper implementation in DevTools) | critical | 8.5 | 1 | Vulnerability Patch |
| 4989 | CVE-2026-21570 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4990 | CVE-2025-8424 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4991 | Pointer authentication (PAC) bypasses | critical | 8.5 | 1 | Exploit Kit |
| 4992 | Debug flag (`setIsDebugMode(true)`) left in production builds | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4993 | AI-Generated Convincing Impersonations | critical | 8.5 | 1 | Data Breach |
| 4994 | Weakly validated XPC connections, Interface Builder (NIB) file injection, kernel code-signing trust cache persistence | critical | 8.5 | 1 | Privilege Escalation / EDR Bypass |
| 4995 | Use of Pirated Corporate Software | critical | 8.5 | 1 | Info-Stealing |
| 4996 | Stolen web cookies (session IDs, personal data) | critical | 8.5 | 1 | Data Exposure |
| 4997 | E-commerce System | critical | 8.5 | 1 | Data Breach |
| 4998 | Decentralized data movement systems | critical | 8.5 | 1 | Data Governance Blind Spot |
| 4999 | Bypassed multi-factor authentication (MFA) | critical | 8.5 | 1 | Data Breach |
| 5000 | Improper handling of inter-app data access in EngageLab SDK | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5001 | Weak or Compromised Employee Credentials | critical | 8.5 | 1 | Data Breach |
| 5002 | Abuse of Microsoft’s Artifact Signing system | critical | 8.5 | 1 | Malware-Signing-as-a-Service (MSaaS) Disruption |
| 5003 | Fake Office 365 login pages | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 5004 | Squidbleed (CVE-2026-47729) | critical | 8.5 | 1 | Memory Leak Vulnerability |
| 5005 | Symbolic link following (CWE-61), UI misrepresentation (CWE-451) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5006 | macOS Script Editor (applescript:// links), Refined ClickFix Technique | critical | 8.5 | 1 | Malware Campaign |
| 5007 | Unrestricted remote-support tools | critical | 8.5 | 1 | Phishing |
| 5008 | CSRF Protection Mechanism in Ruby on Rails | critical | 8.5 | 1 | Vulnerability |
| 5009 | Inadequate employee training on cybersecurity risks | critical | 8.5 | 1 | Data Breach |
| 5010 | Missing row-level security (RLS), role-based access controls, and logic flaws in authentication | critical | 8.5 | 1 | Data Breach |
| 5011 | Unprotected publicly accessible database | critical | 8.5 | 1 | Data Leak |
| 5012 | Programming flaw in platform | critical | 8.5 | 1 | Data Breach |
| 5013 | Identity verification vendor compromise | critical | 8.5 | 1 | Data Breach |
| 5014 | Unsecured Amazon Web Services (AWS) S3 bucket lacking proper access controls | critical | 8.5 | 1 | Data Breach |
| 5015 | cloud application misconfigurations | critical | 8.5 | 1 | phishing |
| 5016 | Fail-open design in security scanning system (CWE-636: Not Failing Securely) | critical | 8.5 | 1 | Supply Chain Attack |
| 5017 | Insider access, malware backdoor | critical | 8.5 | 1 | Cyber-enabled drug trafficking |
| 5018 | CVE-2026-2287 | critical | 8.5 | 1 | Remote Code Execution |
| 5019 | Human Error, Lack of Rate-Limiting and CAPTCHA Protections for APIs, Poor Credential and Certificate Management | critical | 8.5 | 1 | Data Breach |
| 5020 | CVE-2026-33829 | critical | 8.5 | 1 | Information Disclosure |
| 5021 | Microsoft’s legitimate device code authentication flow | critical | 8.5 | 1 | Phishing |
| 5022 | Weak Authentication in AI Platforms | critical | 8.5 | 1 | Data Leakage |
| 5023 | SonicWall SSL VPN vulnerabilities | critical | 8.5 | 1 | ransomware |
| 5024 | Exposed NPM token from misconfigured CircleCI job (suspected) | critical | 8.5 | 1 | Supply-Chain Attack |
| 5025 | Support Credentials | critical | 8.5 | 1 | Data Breach |
| 5026 | Service Account Credential | critical | 8.5 | 1 | Data Breach |
| 5027 | CVE-2025-61882 (Zero-day in Oracle E-Business Suite) | critical | 8.5 | 1 | Data Breach |
| 5028 | Fingerprinting | critical | 8.5 | 1 | Phishing |
| 5029 | Vulnerability in third-party contractor’s software | critical | 8.5 | 1 | Data Breach |
| 5030 | Prior data exposures | critical | 8.5 | 1 | Data Breach |
| 5031 | Excessive data access privileges | critical | 8.5 | 1 | Data Breach |
| 5032 | Unknown vulnerability in external service | critical | 8.5 | 1 | AI-driven unauthorized access |
| 5033 | CVE-2024-28989 | critical | 8.5 | 1 | Vulnerability Exploit |
| 5034 | CVE-2025-23121 | critical | 8.5 | 1 | Vulnerability |
| 5035 | Poor security practices for remote logins | critical | 8.5 | 1 | Data Breach |
| 5036 | Improper data handling via third-party tracking tools (e.g., Google Analytics, Meta Pixel) | critical | 8.5 | 1 | Data Privacy Breach |
| 5037 | Lack of Monitoring for Unauthorized Data Exfiltration | critical | 8.5 | 1 | Data Breach |
| 5038 | Employee targeted via vishing | critical | 8.5 | 1 | Data Breach |
| 5039 | Centralized biometric databases, Lack of robust safeguards, Third-party vendor vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 5040 | CVE-2025-9368 (Resource Allocation Without Limits) | critical | 8.5 | 1 | Denial-of-Service |
| 5041 | Privilege escalation vulnerability in Kaspersky Endpoint Security UI process | critical | 8.5 | 1 | Privilege Escalation |
| 5042 | CVE-2025-33231 | critical | 8.5 | 1 | Vulnerability |
| 5043 | unprotected storage bucket | critical | 8.5 | 1 | data breach |
| 5044 | Social engineering, exploitation of legitimate communication channels | critical | 8.5 | 1 | Phishing Scam |
| 5045 | Weak BYOD Policies | critical | 8.5 | 1 | Insider Threat |
| 5046 | Lack of monitoring for suspicious activity | critical | 8.5 | 1 | Data Breach |
| 5047 | CVE-2026-7195 (CVSS 8.8) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5048 | Unauthorized code in third-party vendor's application | critical | 8.5 | 1 | Data Breach |
| 5049 | CVE-2021-29441 (Nacos configuration server) | critical | 8.5 | 1 | Webshell Attack |
| 5050 | Expired email domain allowing credential reset | critical | 8.5 | 1 | Supply Chain Attack |
| 5051 | CSS pseudo-elements and opacity tricks in Fastmail | critical | 8.5 | 1 | Data Breach |
| 5052 | CVE-2025-27920 (Directory Traversal), CVE-2025-27921 (Reflected XSS - unused) | critical | 8.5 | 1 | Cyber Espionage |
| 5053 | CWE-601: URL Redirection to Untrusted Site (Open Redirect) (via token manipulation) | critical | 8.5 | 1 | Data Breach |
| 5054 | Vulnerability in MOBO subscriber management tool | critical | 8.5 | 1 | Data Breach |
| 5055 | CVE-2025-14847 (MongoBleed) - unverified | critical | 8.5 | 1 | In-game abuse |
| 5056 | Overly permissive guest user configurations in Salesforce Experience Cloud | critical | 8.5 | 1 | Data Theft |
| 5057 | nx npm Package Compromise | critical | 8.5 | 1 | Zero-day Exploitation |
| 5058 | Debug Log File | critical | 8.5 | 1 | Data Breach |
| 5059 | CVE-2026-54432 | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 5060 | Disabled Workspace Trust (Cursor Editor) | critical | 8.5 | 1 | Malware (Infostealer) |
| 5061 | Incorrectly configured database | critical | 8.5 | 1 | Data Leak |
| 5062 | CVE-2024-5806 | critical | 8.5 | 1 | Supply Chain Attack, Data Breach, Ransomware |
| 5063 | Unprotected 'unlink()' call enabling unauthenticated file deletion | critical | 8.5 | 1 | SQL Injection |
| 5064 | CVE-2026-23597 | critical | 8.5 | 1 | Privilege Escalation |
| 5065 | CVE-2026-65105 (Unauthenticated API exposure in NVIDIA NemoClaw) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5066 | CVE-2026-58704 (Google Pixel Modem) | critical | 8.5 | 1 | AI-driven cyberattack |
| 5067 | Insufficient behavioral monitoring | critical | 8.5 | 1 | AI-driven attack |
| 5068 | Unsecured Amazon S3 bucket with backend bug allowing unauthorized access to file directory | critical | 8.5 | 1 | Data Exposure |
| 5069 | Unsecured cloud storage, inadequate access controls, insufficient monitoring | critical | 8.5 | 1 | Data Exposure |
| 5070 | Social engineering (PIN disclosure) | critical | 8.5 | 1 | Phishing |
| 5071 | Data Migration Error | critical | 8.5 | 1 | Data Breach |
| 5072 | legitimate credentials misuse | critical | 8.5 | 1 | phishing |
| 5073 | weak cybersecurity safeguards in third-party vendor (Salesforce) | critical | 8.5 | 1 | data breach |
| 5074 | social engineering targeting IT helpdesks | critical | 8.5 | 1 | data breach |
| 5075 | Network Access Feature in Claude (Sandbox Environment) | critical | 8.5 | 1 | Data Exfiltration |
| 5076 | Incomplete containment of earlier breach (hackerbot-claw), non-atomic token rotation, mutable version tags | critical | 8.5 | 1 | Supply Chain Attack |
| 5077 | User trust and lack of awareness | critical | 8.5 | 1 | Phishing |
| 5078 | CVE-2026-24281 | critical | 8.5 | 1 | Data Exposure |
| 5079 | FortiGate Misconfiguration | critical | 8.5 | 1 | Zero-day Exploitation |
| 5080 | CVE-2021-47960 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5081 | CVE-2026-34926 (Directory Traversal - CWE-23) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5082 | Misconfigured integrations, exposed credentials, authentication tokens | critical | 8.5 | 1 | Data Breach, Extortion |
| 5083 | CVE-2026-13230 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5084 | Hadoop WebHDFS Hardcoded Credentials | critical | 8.5 | 1 | AI Security Breach |
| 5085 | Android Wireless Debugging, Accessibility Service permissions, Developer Options | critical | 8.5 | 1 | Malware (Banking Trojan) |
| 5086 | unsecured backup databases co-located with active databases | critical | 8.5 | 1 | data breach |
| 5087 | CVE-2025-54820 (Stack-based buffer overflow, CWE-121) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 5088 | CVE-2026-6267 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 5089 | Employee deception, potential weak passwords or third-party vulnerabilities (Okta identity management service) | critical | 8.5 | 1 | Data Breach |
| 5090 | Improper data storage practices | critical | 8.5 | 1 | Data Breach |
| 5091 | CVE-2026-0740 (Ninja Forms) | critical | 8.5 | 1 | Exploitation Campaign |
| 5092 | Lack of rate-limiting measures | critical | 8.5 | 1 | Data Breach |
| 5093 | CVE-2023-33538 | critical | 8.5 | 1 | Botnet Deployment |
| 5094 | WP File Manager (WordPress) | critical | 8.5 | 1 | Webshell Attack |
| 5095 | third-party security gaps | critical | 8.5 | 1 | data breach |
| 5096 | Modification of Rabby Wallet's `persistAllKeyrings()` function to exfiltrate unencrypted keyring data | critical | 8.5 | 1 | Malware Distribution |
| 5097 | Insufficient user identification and authentication (UIA) controls | critical | 8.5 | 1 | Data Security Audit |
| 5098 | Amazon S3 Storage Account | critical | 8.5 | 1 | Data Breach |
| 5099 | Inadequate protection of sensitive consumer data | critical | 8.5 | 1 | Data Breach |
| 5100 | Vulnerabilities in a property information-sharing system used exclusively by real estate companies | critical | 8.5 | 1 | Data Breach |
| 5101 | CVE-2026-4782 (CVSS 6.5) | critical | 8.5 | 1 | SQL Injection |
| 5102 | URL Vulnerability | critical | 8.5 | 1 | Data Breach |
| 5103 | Citrix software vulnerability | critical | 8.5 | 1 | Data Breach |
| 5104 | Insufficient VPN authentication, ineffective abnormal behavior detection | critical | 8.5 | 1 | Data Breach |
| 5105 | SQLi in Postgres MCP (bypassing read-only restrictions) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 5106 | Third-party reporting tool (Metabase) vulnerability | critical | 8.5 | 1 | Data Breach |
| 5107 | Access Control Weakness | critical | 8.5 | 1 | Data Exposure |
| 5108 | Human Error (Telecommunications Employee Deception) | critical | 8.5 | 1 | Data Breach |
| 5109 | CVE-2026-50507 (CWE-306: Missing Authentication for Critical Function) | critical | 8.5 | 1 | Security Feature Bypass |
| 5110 | Human Error (Employee Compromise) | critical | 8.5 | 1 | Data Breach |
| 5111 | Reliance on phone numbers for multi-factor authentication (SMS-based), weak email security, reused passwords, exposed personal data from breaches | critical | 8.5 | 1 | Mobile Fraud (SIM Swapping/Account Takeover) |
| 5112 | WhatsApp Desktop Client | critical | 8.5 | 1 | Malware Campaign |
| 5113 | CVE-2026-1357 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 5114 | Compromised financial advisors' devices | critical | 8.5 | 1 | Cybersecurity Breach |
| 5115 | Unknown vulnerability in the spam quarantine server software | critical | 8.5 | 1 | Data Breach |
| 5116 | Visual Studio Code tasks.json | critical | 8.5 | 1 | Supply Chain Attack |
| 5117 | Open-access data sharing model and inadvertent exposure of raw data through published code | critical | 8.5 | 1 | Data Breach |
| 5118 | Lack of runtime risk controls | critical | 8.5 | 1 | AI-related identity breach |
| 5119 | Windows Shell Spoofing (CVE-2026-32202) | critical | 8.5 | 1 | Data Breach |
| 5120 | WordPress plugin vulnerability (WooCommerce Wholesale Lead Capture) | critical | 8.5 | 1 | AI-driven attack |
| 5121 | Authentication failures | critical | 8.5 | 1 | API Security Breach |
| 5122 | Security access codes obtained through deception | critical | 8.5 | 1 | Hacking, Identity Theft, Data Breach, Cyberstalking |
| 5123 | CVE-2025-XXXX (WebKit Zero-Day 1) | critical | 8.5 | 1 | Zero-Day Exploit |
| 5124 | Internal Authentication API bug | critical | 8.5 | 1 | Authentication Vulnerability |
| 5125 | Lack of Multi-Factor Authentication (implied) | critical | 8.5 | 1 | Data Breach |
| 5126 | Insufficient Mass Email Controls | critical | 8.5 | 1 | Data Breach |
| 5127 | Six low-severity flaws | critical | 8.5 | 1 | Data Leak |
| 5128 | Human Error (Improper Document Upload) | critical | 8.5 | 1 | Data Breach (Inadvertent Disclosure) |
| 5129 | Improper pinning of user pages in `rds_message_zcopy_from_user()` function (RDS zerocopy send path) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 5130 | sp_invoke_external_rest_endpoint (arbitrary HTTP requests) | critical | 8.5 | 1 | Data Exfiltration |
| 5131 | CVE-2025-31334 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5132 | CVE-2026-1220 (Race Condition in V8 JavaScript Engine) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5133 | Key Reuse Vulnerability (Android) | critical | 8.5 | 1 | Privacy Violation |
| 5134 | Lack of token revocation controls | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 5135 | CVE-2026-50656 | critical | 8.5 | 1 | Data Breach |
| 5136 | CVE-2026-3519 | critical | 8.5 | 1 | vulnerability |
| 5137 | CVE-2026-21513 | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 5138 | Website Bug | critical | 8.5 | 1 | Data Exposure |
| 5139 | Email Misdirection | critical | 8.5 | 1 | Data Breach |
| 5140 | Apple Notarization Bypass (ChillyHell) | critical | 8.5 | 1 | Malware (Infostealer) |
| 5141 | GoAnywhere MFT SaaS | critical | 8.5 | 1 | Data Breach |
| 5142 | Lack of access controls and monitoring | critical | 8.5 | 1 | Unauthorized Data Access |
| 5143 | Abuse of Microsoft Phone Link synchronization feature, living-off-the-land binaries (LOLBins) | critical | 8.5 | 1 | Cyberespionage, Malware Attack |
| 5144 | Major Security Flaw in Website | critical | 8.5 | 1 | Data Exposure |
| 5145 | Stack-based buffer overflow (JVN#35567473) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 5146 | Unauthorized access to business email account | critical | 8.5 | 1 | Data Breach |
| 5147 | lack of phishing-resistant authentication | critical | 8.5 | 1 | phishing |
| 5148 | Lack of cybersecurity hygiene, insufficient vendor expertise | critical | 8.5 | 1 | Security Probe |
| 5149 | Sequential user ID system with no authentication or rate limiting | critical | 8.5 | 1 | Data Breach |
| 5150 | Weak and reused passwords | critical | 8.5 | 1 | Account Takeover |
| 5151 | CVE-2025-67601 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5152 | CVE-2026-0709 | critical | 8.5 | 1 | Supply Chain Attack |
| 5153 | CVE-2026-24308 | critical | 8.5 | 1 | Data Exposure |
| 5154 | Improperly secured file on public-facing website | critical | 8.5 | 1 | Data Breach |
| 5155 | Weak Accountability | critical | 8.5 | 1 | Data Breach |
| 5156 | XSS in GitLab Duo | critical | 8.5 | 1 | Vulnerability Disclosure |
| 5157 | Lack of strict email authentication (SPF, DMARC, DKIM), whitelisted domains, MFA bypass via token replay | critical | 8.5 | 1 | Phishing, Adversary-in-the-Middle (AiTM), Device-Code Phishing |
| 5158 | Insufficient Identity Management | critical | 8.5 | 1 | Data Breach |
| 5159 | internal API vulnerability (details undisclosed) | critical | 8.5 | 1 | data breach |
| 5160 | Human Error (Tricked Call Center Worker) | critical | 8.5 | 1 | Data Breach |
| 5161 | Plaintext Password Transmission (Design Hub) | critical | 8.5 | 1 | Data Exposure |
| 5162 | Unsecured email API endpoints with improper input validation | critical | 8.5 | 1 | Phishing, Data Theft, Persistent Access |
| 5163 | Bias in AI algorithms (e.g., loan approvals, credit scoring) | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 5164 | CVE-2014-0160 (Heartbleed - Out-of-Bounds Read in OpenSSL) | critical | 8.5 | 1 | Memory Corruption |
| 5165 | Legitimate API traffic for command-and-control (C2) communications | critical | 8.5 | 1 | Cyber Espionage |
| 5166 | Shadow AI usage | critical | 8.5 | 1 | AI-related identity breach |
| 5167 | CVE-2026-85102 (Check Point VPN) | critical | 8.5 | 1 | AI-driven cyberattack |
| 5168 | CVE-2025-4123 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5169 | CVE-2026-20163 (Improper Neutralization of Special Elements used in a Command - CWE-77) | critical | 8.5 | 1 | Remote Command Execution (RCE) |
| 5170 | Debug flag (`setIsDebugMode(true)`) left active in production code | critical | 8.5 | 1 | Account Takeover |
| 5171 | Improper data handling during system restoration | critical | 8.5 | 1 | Data Breach |
| 5172 | CVE-2024-34102 (CosmicSting) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5173 | DNS Infrastructure Weakness (Box Domains) | critical | 8.5 | 1 | DNS Hijacking |
| 5174 | Improper Database Security | critical | 8.5 | 1 | Data Leak |
| 5175 | DLL Sideloading via YY platform's updat.exe | critical | 8.5 | 1 | Malware Campaign |
| 5176 | known vulnerabilities in open-source software | critical | 8.5 | 1 | AI-powered cyberattack |
| 5177 | CVE-2025-0520 (CVSS 9.4) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 5178 | CVE-2025-54236 (SessionReaper) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5179 | User account compromise | critical | 8.5 | 1 | Data Breach |
| 5180 | Unverified Update Mechanism (Lack of Code Signing) | critical | 8.5 | 1 | Vulnerability |
| 5181 | Vulnerability in Gladinet CentreStack | critical | 8.5 | 1 | Data Breach |
| 5182 | Weaknesses in IVR System Authentication | critical | 8.5 | 1 | Cyberattack |
| 5183 | Security flaw in third-party software | critical | 8.5 | 1 | Data Breach |
| 5184 | Stolen npm/GitHub publishing tokens, cloud credentials, SSH keys, and CI/CD pipeline secrets | critical | 8.5 | 1 | Supply-Chain Attack |
| 5185 | Human Trust (Job Seekers) | critical | 8.5 | 1 | APT (Advanced Persistent Threat) |
| 5186 | SIM-swapping | critical | 8.5 | 1 | SIM-swapping |
| 5187 | Zombie Card Attack | critical | 8.5 | 1 | Data Breach |
| 5188 | Weak authentication checks, lack of rate-limiting controls in AI-driven password reset process | critical | 8.5 | 1 | Account Takeover |
| 5189 | Lack of Policy Enforcement for AI Tool Usage | critical | 8.5 | 1 | Data Breach |
| 5190 | Social Engineering (Employee Compromise) | critical | 8.5 | 1 | Data Breach |
| 5191 | Unknown vulnerability in Oracle E-Business Suite (CVE not specified) | critical | 8.5 | 1 | Data Breach / Ransomware Attack |
| 5192 | Weaknesses in third-party integrations with Salesforce-connected applications (not Salesforce itself) | critical | 8.5 | 1 | Data Breach |
| 5193 | MOVEit Transfer file-sharing software vulnerability (prior incident) | critical | 8.5 | 1 | Ransomware |
| 5194 | Abandoned software in trusted repository | critical | 8.5 | 1 | Phishing |
| 5195 | Indirect prompt injection in AI agents | critical | 8.5 | 1 | Indirect Prompt Injection Attack |
| 5196 | CVE-2025-15630 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5197 | CVE-2026-65640 (GHSA-8vr3-7mxf-gx8w) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 5198 | Security vulnerability in pre-order process | critical | 8.5 | 1 | Data Breach |
| 5199 | Unsecured Data Transmission | critical | 8.5 | 1 | Data Breach |
| 5200 | WebAuthn origin requests | critical | 8.5 | 1 | Privacy Bypass |
| 5201 | Flash Player | critical | 8.5 | 1 | Cyber Attack |
| 5202 | Flaw in the project’s website | critical | 8.5 | 1 | Data Breach |
| 5203 | Inadequate internal monitoring and access controls | critical | 8.5 | 1 | Data Breach |
| 5204 | Resource Constraints in DHS | critical | 8.5 | 1 | Security Oversight |
| 5205 | Training gaps | critical | 8.5 | 1 | Data Breach |
| 5206 | Insufficient data security policies and controls | critical | 8.5 | 1 | Data Leak |
| 5207 | CVE-2025-9293 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5208 | unpatched vulnerabilities in enterprise software | critical | 8.5 | 1 | ransomware |
| 5209 | improper decommissioning of legacy cloud storage | critical | 8.5 | 1 | data breach |
| 5210 | Unpatched VPN endpoint | critical | 8.5 | 1 | Ransomware Attack |
| 5211 | Inconsistent security measures | critical | 8.5 | 1 | Phishing |
| 5212 | Inadequate data handling and publication controls | critical | 8.5 | 1 | Data Exposure |
| 5213 | MOVEit secure file transfer tool vulnerability | critical | 8.5 | 1 | Data Breach |
| 5214 | Oracle WebLogic Vulnerability (CVE not specified) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5215 | Public chat rooms unencrypted and accessible to any user, hardcoded LDAP credentials in shared scripts | critical | 8.5 | 1 | Data Breach |
| 5216 | CVE-2026-50661 | critical | 8.5 | 1 | Security Feature Bypass |
| 5217 | Exposed AWS cloud storage access key | critical | 8.5 | 1 | Data Breach |
| 5218 | Third-party authentication (Okta SSO) | critical | 8.5 | 1 | Data Breach |
| 5219 | CVE-2024-23222 (WebKit RCE - cassowary) | critical | 8.5 | 1 | Exploit Kit / Malware Campaign |
| 5220 | Multi-Factor Authentication (MFA) bypass, Session token hijacking, Credential theft via phishing kits | critical | 8.5 | 1 | Phishing/Vishing, Credential Theft, Data Breach, Session Hijacking |
| 5221 | Java Deserialization | critical | 8.5 | 1 | Malware Distribution |
| 5222 | MOVEit Transfer Zero-Day (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 5223 | Outdated TEE image reuse | critical | 8.5 | 1 | Zero-day vulnerability |
| 5224 | CVE-2026-20700 (Memory-corruption in dyld component) | critical | 8.5 | 1 | Zero-Day Exploit |
| 5225 | Human Trust and Psychological Manipulation | critical | 8.5 | 1 | Cryptocurrency Investment Fraud |
| 5226 | Insufficient input sanitization and double-parsing bug in 'Dispatch Search' feature | critical | 8.5 | 1 | Data Breach |
| 5227 | Over-privileged access, improper offboarding, lack of monitoring | critical | 8.5 | 1 | Insider Threat |
| 5228 | Unauthorized Plugin | critical | 8.5 | 1 | Data Breach |
| 5229 | Social Engineering (Urgent KYC/Billing Alerts) | critical | 8.5 | 1 | Phishing Scam |
| 5230 | Hardcoded credentials in web code | critical | 8.5 | 1 | Data Breach |
| 5231 | CREATE EXTERNAL MODEL (NTLM coercion) | critical | 8.5 | 1 | Data Exfiltration |
| 5232 | Lack of Physical Security for Development Device | critical | 8.5 | 1 | Trade Secret Theft |
| 5233 | CVE-2026-20896 | critical | 8.5 | 1 | Authentication Bypass |
| 5234 | Weak external access policies for collaboration platforms | critical | 8.5 | 1 | Phishing |
| 5235 | Unpatched vulnerabilities in GlobalProtect | critical | 8.5 | 1 | Privilege Escalation |
| 5236 | Salesforce integration flaw (Drift-Salesloft) | critical | 8.5 | 1 | data breach |
| 5237 | Client-Side Reward Points Validation (Mobile App) | critical | 8.5 | 1 | Data Exposure |
| 5238 | Broken Access Control (OWASP Top 10) | critical | 8.5 | 1 | Data Exposure |
| 5239 | unpatched cloud tools (speculated) | critical | 8.5 | 1 | data breach |
| 5240 | Ineffective Security Configurations | critical | 8.5 | 1 | Data Breach |
| 5241 | CVE-2025-15627 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5242 | Shared internal service (JFrog Artifactory) bridging isolated code-execution containers via Item Management API | critical | 8.5 | 1 | Data Theft |
| 5243 | fragmented infrastructure | critical | 8.5 | 1 | ransomware |
| 5244 | Lack of encryption in pager networks | critical | 8.5 | 1 | Data Exposure |
| 5245 | Unauthorized Access to Customer Account Information | critical | 8.5 | 1 | Data Exposure |
| 5246 | Clerical Error | critical | 8.5 | 1 | Data Breach |
| 5247 | Phone signal interception | critical | 8.5 | 1 | Surveillance |
| 5248 | CVE-2025-31125 | critical | 8.5 | 1 | Cyberattack |
| 5249 | AI-generated_deepfakes | critical | 8.5 | 1 | data_breach |
| 5250 | Third-party Salesforce tenant misconfiguration/access controls | critical | 8.5 | 1 | Data Breach |
| 5251 | CVE-2026-23111 (Use-after-free in nftables subsystem) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5252 | CVE-2026-74469 | critical | 8.5 | 1 | Privilege Escalation |
| 5253 | Unusual access to GitHub repositories | critical | 8.5 | 1 | Hacking/Unauthorized Access |
| 5254 | CVE-2026-85880 (Windows kernel privilege-escalation) | critical | 8.5 | 1 | Espionage, Cyber Attack |
| 5255 | Meraki API keys, unsecured surveillance systems | critical | 8.5 | 1 | Data Breach |
| 5256 | Misconfigured Storage Buckets | critical | 8.5 | 1 | Data Leak |
| 5257 | Unauthenticated AI services | critical | 8.5 | 1 | LLMjacking |
| 5258 | Expired domain takeover, lack of ongoing security validation for Office add-ins | critical | 8.5 | 1 | Phishing, Credential Theft, Data Exfiltration |
| 5259 | Zero-day vulnerability in MOVEit Transfer application | critical | 8.5 | 1 | Data Breach |
| 5260 | Account Compromise | critical | 8.5 | 1 | Data Breach |
| 5261 | CVE-2023-6895 | critical | 8.5 | 1 | Espionage |
| 5262 | Weak MD5 hashing | critical | 8.5 | 1 | Data Exposure |
| 5263 | Unpatched Smart Contract Bugs | critical | 8.5 | 1 | Privacy Violation |
| 5264 | Legitimate plugin disguise, credential harvesting via hardcoded server | critical | 8.5 | 1 | Malware Campaign |
| 5265 | Stolen WordPress credentials, DLL side-loading, infostealer malware | critical | 8.5 | 1 | Remote Access Trojan (RAT) Deployment |
| 5266 | SonicWall zero-days | critical | 8.5 | 1 | ransomware |
| 5267 | hardcoded secrets in code | critical | 8.5 | 1 | data exposure |
| 5268 | CVE-2026-27970 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 5269 | CISA-listed Known Exploited Vulnerabilities (KEVs) | critical | 8.5 | 1 | ransomware |
| 5270 | CVE-2026-3338 | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 5271 | CVE-2026-11645 (Out-of-bounds memory access in V8 JavaScript engine) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 5272 | Lack of Robust Guardrails for Non-Text Modalities | critical | 8.5 | 1 | Prompt Extraction |
| 5273 | Universal CSS injection in Opera GX's GX Mods feature | critical | 8.5 | 1 | Data Exfiltration |
| 5274 | CVE-2026-2447 (Heap buffer overflow in libvpx video codec) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5275 | Zero-day vulnerability in third-party software (patched post-incident) | critical | 8.5 | 1 | Data Breach |
| 5276 | Exposed Magicbell API Keys and Secrets | critical | 8.5 | 1 | Data Exposure |
| 5277 | Third-party vendor breach | critical | 8.5 | 1 | Data Breach |
| 5278 | Undisclosed flaw in package-installer tool | critical | 8.5 | 1 | AI Model Breach |
| 5279 | CVE-not-yet-assigned (as of description) – RCE via `new Function()` in `expr-eval` < 2.0.2 | critical | 8.5 | 1 | Vulnerability |
| 5280 | Weak/Reused Passwords (from third-party sources) | critical | 8.5 | 1 | Account Takeover |
| 5281 | Unpatched Security Gaps | critical | 8.5 | 1 | Security Oversight |
| 5282 | URL fetcher failing to block internal domains | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 5283 | Undisclosed zero-day vulnerability in WhatsApp calling feature | critical | 8.5 | 1 | Zero-Day Exploit |
| 5284 | Internal Collaboration Tool | critical | 8.5 | 1 | Data Breach |
| 5285 | CWE-506: Embedded Malicious Code | critical | 8.5 | 1 | Dependency Confusion |
| 5286 | Insufficient identity verification in hiring processes, reliance on social media badges | critical | 8.5 | 1 | Identity Fraud, Insider Threat, Cyber Espionage |
| 5287 | Misconfigured access control, lack of IP whitelisting | critical | 8.5 | 1 | Data Leak |
| 5288 | Lack of chip or tap-to-pay security on government benefits cards | critical | 8.5 | 1 | Skimming |
| 5289 | Unsecured digital identities for AI agents | critical | 8.5 | 1 | Data Leakage |
| 5290 | Session hijacking | critical | 8.5 | 1 | Malware (RAT) |
| 5291 | CVE-2026-68121 | critical | 8.5 | 1 | Privilege Escalation |
| 5292 | Unverified dependencies in development pipelines | critical | 8.5 | 1 | Supply-Chain Attack |
| 5293 | WebOTP API, Clipboard Access, Notification Control, PWA Installation Permissions, Android Permissions Abuse | critical | 8.5 | 1 | Phishing |
| 5294 | unencrypted patient records | critical | 8.5 | 1 | ransomware |
| 5295 | Public web server misconfiguration | critical | 8.5 | 1 | Data Breach |
| 5296 | VPN bypass | critical | 8.5 | 1 | Data Breach |
| 5297 | Failure to follow internal procedures and licensing obligations | critical | 8.5 | 1 | SIM Swap Attack |
| 5298 | Unsecured server, weak account security | critical | 8.5 | 1 | Data Breach |
| 5299 | Insufficient validation process for third-party API access | critical | 8.5 | 1 | Data Breach |
| 5300 | Perimeter security measures | critical | 8.5 | 1 | Data Breach |
| 5301 | ShadowLeak (CVE pending) | critical | 8.5 | 1 | Data Exfiltration |
| 5302 | Inconsistent DLP controls | critical | 8.5 | 1 | Data Breach |
| 5303 | Malicious OAuth app permissions | critical | 8.5 | 1 | Data Breach |
| 5304 | Shared contractor accounts, API key exposure, URL convention deduction | critical | 8.5 | 1 | Unauthorized Access |
| 5305 | account takeover (ATO) | critical | 8.5 | 1 | supply-chain attack |
| 5306 | Broken authorization boundary in AI workflows, failure to propagate requester identities to downstream actions | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 5307 | Social Engineering, VoIP Spoofing, Abuse of Legitimate Email Flows (SPF/DKIM Bypass) | critical | 8.5 | 1 | Phishing |
| 5308 | CVE-2025-32711 (CVSS 9.3) | critical | 8.5 | 1 | AI Command Injection |
| 5309 | CVE-2026-19490 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 5310 | Missing Reporting Mechanisms for Objectionable Content | critical | 8.5 | 1 | Data Breach |
| 5311 | Click2Gov Payment System | critical | 8.5 | 1 | Data Breach |
| 5312 | CVE-2025-55177 (WhatsApp Zero-Click) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5313 | MOVEit file-transfer vulnerability | critical | 8.5 | 1 | Data Breach |
| 5314 | CVE-2026-46331 (pedit COW) | critical | 8.5 | 1 | Privilege Escalation |
| 5315 | Improper cryptographic binding of encrypted reasoning traces to user sessions/model tiers | critical | 8.5 | 1 | Data Breach |
| 5316 | CVE-2025-33230 | critical | 8.5 | 1 | Vulnerability |
| 5317 | Shared Inbox Access | critical | 8.5 | 1 | Data Breach |
| 5318 | Absence of defensible deletion policies | critical | 8.5 | 1 | Data Breach |
| 5319 | misconfigured Azure Blob storage permissions | critical | 8.5 | 1 | data exposure |
| 5320 | Technical error in user data retrieval/logic (likely session or caching misconfiguration) | critical | 8.5 | 1 | Data Exposure (Unintentional Disclosure) |
| 5321 | CVE-2026-27739 | critical | 8.5 | 1 | SSRF (Server-Side Request Forgery) |
| 5322 | CVE-2025-49870 (Unauthenticated SQL Injection in PayPal IPN handling) | critical | 8.5 | 1 | Vulnerability |
| 5323 | Hardcoded secrets in AI-generated code, MCP configurations, overprivileged access | critical | 8.5 | 1 | Data Leak |
| 5324 | Path traversal (27.3%) | critical | 8.5 | 1 | API Security Breach |
| 5325 | Software vulnerabilities in AI tools (e.g., backdoors, bugs) | critical | 8.5 | 1 | Data Leakage |
| 5326 | weak access controls at third-party vendor | critical | 8.5 | 1 | data breach |
| 5327 | Excessive permissions in AI agents | critical | 8.5 | 1 | Data Breach |
| 5328 | Sleeping Beauty | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5329 | Misconfiguration in Trivy vulnerability scanner | critical | 8.5 | 1 | Supply Chain Attack |
| 5330 | CVE-2026-46376 (Use of Hard-coded Credentials - CWE-798) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5331 | Design flaw in metadata handling for public pages | critical | 8.5 | 1 | Privacy Leak |
| 5332 | Label elements and custom attributes in Outlook | critical | 8.5 | 1 | Data Breach |
| 5333 | CVE-2026-68820 | critical | 8.5 | 1 | Data Breach |
| 5334 | CVE-2025-59367 (Authentication Bypass in DSL-series routers) | critical | 8.5 | 1 | Vulnerability |
| 5335 | Lack of Physical Security / Unencrypted Device | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 5336 | CVE-2026-42208 | critical | 8.5 | 1 | SQL Injection |
| 5337 | Unsecured personal information handling | critical | 8.5 | 1 | Data Breach |
| 5338 | third-party_integrations | critical | 8.5 | 1 | data_breach |
| 5339 | CVE-2026-3337 | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 5340 | Third-Party Integrations | critical | 8.5 | 1 | Credential Exposure |
| 5341 | Lack of input validation in web configuration interfaces | critical | 8.5 | 1 | DNS Hijacking |
| 5342 | Microsoft Windows Vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5343 | DOM-Based UI Manipulation | critical | 8.5 | 1 | Vulnerability Disclosure |
| 5344 | Unencrypted backup media, unlocked storage cabinet | critical | 8.5 | 1 | Data Breach |
| 5345 | Default Password on Code Repository | critical | 8.5 | 1 | Data Exposure |
| 5346 | Publicly Accessible Firebase Storage Bucket | critical | 8.5 | 1 | Data Breach |
| 5347 | inadequate staff training | critical | 8.5 | 1 | data breach |
| 5348 | Blockchain immutability (append-only ledger), Lack of takedown mechanisms for decentralized infrastructure | critical | 8.5 | 1 | Info-Stealer / Malware |
| 5349 | CVE-2026-70329 (Integer Overflow/Wraparound - CWE-190) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 5350 | Poor M365 configurations | critical | 8.5 | 1 | Data Breach |
| 5351 | Overbroad OAuth Token Permissions | critical | 8.5 | 1 | Data Breach |
| 5352 | Flawed auto-populate feature in online quote platform | critical | 8.5 | 1 | Data Exposure |
| 5353 | WinRAR vulnerability | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5354 | Lack of user consent for data sharing with third-party ad platforms | critical | 8.5 | 1 | Privacy Violation |
| 5355 | Lack of robust identity verification during hiring process | critical | 8.5 | 1 | Data Breach (Insider Threat / Identity Misuse) |
| 5356 | Legal loophole exempting political parties from provincial privacy regulations | critical | 8.5 | 1 | Data Breach |
| 5357 | Improper handling of sensitive credentials in web assets | critical | 8.5 | 1 | Data Exposure |
| 5358 | CVE-2026-21514 (CWE-807 - Improper security decision-making based on untrusted inputs) | critical | 8.5 | 1 | Zero-Day Vulnerability Exploitation |
| 5359 | CVE-2025-68428 | critical | 8.5 | 1 | Local File Inclusion / Path Traversal |
| 5360 | Unsecured Internet-Connected Database | critical | 8.5 | 1 | Data Exposure |
| 5361 | Persistent refresh_token in OpenAI Codex authentication | critical | 8.5 | 1 | Supply Chain Attack |
| 5362 | Unpatched vulnerabilities in end-of-life PHP versions (e.g., PHP 7.4) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5363 | Server Vulnerabilities | critical | 8.5 | 1 | Smishing Scam |
| 5364 | Salesforce environment misconfiguration/access control | critical | 8.5 | 1 | Data Breach |
| 5365 | CVE-2026-80844 | critical | 8.5 | 1 | Privilege Escalation |
| 5366 | passkey storage in password managers | critical | 8.5 | 1 | phishing |
| 5367 | Stolen Personal Data from External Sources | critical | 8.5 | 1 | Data Breach |
| 5368 | Weak cybersecurity defenses, lack of dedicated cybersecurity staff, reliance on ed-tech tools | critical | 8.5 | 1 | Ransomware |
| 5369 | Backend API endpoint lacking proper authentication checks | critical | 8.5 | 1 | Data Breach |
| 5370 | CVE-2026-1602 | critical | 8.5 | 1 | Authentication Bypass |
| 5371 | Unrotated Service Account Token | critical | 8.5 | 1 | Data Breach (OAuth Token Compromise) |
| 5372 | GraphQL API Misconfiguration | critical | 8.5 | 1 | Data Leak |
| 5373 | Misconfigured test environments with unintended internet access | critical | 8.5 | 1 | AI Model Escape |
| 5374 | Human Error (Improper Handling of Public Records Request) | critical | 8.5 | 1 | Data Breach (Unintentional Disclosure) |
| 5375 | misconfigured third-party integrations | critical | 8.5 | 1 | ransomware |
| 5376 | Patched security vulnerability | critical | 8.5 | 1 | Data Breach |
| 5377 | Bypass Route in Femtocell Management Server | critical | 8.5 | 1 | Data Breach |
| 5378 | CVE-2025-43300 (Apple Zero-Day) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5379 | Remote Dynamic Dependencies (RDD) | critical | 8.5 | 1 | Supply Chain Attack |
| 5380 | Lowered security guardrails during controlled testing | critical | 8.5 | 1 | Social Engineering |
| 5381 | Canvas learning platform vulnerability (Jenks Public Schools, Gordon Cooper Technology Center) | critical | 8.5 | 1 | Data Breach |
| 5382 | lack of sandboxing for physical GPU-equipped machines | critical | 8.5 | 1 | malware |
| 5383 | CVE-2026-25903 | critical | 8.5 | 1 | Authorization Bypass |
| 5384 | Legacy accounts | critical | 8.5 | 1 | Phishing |
| 5385 | Lack of Second-Layer Security Checks in API Configurations | critical | 8.5 | 1 | Data Breach |
| 5386 | CVE-2014-6271 (Shellshock) | critical | 8.5 | 1 | Exploit Trends |
| 5387 | Hardcoded Google API keys with expanded authentication capabilities | critical | 8.5 | 1 | Data Exposure |
| 5388 | Weak encryption configurations (e.g., BitLocker), cached authentication tokens, lack of hardware-rooted security | critical | 8.5 | 1 | Device Theft / Data Breach |
| 5389 | Parking Permit System Flaw (since 2017) | critical | 8.5 | 1 | Data Breach |
| 5390 | Coruna (23 distinct security flaws) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5391 | Software vulnerabilities (AI-accelerated identification) | critical | 8.5 | 1 | Cyber Espionage, Critical Infrastructure Attack, Data Breach |
| 5392 | ConnectWise software vulnerability | critical | 8.5 | 1 | Data Breach |
| 5393 | Excessive Discord SDK logging writing private data to local log files in plaintext | critical | 8.5 | 1 | Data Exposure |
| 5394 | Unmonitored mass data downloads/email exfiltration | critical | 8.5 | 1 | Data Breach |
| 5395 | Governance gap in data access controls | critical | 8.5 | 1 | Third-party data exploitation |
| 5396 | Third-Party Application Misconfiguration | critical | 8.5 | 1 | Data Breach |
| 5397 | Unauthenticated access flaw in API endpoint `/api/now/related_list_edit/create` with `requires_authentication=false` | critical | 8.5 | 1 | Unauthorized Data Access |
| 5398 | CVE-2026-2836 | critical | 8.5 | 1 | HTTP Request Smuggling |
| 5399 | Weaknesses in Chrome’s Google Password Manager synchronization, TPM-wrapped device identity key exposure, and insecure WebAuthn policy configurations (userVerification='preferred') | critical | 8.5 | 1 | Credential Theft |
| 5400 | ClickFix technique | critical | 8.5 | 1 | phishing |
| 5401 | Inadequate cybersecurity protections | critical | 8.5 | 1 | Data Breach |
| 5402 | CVE-2025-23120 | critical | 8.5 | 1 | Vulnerability |
| 5403 | CVE-2025-34085 (Simple File List) | critical | 8.5 | 1 | Exploitation Campaign |
| 5404 | Temporary unsecured storage of user data and PGP keys | critical | 8.5 | 1 | Data Breach |
| 5405 | CVE-2025-14756 | critical | 8.5 | 1 | Command Injection |
| 5406 | Out-of-bounds write flaw in Alpitronic HYC50 EV charger | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 5407 | Compromised company account on GitHub | critical | 8.5 | 1 | Data Breach |
| 5408 | Insufficient MFA | critical | 8.5 | 1 | Phishing |
| 5409 | Malicious approvals | critical | 8.5 | 1 | Phishing |
| 5410 | Improper data retention (post-contract) | critical | 8.5 | 1 | Data Breach |
| 5411 | CVE-2026-81000 | critical | 8.5 | 1 | Privilege Escalation |
| 5412 | Lack of separation between instructions and data in large language models | critical | 8.5 | 1 | AI Vulnerability Misunderstanding |
| 5413 | Improper Access Controls, Undisclosed System Features | critical | 8.5 | 1 | Unauthorized Data Access |
| 5414 | CVE-2026-6682 (FAT32 integer overflow) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 5415 | Parser differential between JavaScript and libc (getaddrinfo()) | critical | 8.5 | 1 | Sandbox Bypass |
| 5416 | ClawJacked (CVE not specified) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5417 | Missing role checks during user onboarding | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 5418 | CVE-2026-0629 | critical | 8.5 | 1 | Authentication Bypass |
| 5419 | CVE-2025-8099 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5420 | Unpatched CMS vulnerability | critical | 8.5 | 1 | Supply-Chain Attack |
| 5421 | Legitimate third-party cloud systems bypass | critical | 8.5 | 1 | Data Breach |
| 5422 | Hardcoded AES Encryption Key | critical | 8.5 | 1 | Vulnerability Exploitation |
| 5423 | Social Engineering (ClickFix technique) | critical | 8.5 | 1 | Malware Campaign |
| 5424 | Social engineering (impersonation of Signal Support) | critical | 8.5 | 1 | Phishing |
| 5425 | GitHub Agentic Workflows (AI-powered automation) | critical | 8.5 | 1 | Data Leak |
| 5426 | CVE-2026-56155 (Insufficient Granularity of Access Control - CWE-1220) | critical | 8.5 | 1 | Privilege Escalation |
| 5427 | Human error (phishing attack on staff) | critical | 8.5 | 1 | Data Breach |
| 5428 | Semantic Drift in Multimodal AI | critical | 8.5 | 1 | Prompt Extraction |
| 5429 | Software Update | critical | 8.0 | 1 | Data Breach |
| 5430 | Physical Loss of Device | critical | 8.0 | 1 | Data Breach |
| 5431 | Sequential User ID Bug | critical | 8.0 | 1 | Data Breach |
| 5432 | CWE Exposure of Resource to Wrong Sphere | critical | 8.0 | 1 | Vulnerability |
| 5433 | Accellion’s FTA | critical | 8.0 | 1 | Data Breach |
| 5434 | Misconfiguration in computer system | critical | 8.0 | 1 | Data Breach |
| 5435 | Security flaw in the patient portal | critical | 8.0 | 1 | Data Breach |
| 5436 | Lack of security safeguards in the contract | critical | 8.0 | 1 | Data Breach |
| 5437 | Points of Sale | critical | 8.0 | 1 | Data Breach |
| 5438 | Radio Communications Disruption | critical | 8.0 | 1 | Vulnerability Exploitation |
| 5439 | System Bug | critical | 8.0 | 1 | Data Disclosure |
| 5440 | Keyboard Software Bug | critical | 8.0 | 1 | Software Vulnerability |
| 5441 | Compromised Administrative Staff Account | critical | 8.0 | 1 | Data Breach |
| 5442 | Unsecured Data Storage Device | critical | 8.0 | 1 | Data Breach |
| 5443 | Third-party Vendor Access | critical | 8.0 | 1 | Data Breach |
| 5444 | Application Vulnerability | critical | 8.0 | 1 | Data Breach |
| 5445 | RCE vulnerability in Dynamicweb software | critical | 8.0 | 1 | Remote Code Execution (RCE) |
| 5446 | Database Access | critical | 8.0 | 1 | Data Breach |
| 5447 | Misconfigured Server | critical | 8.0 | 1 | Data Breach |
| 5448 | Authentication process for My Account login details | critical | 8.0 | 1 | Data Breach |
| 5449 | Employee Sharing Sensitive Information | critical | 8.0 | 1 | Data Breach |
| 5450 | Unauthorized Access by Insider | critical | 8.0 | 1 | Data Breach |
| 5451 | Improper Data Redaction | critical | 8.0 | 1 | Data Breach |
| 5452 | Human Resources Information Access | critical | 8.0 | 1 | Data Breach |
| 5453 | Misconfigured GitHub repository | critical | 8.0 | 1 | Data Leak |
| 5454 | Impersonation of law enforcement officials | critical | 8.0 | 1 | Data Leak |
| 5455 | Various vulnerabilities scanned by the Angler exploit kit | critical | 8.0 | 1 | Malvertising |
| 5456 | Insufficient security protections in cloud-based storage container | critical | 8.0 | 1 | Data Breach |
| 5457 | Accellion file-sharing system | critical | 8.0 | 1 | Data Breach |
| 5458 | CVE-2025-61884 (potential, not yet confirmed as exploited) | high | 7.5 | 1 | ransomware |
| 5459 | Improper handling of sensitive information | high | 7.5 | 1 | Data Breach |
| 5460 | Obfuscated Code in Extensions | high | 7.5 | 1 | Malicious Software |
| 5461 | security systems vulnerability | high | 7.5 | 1 | data breach |
| 5462 | CVE-2025-61884 | high | 7.5 | 1 | Cyberattack |
| 5463 | Stack space exhaustion in user code with async_hooks enabled | high | 7.5 | 1 | Denial-of-Service (DoS) |
| 5464 | Review Process Bypass | high | 7.5 | 1 | Ransomware |
| 5465 | Weak third-party security (shared data exchange platform) | high | 7.5 | 1 | Data Theft Extortion |
| 5466 | Email account takeover, lack of payment verification | high | 7.5 | 1 | Business Email Compromise (BEC) |
| 5467 | Compromised Update Server | high | 7.5 | 1 | Malware Distribution |
| 5468 | Employee login credentials | high | 7.5 | 1 | Ransomware Attack |
| 5469 | Payment provider vulnerability | high | 7.5 | 1 | Bank Fraud |
| 5470 | Zero-day vulnerability in third-party software (Oracle E-Business Suite) | high | 7.5 | 1 | Data Breach |
| 5471 | CVE-2023-34362 (MOVEit) | high | 7.5 | 1 | ransomware |
| 5472 | Payment system vulnerability | high | 7.5 | 1 | Data Breach |
| 5473 | POS Systems | high | 7.5 | 1 | Data Breach |
| 5474 | Fragmented security tools, insufficient email security coverage | high | 7.5 | 1 | Ransomware |
| 5475 | IT System Glitch | high | 7.5 | 1 | Data Breach |
| 5476 | Oracle E-Business Suite Zero-Day (Unauthenticated, Low Complexity) | high | 7.5 | 1 | Cyberattack |
| 5477 | Firewall Vulnerability | high | 7.5 | 1 | Ransomware Attack |
| 5478 | legacy perimeter firewall | high | 7.5 | 1 | Ransomware |
| 5479 | Vulnerabilities in global digital infrastructure | high | 7.5 | 1 | Ransomware |
| 5480 | Lack of multi-factor authentication (MFA) on domain accounts | high | 7.5 | 1 | Ransomware Attempt |
| 5481 | outdated software, overworked staff, limited holiday response times | high | 7.5 | 1 | phishing |
| 5482 | Internet-accessible flaws | high | 7.5 | 1 | Ransomware |
| 5483 | Weak Password Policy | high | 6.5 | 1 | Hacking Incident |
| 5484 | Loneliness | high | 6.0 | 1 | Scam |
| 5485 | Authentication protocol vulnerabilities | high | 6.0 | 1 | Cyberattack |
| 5486 | Rapid development cycles outpacing security reviews | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5487 | Lack of Oversight/Enforcement of Access Controls | high | 6.0 | 1 | Data Breach |
| 5488 | Abuse of trusted .arpa domain for reverse DNS lookups | high | 6.0 | 1 | Phishing |
| 5489 | Phishable OTP Tokens for Mobile Wallet Provisioning | high | 6.0 | 1 | Financial Fraud |
| 5490 | Improper folder permissions on file servers | high | 6.0 | 1 | Data Breach |
| 5491 | VMware vCenter Server vulnerability | high | 6.0 | 1 | Vulnerability Exploitation |
| 5492 | Data processing error | high | 6.0 | 1 | Data Breach |
| 5493 | Misconfigured database backup access | high | 6.0 | 1 | Data Breach |
| 5494 | Security flaw in Progress' MOVEit data transfer programme | high | 6.0 | 1 | Data Breach |
| 5495 | Reused/Weak Passwords | high | 6.0 | 1 | Data Breach |
| 5496 | Brokerage Platforms Allowing MFA via Text/Call | high | 6.0 | 1 | Financial Fraud |
| 5497 | Unsecured Personal Laptop | high | 6.0 | 1 | Data Breach |
| 5498 | Unencrypted USB Flash Drive | high | 6.0 | 1 | Data Breach |
| 5499 | Improper backup file storage | high | 6.0 | 1 | Data Breach |
| 5500 | Data Privacy Policy | high | 6.0 | 1 | Data Disclosure |
| 5501 | Public exposure of environment configuration file | high | 6.0 | 1 | Data Breach |
| 5502 | CSP frame-src Bypass (Compromised Allowed Domains) | high | 6.0 | 1 | Data Breach |
| 5503 | Vulnerabilities in ticketing and access control systems | high | 6.0 | 1 | Cyberattack |
| 5504 | Lack of API-Centric Threat Intelligence Sharing | high | 6.0 | 1 | Operational Risk |
| 5505 | Public Access to Amazon S3 Bucket | high | 6.0 | 1 | Data Exposure |
| 5506 | lapses in cybersecurity measures | high | 6.0 | 1 | cyber intrusion |
| 5507 | lack of verification for online investments | high | 6.0 | 1 | fraud |
| 5508 | Exposed ADB services without authentication | high | 6.0 | 1 | Botnet |
| 5509 | Configuration Mistake | high | 6.0 | 1 | Data Leak |
| 5510 | Human error (opening malicious attachment) | high | 6.0 | 1 | Phishing |
| 5511 | Third-Party CRM Integration Vulnerabilities | high | 6.0 | 1 | Data Breach |
| 5512 | misconfigured slot machine software | high | 6.0 | 1 | fraud |
| 5513 | Bypass of Time-Limited MFA Windows | high | 6.0 | 1 | Financial Fraud |
| 5514 | Human Error (Inadvertent Disclosure in Public Documents) | high | 6.0 | 1 | Data Breach |
| 5515 | Physical Sensor Feeds | high | 6.0 | 1 | Market Manipulation |
| 5516 | holiday distraction | high | 6.0 | 1 | phishing |
| 5517 | Insufficient Contextual Risk Awareness | high | 6.0 | 1 | Social Engineering |
| 5518 | TotoLink router firmware update server | high | 6.0 | 1 | DDoS Attack |
| 5519 | Sitting Ducks (DNS misconfiguration) | high | 6.0 | 1 | Scam / Fraudulent Push Notifications |
| 5520 | Human Trust in Known Contacts | high | 6.0 | 1 | Phishing |
| 5521 | misconfigured database | high | 6.0 | 1 | data exposure |
| 5522 | Exposed Google API key | high | 6.0 | 1 | Data Exposure |
| 5523 | inadequate contractor monitoring | high | 6.0 | 1 | insider threat |
| 5524 | Unencrypted and Unprotected Data Storage | high | 6.0 | 1 | Data Breach |
| 5525 | Weak front-end identity verification, outdated workflow designs, lack of real-time identity checks | high | 6.0 | 1 | Identity Fraud, Automated Bot Attack |
| 5526 | Player trust in unofficial marketplaces | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5527 | CVE-2024-38197 (CVSS 6.5: Medium) | high | 6.0 | 1 | Spoofing |
| 5528 | Lack of Device Encryption | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5529 | Human vulnerability (phishing) | high | 6.0 | 1 | Phishing |
| 5530 | Dangerous React Patterns (dangerouslySetInnerHTML near iframes) | high | 6.0 | 1 | Data Breach |
| 5531 | CVE-2026-0231 (CWE-497) | high | 6.0 | 1 | Vulnerability |
| 5532 | Email Account and Tax Preparation Software | high | 6.0 | 1 | Data Breach |
| 5533 | CVE-2025-24061 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5534 | Flaw in Ivanti Endpoint Manager Mobile (EPMM) | high | 6.0 | 1 | Data Breach |
| 5535 | unprotected storage | high | 6.0 | 1 | data exposure |
| 5536 | low cybersecurity awareness | high | 6.0 | 1 | phishing |
| 5537 | Weak authentication mechanism (Phone Number/PIN model) | high | 6.0 | 1 | Unauthorized Access |
| 5538 | potential weaknesses in email system security | high | 6.0 | 1 | phishing |
| 5539 | Lack of endpoint security for attendee devices | high | 6.0 | 1 | Malware |
| 5540 | Weak Internal Controls (Prior Embezzlement) | high | 6.0 | 1 | Fraud |
| 5541 | Third-Party Integration (Drift Email/Salesloft) | high | 6.0 | 1 | Data Breach |
| 5542 | Improper data management practices | high | 6.0 | 1 | Data Leak |
| 5543 | Unencrypted device with sensitive data (despite password protection) | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5544 | Browser hijacking via malicious script | high | 6.0 | 1 | DDoS Attack, Content Tampering, Malicious JavaScript Injection |
| 5545 | Unguarded Physical Access Points | high | 6.0 | 1 | Physical Theft |
| 5546 | Abuse of trusted cloud services (Firebase, Google Translate) | high | 6.0 | 1 | Phishing |
| 5547 | Unsecured Active Directory | high | 6.0 | 1 | Data Breach |
| 5548 | Exposed Data on Website | high | 6.0 | 1 | Data Leak |
| 5549 | Weak Password Policy (Password: 'Louvre', 'Thales') | high | 6.0 | 1 | Physical Theft |
| 5550 | Weak Administrator Password | high | 6.0 | 1 | Data Breach |
| 5551 | Public fear | high | 6.0 | 1 | Phishing |
| 5552 | Public Venmo Account | high | 6.0 | 1 | Data Exposure |
| 5553 | Lack of proactive domain monitoring and registration of brand variations | high | 6.0 | 1 | Cybersquatting, Phishing, Malware Distribution, Fraud |
| 5554 | psychological manipulation (e.g., fear of missing out on high returns) | high | 6.0 | 1 | fraud |
| 5555 | Lack of Continuous Credential Monitoring | high | 6.0 | 1 | Credential Theft |
| 5556 | Lack of access controls and monitoring for ALPR system | high | 6.0 | 1 | Unauthorized Access |
| 5557 | Lack of Geofencing for Transaction Validation | high | 6.0 | 1 | Financial Fraud |
| 5558 | Backup Device Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5559 | Lack of AI governance framework, overly permissive access controls, accumulated tech debt in permission management | high | 6.0 | 1 | Data Breach |
| 5560 | Rapid Response to Urgent Requests from Seniors | high | 6.0 | 1 | Social Engineering |
| 5561 | Phishing/Malware | high | 6.0 | 1 | Data Breach |
| 5562 | Human Error (Fatigue/Jetlag) | high | 6.0 | 1 | Phishing |
| 5563 | Integer underflow in mach_o::Archive::Entry::name() function (CVE not specified) | high | 6.0 | 1 | Vulnerability |
| 5564 | Lack of vetting for third-party game demos (Valve/Steam) | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5565 | Default Configurations in Security Tools | high | 6.0 | 1 | Operational Risk |
| 5566 | Legacy IT systems and outdated infrastructure | high | 6.0 | 1 | Cybersecurity Awareness and Infrastructure Vulnerability |
| 5567 | Vulnerability in TinyPulse employee survey platform | high | 6.0 | 1 | Data Breach |
| 5568 | Inadequate Coordination of Security Escort | high | 6.0 | 1 | Physical Security Breach |
| 5569 | Logic error in temporary file access and download request handling | high | 6.0 | 1 | Logic Flaw / Guardrail Bypass |
| 5570 | Trust in familiar services | high | 6.0 | 1 | Cyber Espionage |
| 5571 | human error (successful phishing) | high | 6.0 | 1 | data breach |
| 5572 | Unsecured Endpoints | high | 6.0 | 1 | Data Security Incident |
| 5573 | Outdated Antivirus/Anti-Malware Tools | high | 6.0 | 1 | Data Breach Risk |
| 5574 | unsecured QR code access | high | 6.0 | 1 | fraud |
| 5575 | Employee email account credentials | high | 6.0 | 1 | Data Breach |
| 5576 | Malicious Software Installation | high | 6.0 | 1 | Data Breach |
| 5577 | Email Account Security | high | 6.0 | 1 | Email Hijacking |
| 5578 | AI Agent Memory Access | high | 6.0 | 1 | Prompt Injection |
| 5579 | Fortra's GoAnywhere MFT platform's zero-day vulnerability | high | 6.0 | 1 | Data Breach |
| 5580 | Improper storage of personal information | high | 6.0 | 1 | Data Breach |
| 5581 | Unencrypted Device | high | 6.0 | 1 | Data Breach |
| 5582 | System Vulnerability | high | 6.0 | 1 | Data Breach |
| 5583 | Weak Access Controls in Citrix Systems | high | 6.0 | 1 | Data Breach |
| 5584 | Password Manager Bypass | high | 6.0 | 1 | Phishing |
| 5585 | Lack of authentication on Kubernetes console | high | 6.0 | 1 | Cloud Security Breach |
| 5586 | Payment card processing system | high | 6.0 | 1 | Data Breach |
| 5587 | Paycor's MOVEit Transfer software | high | 6.0 | 1 | Data Breach |
| 5588 | URL Parameter Manipulation (collection) | high | 6.0 | 1 | Prompt Injection |
| 5589 | Complexity in visibility and control | high | 6.0 | 1 | Data Breach |
| 5590 | shared/default credentials | high | 6.0 | 1 | election fraud |
| 5591 | Lack of Visibility in Rapid Development Cycles | high | 6.0 | 1 | DDoS Attack |
| 5592 | Internal Employee Privileges | high | 6.0 | 1 | Data Breach |
| 5593 | API security flaw in Kiln’s infrastructure (used for Solana staking operations) | high | 6.0 | 1 | cyberattack |
| 5594 | Outdated Technology Infrastructure | high | 6.0 | 1 | Data Leakage |
| 5595 | Generic Design of Legitimate Settlement Sites | high | 6.0 | 1 | Phishing |
| 5596 | Third-party AI tools | high | 6.0 | 1 | DDoS |
| 5597 | Unsecured Physical Device (Password-protected laptop) | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5598 | lack of multi-factor authentication (MFA) on crypto accounts | high | 6.0 | 1 | cyber theft |
| 5599 | Privacy Controls | high | 6.0 | 1 | Data Breach |
| 5600 | Third-party software (TanStack) | high | 6.0 | 1 | AI-generated exploits |
| 5601 | Four zero-day vulnerabilities in IBM Data Risk Manager | high | 6.0 | 1 | Zero-Day Exploit |
| 5602 | Weak SMS-based Multi-Factor Authentication (MFA) | high | 6.0 | 1 | Financial Fraud |
| 5603 | CVE-2025-43300 (Apple OS-level zero-day) | high | 6.0 | 1 | Zero-day exploit |
| 5604 | CVE-2025-57714 (Unquoted Search Path in NetBak Replicator 4.5.x) | high | 6.0 | 1 | Vulnerability |
| 5605 | Lack of Security Clearance Enforcement | high | 6.0 | 1 | Data Exposure |
| 5606 | Credential Stuffing | high | 6.0 | 1 | Authentication Security Improvement |
| 5607 | insufficient monitoring of collaboration platforms | high | 6.0 | 1 | data breach |
| 5608 | Fragmented Security Tool Integration | high | 6.0 | 1 | Operational Risk |
| 5609 | Programming Update Error | high | 6.0 | 1 | Data Breach |
| 5610 | Exposure of Install Action Tokens | high | 6.0 | 1 | Data Breach |
| 5611 | Microsoft OAuth 2.0 Device Authorization Flow, Lack of Conditional Access Enforcement | high | 6.0 | 1 | Phishing, Business Email Compromise (BEC), OAuth Abuse |
| 5612 | Unauthorized access due to call center employee negligence | high | 6.0 | 1 | Data Breach |
| 5613 | Abuse of legitimate Windows utility (mshta.exe), SCL:-1 spam-confidence bypass | high | 6.0 | 1 | Phishing |
| 5614 | Regulatory Filing Systems (e.g., EDGAR, PACER) | high | 6.0 | 1 | Market Manipulation |
| 5615 | Use of Non-Official Communication Channels | high | 6.0 | 1 | Phishing |
| 5616 | Backend Update Bug | high | 6.0 | 1 | Bug/Exploit |
| 5617 | File Decompression in Kernel | high | 6.0 | 1 | Vulnerability Exploit |
| 5618 | Unpatched/Outdated Systems (Windows Server 2003) | high | 6.0 | 1 | Physical Theft |
| 5619 | Compromised user credentials | high | 6.0 | 1 | Data Breach |
| 5620 | Internal Employee Access | high | 6.0 | 1 | Data Breach |
| 5621 | Human Error / Lack of Authentication Protocols | high | 6.0 | 1 | Data Breach |
| 5622 | Weak Login Verification | high | 6.0 | 1 | Data Breach |
| 5623 | User Trust in Legitimate Software Repositories | high | 6.0 | 1 | Malware Distribution |
| 5624 | Security vulnerabilities in IP cameras | high | 6.0 | 1 | DDoS Attack |
| 5625 | DNS misconfiguration (abandoned domains with improper nameserver delegation) | high | 6.0 | 1 | DNS Misconfiguration Exploitation |
| 5626 | Human factor (phishing) | high | 6.0 | 1 | Phishing |
| 5627 | Insufficient Monitoring of Third-Party Integrations | high | 6.0 | 1 | Unauthorized Access |
| 5628 | Data breach via third-party vendor | high | 6.0 | 1 | Phishing |
| 5629 | Default Weak Passwords | high | 6.0 | 1 | Unauthorized Access |
| 5630 | Human trust in authentic-looking communications | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 5631 | Trust in official app marketplaces, deceptive email outreach | high | 6.0 | 1 | Phishing |
| 5632 | CVE-2024-36347 | high | 6.0 | 1 | Vulnerability |
| 5633 | Undisclosed Data Breaches | high | 6.0 | 1 | Market Manipulation |
| 5634 | user typographical errors | high | 6.0 | 1 | phishing |
| 5635 | Lack of multi-factor authentication (MFA) in some cases | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 5636 | lack of domain registration oversight | high | 6.0 | 1 | phishing |
| 5637 | IT vendor vulnerability confirmed by the Ministry of Health | high | 6.0 | 1 | Data Breach |
| 5638 | CVE-2025-24071 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5639 | CVE-2025-32432 (Craft CMS) | high | 6.0 | 1 | cyberattack |
| 5640 | Weak Password Hashing (MD5 without salt) | high | 6.0 | 1 | Data Breach |
| 5641 | Unsecured installation page, lack of session validation, exposed administrative endpoints | high | 6.0 | 1 | Malware Distribution |
| 5642 | Potential SharePoint vulnerability (unconfirmed) | high | 6.0 | 1 | Cyberattack |
| 5643 | GitHub Credentials | high | 6.0 | 1 | Data Breach |
| 5644 | Weak Third-Party Compliance Standards | high | 6.0 | 1 | Data Leakage |
| 5645 | Unvalidated PostMessage Origins | high | 6.0 | 1 | Data Breach |
| 5646 | Mistaken Disclosure | high | 6.0 | 1 | Data Breach |
| 5647 | AI Platform Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5648 | GoAnywhere MFT zero-day vulnerability | high | 6.0 | 1 | Data Breach |
| 5649 | Employee Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5650 | Compromised software via phishing | high | 6.0 | 1 | Phishing Attack |
| 5651 | Abuse of Legitimate Services | high | 6.0 | 1 | Phishing |
| 5652 | Data mismatch error in system logic | high | 6.0 | 1 | Data Breach (Unauthorized Access/Disclosure) |
| 5653 | weak monitoring of east-west traffic | high | 6.0 | 1 | phishing |
| 5654 | Lack of data-sharing protocols in pilot programs | high | 6.0 | 1 | Data Breach / Unauthorized Data Sharing |
| 5655 | lack of verification by job seekers | high | 6.0 | 1 | social engineering |
| 5656 | Cloud Storage System | high | 6.0 | 1 | Data Breach |
| 5657 | CVE-2026-77692 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5658 | Improper Access | high | 6.0 | 1 | Data Breach |
| 5659 | Human Vulnerability (Blackmail) | high | 6.0 | 1 | Extortion, Insider Threat, Retail Theft |
| 5660 | Lack of Data Wiping and Encryption | high | 6.0 | 1 | Data Breach |
| 5661 | Exploitable Gaps in Contactless Payment Tokenization | high | 6.0 | 1 | Financial Fraud |
| 5662 | Critical Infrastructure Vulnerabilities (e.g., Power Grid Exploitation) | high | 6.0 | 1 | Cybercrime Network Dismantling |
| 5663 | Incorrectly Configured AWS Bucket | high | 6.0 | 1 | Data Exposure |
| 5664 | Absence of Endpoint Monitoring | high | 6.0 | 1 | Data Breach Risk |
| 5665 | Human Error (Incorrect Address Usage) | high | 6.0 | 1 | Data Breach |
| 5666 | Employee's Microsoft 365 Account | high | 6.0 | 1 | Data Breach |
| 5667 | CVE-2025-2848 | high | 6.0 | 1 | Vulnerability Exploitation |
| 5668 | Exploitation of Apple’s account creation process (excessive character acceptance in name fields) and security alert email system | high | 6.0 | 1 | Phishing (Callback Phishing) |
| 5669 | Stolen Google Gemini API Keys | high | 6.0 | 1 | Fraud |
| 5670 | Software Update Issue | high | 6.0 | 1 | Data Breach |
| 5671 | Fake pop-up window | high | 6.0 | 1 | Data Breach |
| 5672 | Medium and high severity vulnerabilities in Ivanti EPMM software | high | 6.0 | 1 | Cyber Attack |
| 5673 | Alert System Failure | high | 6.0 | 1 | Data Breach |
| 5674 | Suspicious code on online payment portal | high | 6.0 | 1 | Data Breach |
| 5675 | Bypass of Chromium’s Secure Preferences and HMAC/App-Bound encrypted hashes | high | 6.0 | 1 | Malware Campaign |
| 5676 | DVRs/NVRs | high | 6.0 | 1 | DDoS Attack |
| 5677 | Lack of Public Awareness | high | 6.0 | 1 | Phishing |
| 5678 | Lack of secondary verification in AI-driven DeFi systems, Insufficient security filters for obfuscated commands | high | 6.0 | 1 | AI Exploitation, Prompt Injection, Unauthorized Token Transfer |
| 5679 | Apache HTTP server vulnerability | high | 6.0 | 1 | Cyber Espionage |
| 5680 | E-Verify's inability to verify the authenticity of presented documents | high | 6.0 | 1 | Identity Theft |
| 5681 | Lack of user awareness, trust in government services, and reusable phishing infrastructure | high | 6.0 | 1 | Phishing |
| 5682 | Unsecured Zoom Classroom | high | 6.0 | 1 | Cyber Attack |
| 5683 | Open Elastic Search Instances | high | 6.0 | 1 | Data Exposure |
| 5684 | Lack of U2F/Physical Security Key Enforcement | high | 6.0 | 1 | Financial Fraud |
| 5685 | Unauthorized access from outside of Europe | high | 6.0 | 1 | DDoS Attack |
| 5686 | Fake CAPTCHA prompts, social engineering | high | 6.0 | 1 | Malware Attack |
| 5687 | KNX Protocol Connection Authorization Option 1 | high | 6.0 | 1 | Phishing |
| 5688 | Unauthorized access to an employee's email account | high | 6.0 | 1 | Data Breach |
| 5689 | Misconfigured Docker Daemon (Exposed to Internet) | high | 6.0 | 1 | DDoS Attack |
| 5690 | Unspecified vulnerability in 2Keys MFA system (Interac-owned) | high | 6.0 | 1 | Data Breach |
| 5691 | Human Error (Unauthorized Information Disclosure) | high | 6.0 | 1 | Data Breach |
| 5692 | Exploitation of GitHub's Discussions feature and perceived trustworthiness of security advisories | high | 6.0 | 1 | Phishing |
| 5693 | human error (lack of training) | high | 6.0 | 1 | phishing |
| 5694 | Decentralized Voting/Oracle Mechanisms | high | 6.0 | 1 | Market Manipulation |
| 5695 | Improper data storage | high | 6.0 | 1 | Data Breach |
| 5696 | Data Collection Practices | high | 6.0 | 1 | Data Privacy Issue |
| 5697 | Shadow IT | high | 6.0 | 1 | Security Control Bypass |
| 5698 | Possible exploitation of a vulnerability in one ministry’s IT systems | high | 6.0 | 1 | Cybersecurity Breach |
| 5699 | Lack of end-to-end encryption in standard email protocols, Absence of proper email authentication mechanisms | high | 6.0 | 1 | Business Email Compromise (BEC) |
| 5700 | Potentially CVE-2025-53779 (Windows Kerberos) | high | 6.0 | 1 | Data Breach |
| 5701 | Absence of Passkey Support | high | 6.0 | 1 | Phishing |
| 5702 | Weak PIN reset security | high | 6.0 | 1 | Data Breach |
| 5703 | Exposure of Customer Data | high | 6.0 | 1 | Data Exposure |
| 5704 | Compromised Employee Mailbox | high | 6.0 | 1 | Data Breach |
| 5705 | Weak/Leaked Credentials | high | 6.0 | 1 | Data Breach |
| 5706 | CVE-2025-53770 (SharePoint Server, 'ToolShell') | high | 6.0 | 1 | Data Breach |
| 5707 | Social engineering, lack of verification for financial transactions | high | 6.0 | 1 | Fraud |
| 5708 | Use of Personal Device for Corporate Access | high | 6.0 | 1 | Data Breach |
| 5709 | Poor password hygiene (weak, reused, or easily guessable passwords) | high | 6.0 | 1 | data breach |
| 5710 | CVE-2026-19667 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5711 | Unauthorized tools | high | 6.0 | 1 | Insider Threat |
| 5712 | Human Trust in Legitimate Breach Alerts | high | 6.0 | 1 | Phishing / Social Engineering |
| 5713 | Security Misconfiguration | high | 6.0 | 1 | Data Leak |
| 5714 | NFC Protocol Abuse (Legitimate Traffic Relay) | high | 6.0 | 1 | Financial Fraud |
| 5715 | Unspecified software vulnerability in 2Keys MFA system | high | 6.0 | 1 | Data Breach |
| 5716 | human trust/urgency bias | high | 6.0 | 1 | social engineering |
| 5717 | Human Trust and Urgency | high | 6.0 | 1 | Social Engineering Scam |
| 5718 | CVE-2026-55407 (Unbounded heap allocation in `decode_unknown_field` function) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5719 | CVE-2026-81563 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5720 | Fault in the code of EOSBet's smart contracts | high | 6.0 | 1 | Cryptocurrency Theft |
| 5721 | Delayed Tool Invocation | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 5722 | Lack of proper access restrictions, unnecessary system access | high | 6.0 | 1 | Data Breach |
| 5723 | Weak Multi-Factor Authentication (MFA) on Twitter Employee Accounts | high | 6.0 | 1 | Account Takeover |
| 5724 | No Device Encryption | high | 6.0 | 1 | Data Breach Risk |
| 5725 | External Access to Validator Keys | high | 6.0 | 1 | Blockchain Security Breach |
| 5726 | Lack of Access Controls (No Password Protection) | high | 6.0 | 1 | Data Breach (Unintentional Exposure) |
| 5727 | Same password for multiple accounts | high | 6.0 | 1 | Cyber Attack |
| 5728 | Lack of Email Encryption / Employee Negligence | high | 6.0 | 1 | Data Breach |
| 5729 | Security Setting Error | high | 6.0 | 1 | Data Breach |
| 5730 | Lack of Secure Document Disposal Procedures | high | 6.0 | 1 | Data Breach (Physical) |
| 5731 | Misplaced Thumb Drive | high | 6.0 | 1 | Data Breach |
| 5732 | Offline functionality of Cellebrite UFED tools | high | 6.0 | 1 | Unauthorized Data Extraction |
| 5733 | Absence of Document Automation/Redaction Tools | high | 6.0 | 1 | Data Leakage |
| 5734 | alleged exploitation of parking permit system to gain unauthorized access | high | 6.0 | 1 | phishing |
| 5735 | User Trust in Discounted/Rare Item Offers | high | 6.0 | 1 | DDoS Attack |
| 5736 | System Malfunction | high | 6.0 | 1 | Data Leak |
| 5737 | CVE-2025-37735 (Improper Preservation of Permissions) | high | 6.0 | 1 | Vulnerability / Privilege Escalation |
| 5738 | Weakness in GPS Navigation System Authentication/Encryption | high | 6.0 | 1 | GPS Spoofing / Maritime Cyber Incident |
| 5739 | Exposed security domain secret (SDS) in Chrome logs/memory | high | 6.0 | 1 | Vulnerability Exploitation |
| 5740 | MOVEit file transfer program | high | 6.0 | 1 | Data Breach |
| 5741 | Lack of robust security measures | high | 6.0 | 1 | Hacking |
| 5742 | Misconfiguration in talent management software | high | 6.0 | 1 | Data Breach |
| 5743 | Weak DDoS mitigation (gaming platforms) | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5744 | ARC processor flaws | high | 6.0 | 1 | DDoS Attack |
| 5745 | Fortra GoAnywhere secure file transfer platform | high | 6.0 | 1 | Data Breach |
| 5746 | CVE-2026-80274 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5747 | Lack of Regulatory Oversight in Cryptocurrency Operations | high | 6.0 | 1 | Cybercrime Network Dismantling |
| 5748 | CVE-2026-26127 (Out-of-bounds read, CWE-125) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5749 | Realtek chips | high | 6.0 | 1 | DDoS Attack |
| 5750 | Basic Security Vulnerability | high | 6.0 | 1 | Data Breach |
| 5751 | Unsecured Remote Work Environments | high | 6.0 | 1 | Human Error |
| 5752 | Google Visualization API | high | 6.0 | 1 | Cryptocurrency Theft |
| 5753 | TOCTOU Vulnerability | high | 6.0 | 1 | Vulnerability Exploitation |
| 5754 | Over-Permissive Ticket Transfer Features | high | 6.0 | 1 | Account Takeover (ATO) |
| 5755 | Unauthorized Disclosure of Surveillance Footage | high | 6.0 | 1 | Physical Security Breach |
| 5756 | Vulnerable version of Trust Wallet browser extension (v2.68) | high | 6.0 | 1 | Supply Chain Attack |
| 5757 | unauthorized data access/exfiltration by terminated employee | high | 6.0 | 1 | data breach |
| 5758 | Human Error (Improper Data Handling) | high | 6.0 | 1 | Data Breach (Accidental Disclosure) |
| 5759 | Unpatched flaw in a commercial MDM system | high | 6.0 | 1 | Data Breach |
| 5760 | Unsecured Email Account | high | 6.0 | 1 | Data Breach |
| 5761 | AI-assisted coding error (unauthenticated open web directory) | high | 6.0 | 1 | Data Breach |
| 5762 | Website platform configuration error (password-protected documents made publicly accessible via search) | high | 6.0 | 1 | data breach |
| 5763 | Over-reliance on email/text-based communication without secondary validation | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 5764 | Payment gateway manipulation | high | 6.0 | 1 | Payment System Exploitation |
| 5765 | lack of authentication for mobile device pairing | high | 6.0 | 1 | fraud |
| 5766 | Weak WordPress Administrator Credentials | high | 6.0 | 1 | Fraud |
| 5767 | Unpatched Endpoints | high | 6.0 | 1 | Credential Theft |
| 5768 | Default/Lack of Credentials | high | 6.0 | 1 | DDoS Attack |
| 5769 | Potential compromise of routers by Chinese state-sponsored hackers | high | 6.0 | 1 | Security Concerns and Investigations |
| 5770 | Inadequate Remote Work Policies | high | 6.0 | 1 | Data Leak |
| 5771 | Generic Compliance Policies | high | 6.0 | 1 | Data Breach |
| 5772 | Lack of rate-limiting or size restrictions on contact list uploads, enabling mass verification of phone numbers associated with WhatsApp accounts. | high | 6.0 | 1 | Privacy Vulnerability |
| 5773 | Human Error/Employee Misconduct | high | 6.0 | 1 | Unauthorized Access and Data Breach |
| 5774 | Improper access to email account | high | 6.0 | 1 | Data Breach |
| 5775 | Overly Permissive Sandbox Attributes (allow-same-origin + allow-scripts) | high | 6.0 | 1 | Data Breach |
| 5776 | Human Error (Misplaced Trust in Email Communication) | high | 6.0 | 1 | Business Email Compromise (BEC) |
| 5777 | Third-party file sharing product | high | 6.0 | 1 | Data Breach |
| 5778 | Drift’s OAuth integration flow vulnerability | high | 6.0 | 1 | Data Breach |
| 5779 | Permission Misconfiguration | high | 6.0 | 1 | Data Exposure |
| 5780 | Setup Configuration | high | 6.0 | 1 | Data Leak |
| 5781 | Insecure Direct Object Reference (IDOR) in media access endpoints (/media/{ID}) | high | 6.0 | 1 | Data Breach |
| 5782 | CVE-2026-19666 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5783 | lack of real-time maritime tracking safeguards | high | 6.0 | 1 | physical cyber convergence |
| 5784 | Inadequate User Consent Mechanisms | high | 6.0 | 1 | Data Breach |
| 5785 | exploitation of job application platforms | high | 6.0 | 1 | social engineering |
| 5786 | Adversary-in-the-Middle (AiTM), MFA Bypass | high | 6.0 | 1 | Data Breach |
| 5787 | ThinkPHP, Jenkins, Hadoop YARN vulnerabilities | high | 6.0 | 1 | Botnet, DDoS |
| 5788 | Delay introduction via VPN | high | 6.0 | 1 | Cheating via VPN |
| 5789 | Coding techniques to enter the Naviance student site | high | 6.0 | 1 | Data Breach |
| 5790 | Absence of Technical Safeguards (Encryption/De-identification) | high | 6.0 | 1 | Data Breach |
| 5791 | MOVEit zero-day vulnerability | high | 6.0 | 1 | Data Breach |
| 5792 | Weak Cybersecurity Standards in Financial and E-Commerce Sectors | high | 6.0 | 1 | Cybercrime Network Dismantling |
| 5793 | insufficient security protections | high | 6.0 | 1 | cyber intrusion |
| 5794 | Zero-day exploit (2FA bypass) | high | 6.0 | 1 | AI-generated exploits |
| 5795 | Payment .php file vulnerability | high | 6.0 | 1 | Data Breach |
| 5796 | Business Continuity Dependencies | high | 6.0 | 1 | Third-Party Risk |
| 5797 | Insertion of malicious script | high | 6.0 | 1 | Data Breach |
| 5798 | Abuse of Google Tag Manager (GTM) | high | 6.0 | 1 | Credit Card Skimming |
| 5799 | AI-generated content | high | 6.0 | 1 | Phishing |
| 5800 | Internal Access Controls | high | 6.0 | 1 | Data Breach |
| 5801 | Incorrect Address Usage | high | 6.0 | 1 | Data Breach |
| 5802 | Family Member Trust Exploitation | high | 6.0 | 1 | Fraud |
| 5803 | Web-based payroll program | high | 6.0 | 1 | Data Breach |
| 5804 | Human vulnerability through social engineering | high | 6.0 | 1 | Social Engineering Attack |
| 5805 | Non-secure data storage location | high | 6.0 | 1 | Data Breach |
| 5806 | Publicly Available Environment Files | high | 6.0 | 1 | Data Exposure |
| 5807 | Vulnerable Laravel version or misconfiguration | high | 6.0 | 1 | Data Exposure |
| 5808 | Insufficient verification protocols for payment changes | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 5809 | Hardcoded Credentials in Internal Portals | high | 6.0 | 1 | Data Breach |
| 5810 | Unsecured Collaborative Tools | high | 6.0 | 1 | Data Breach Risk |
| 5811 | Reused passwords across multiple services | high | 6.0 | 1 | Credential Stuffing |
| 5812 | Computer Infection | high | 6.0 | 1 | Financial Theft |
| 5813 | Sabre Hospitality Solutions' system | high | 6.0 | 1 | Data Breach |
| 5814 | Lack of Device Encryption/Tracking | high | 6.0 | 1 | Data Security Incident |
| 5815 | PCI DSS 4.0.1 Non-Compliance (Unmanaged Scripts on Payment Pages) | high | 6.0 | 1 | Data Breach |
| 5816 | Fake Context Alignment | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 5817 | Unauthorized access to QuickBooks Online account | high | 6.0 | 1 | Data Breach |
| 5818 | DNS misconfiguration | high | 6.0 | 1 | DNS Hijacking |
| 5819 | Online Store Vulnerability | high | 6.0 | 1 | Data Breach |
| 5820 | NEXTEP self-service kiosks | high | 6.0 | 1 | Data Breach |
| 5821 | Accidental Exposure | high | 6.0 | 1 | Data Breach |
| 5822 | Poor Data Protection Practices | high | 6.0 | 1 | Insider Threat |
| 5823 | Lack of oversight/guidance for opioid settlement fund allocation; flexible spending rules | high | 6.0 | 1 | Financial Misappropriation / Regulatory Non-Compliance |
| 5824 | Compromised Email Credentials | high | 6.0 | 1 | Data Breach |
| 5825 | Lax privacy settings | high | 6.0 | 1 | Data Breach |
| 5826 | Insufficient Staff Training | high | 6.0 | 1 | Data Breach |
| 5827 | Context Poisoning | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 5828 | Browser-Stored Credentials | high | 6.0 | 1 | Credential Theft |
| 5829 | trust in automated AI-driven code analysis | high | 6.0 | 1 | supply chain attack |
| 5830 | Stolen Laptop | high | 6.0 | 1 | Data Breach |
| 5831 | Fortinet VPN vulnerability | high | 6.0 | 1 | Data Breach |
| 5832 | Malicious activity in open-source code repository | high | 6.0 | 1 | Supply Chain Attack |
| 5833 | QGenda's 'QuickLinks' feature allowing unauthenticated access to schedules | high | 6.0 | 1 | Data Exposure |
| 5834 | Weak Authentication for OAuth Tokens | high | 6.0 | 1 | Data Breach |
| 5835 | Human Trust in Authority Figures | high | 6.0 | 1 | Social Engineering |
| 5836 | Improper Data Handling / Public-Facing Website Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5837 | Lack of Data Governance Policies | high | 6.0 | 1 | Data Leakage |
| 5838 | Unspecified vulnerability in a development server | high | 6.0 | 1 | Data Breach |
| 5839 | Post-termination access to company passwords | high | 6.0 | 1 | Unauthorized Access |
| 5840 | lack of multi-factor verification | high | 6.0 | 1 | phishing |
| 5841 | Zero-Day Vulnerability in Fortran GoAnywhere MFT | high | 6.0 | 1 | Data Breach |
| 5842 | Policy workarounds | high | 6.0 | 1 | Insider Threat |
| 5843 | Security weaknesses in NHS websites | high | 6.0 | 1 | Cyberattack |
| 5844 | Test server misconfiguration | high | 6.0 | 1 | Data Breach |
| 5845 | lack of anomaly detection for screenshot activities | high | 6.0 | 1 | insider threat |
| 5846 | Gaps in cybersecurity defenses and delayed breach detection | high | 6.0 | 1 | Data Breach |
| 5847 | CVE-2025-66168 | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5848 | Human (Email Compromise) | high | 6.0 | 1 | Data Breach |
| 5849 | Gaps in cybersecurity | high | 6.0 | 1 | Cyberattack (Hacking) |
| 5850 | Gmail accounts | high | 6.0 | 1 | Data Breach |
| 5851 | Surveillance software | high | 6.0 | 1 | Surveillance |
| 5852 | Employee Account | high | 6.0 | 1 | Data Breach |
| 5853 | Poor Data Handling Protocols | high | 6.0 | 1 | Data Breach |
| 5854 | Routers from T-Mobile, Zyxel, D-Link, Linksys | high | 6.0 | 1 | DDoS Attack |
| 5855 | Human error (email misdelivery) | high | 6.0 | 1 | Data Breach (Human Error / Misdelivery) |
| 5856 | Improper Access Controls on AWS EC2 | high | 6.0 | 1 | DDoS Attack |
| 5857 | Accela Software Error | high | 6.0 | 1 | Data Breach |
| 5858 | Email login credentials | high | 6.0 | 1 | Data Breach |
| 5859 | Social engineering, user trust exploitation | high | 6.0 | 1 | Malware Campaign |
| 5860 | Lack of Automated Secrets Rotation | high | 6.0 | 1 | Credential Theft |
| 5861 | Unsupported OS (Windows 2000, XP, Server 2003) | high | 6.0 | 1 | Security Audit Findings |
| 5862 | Automated Attack | high | 6.0 | 1 | Security Breach |
| 5863 | Public Visibility of Venmo Transactions and Contacts | high | 6.0 | 1 | Data Leak |
| 5864 | CVE-2025-12779 | high | 6.0 | 1 | Vulnerability |
| 5865 | Lack of Physical Security / Unencrypted Laptops | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5866 | Hardcoded Secrets in Code Repositories | high | 6.0 | 1 | Credential Theft |
| 5867 | Human error, Credential harvesting | high | 6.0 | 1 | Data Breach |
| 5868 | Unsecured Employee Roster | high | 6.0 | 1 | Data Breach |
| 5869 | Unpatched zero-day vulnerability | high | 6.0 | 1 | Zero-Day Exploit |
| 5870 | On-board ports containing vehicle data | high | 6.0 | 1 | Vehicle Theft |
| 5871 | Inadvertent transfer of control of the account to a malicious actor | high | 6.0 | 1 | Hacking |
| 5872 | Backup Payment Card Readers | high | 6.0 | 1 | Data Breach |
| 5873 | CVE-2026-20188 (Uncontrolled Resource Consumption - CWE-400) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5874 | Inadvertent Technical Error | high | 6.0 | 1 | Data Breach |
| 5875 | Automatic processing of iCalendar files, Trust in calendar notifications, Device code phishing (ConsentFix) | high | 6.0 | 1 | Phishing |
| 5876 | Misconfigured AWS S3 storage | high | 6.0 | 1 | Data Leak |
| 5877 | human trust in authoritative messages (e.g., toll agencies) | high | 6.0 | 1 | phishing |
| 5878 | Mandatory login gate on social media platform | high | 6.0 | 1 | Notification System Failure |
| 5879 | Unpatched firmware and default credentials in IoT devices | high | 6.0 | 1 | DDoS-for-hire |
| 5880 | Unpatched systems in video surveillance and access control | high | 6.0 | 1 | Security Audit Findings |
| 5881 | Employee Mistake | high | 6.0 | 1 | Data Breach |
| 5882 | Neglected to fix vulnerabilities | high | 6.0 | 1 | Data Breach |
| 5883 | Misconfiguration of AWS Application Load Balancer Authentication | high | 6.0 | 1 | Misconfiguration |
| 5884 | Vendor Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5885 | Installation management process in Mobile VPN with IPSec client for Windows | high | 6.0 | 1 | Privilege Escalation |
| 5886 | Social Engineering (Trust Exploitation, Urgency Tactics) | high | 6.0 | 1 | Phishing |
| 5887 | External System Breach (Hacking) | high | 6.0 | 1 | Data Breach |
| 5888 | Insufficient Email Security Protocols | high | 6.0 | 1 | Phishing |
| 5889 | URL Spoofing | high | 6.0 | 1 | Phishing |
| 5890 | Disconnected Security Tools | high | 6.0 | 1 | DDoS Attack |
| 5891 | Lack of insider threat detection and prevention measures | high | 6.0 | 1 | Insider Threat |
| 5892 | Same-Origin Policy Gaps (postMessage Wildcards, CORS Misconfigurations) | high | 6.0 | 1 | Data Breach |
| 5893 | Human Trust in Branded Communications | high | 6.0 | 1 | Phishing |
| 5894 | Database vulnerability | high | 6.0 | 1 | Data Breach |
| 5895 | Insecure use of pull_request_target in GitHub Actions workflows | high | 6.0 | 1 | Supply Chain Attack |
| 5896 | Legitimate authentication processes | high | 6.0 | 1 | Cyber Espionage |
| 5897 | Administrative Error | high | 6.0 | 1 | Data Breach |
| 5898 | Weak PIN reset security questions | high | 6.0 | 1 | Data Breach |
| 5899 | Flaw in the online application | high | 6.0 | 1 | Data Breach |
| 5900 | Unauthorized access to Microsoft 365 account | high | 6.0 | 1 | Data Breach |
| 5901 | Student Access to Staff Devices | high | 6.0 | 1 | Insider Threat |
| 5902 | Credential theft, Stolen payment tokens | high | 6.0 | 1 | Fraud |
| 5903 | Point-of-sale terminals | high | 6.0 | 1 | Data Breach |
| 5904 | CVE-2025-27610 | high | 6.0 | 1 | Vulnerability Exploitation |
| 5905 | Inadequate Vetting Procedures | high | 6.0 | 1 | Data Exposure |
| 5906 | Inadequate Firewalls | high | 6.0 | 1 | Data Breach |
| 5907 | Package look-up capabilities | high | 6.0 | 1 | Data Breach |
| 5908 | Accès non autorisé aux données clients | high | 6.0 | 1 | Cyberattaque |
| 5909 | Physical ATM Security | high | 6.0 | 1 | Data Breach |
| 5910 | unrestricted access to student email accounts | high | 6.0 | 1 | election fraud |
| 5911 | Lack of verification protocols for financial requests, unauthorized executable file execution | high | 6.0 | 1 | CEO Impersonation Fraud (Boss Scam) |
| 5912 | Misconfigured third-party service | high | 6.0 | 1 | Data Exposure |
| 5913 | Weak Cloud Security (Nintendo) | high | 6.0 | 1 | DDoS Attack |
| 5914 | Weak password ('solarwinds123') | high | 6.0 | 1 | Cyberattack |
| 5915 | Static Filtering in SEGs | high | 6.0 | 1 | Operational Risk |
| 5916 | Weak Authentication in Mobile Wallet Onboarding | high | 6.0 | 1 | Financial Fraud |
| 5917 | Employee error (opening malicious file) | high | 6.0 | 1 | Data Breach |
| 5918 | Stolen authentication cookie | high | 6.0 | 1 | Cyber Espionage |
| 5919 | Unsecured Audio Files | high | 6.0 | 1 | Data Exposure |
| 5920 | Lax controls | high | 6.0 | 1 | Insider Threat |
| 5921 | System-generated error | high | 6.0 | 1 | Data Breach |
| 5922 | Unsecured PHI on Laptop | high | 6.0 | 1 | Data Breach (Theft of Physical Device) |
| 5923 | weaknesses in social media platform moderation | high | 6.0 | 1 | fraud |
| 5924 | Hacked email account (settlement agent) | high | 6.0 | 1 | Payment Redirection Scam |
| 5925 | Accellion's File Transfer Appliance software | high | 6.0 | 1 | Data Breach |
| 5926 | Unpatched external web servers (Nintendo) | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5927 | Legacy X-Frame-Options Ineffectiveness | high | 6.0 | 1 | Data Breach |
| 5928 | CVE-2026-76163 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5929 | Inadequate credential monitoring and reliance on unmanaged devices for SaaS access | high | 6.0 | 1 | Credential Theft |
| 5930 | Lack of Token Rotation | high | 6.0 | 1 | Unauthorized Access |
| 5931 | Unauthorized Change to Website | high | 6.0 | 1 | Data Breach |
| 5932 | Click2Gov | high | 6.0 | 1 | Data Breach |
| 5933 | Software used by a third-party service provider | high | 6.0 | 1 | Data Breach |
| 5934 | Human Error (IT Support Tricked) | high | 6.0 | 1 | Data Breach |
| 5935 | misconfigured public-facing storage/exposure of sensitive backup file | high | 6.0 | 1 | data exposure |
| 5936 | Exposed Private Data | high | 6.0 | 1 | Data Leak |
| 5937 | Weak Authentication (Slack Cookies) | high | 6.0 | 1 | Data Breach |
| 5938 | Outdated Website | high | 6.0 | 1 | Data Breach |
| 5939 | CVE-2026-21525 (NULL pointer dereference, CWE-476) | high | 6.0 | 1 | Zero-Day Vulnerability |
| 5940 | Expanded digital identities, permissions, and access points due to AI adoption | high | 6.0 | 1 | Data Breach |
| 5941 | Suspicious WordPress plugin | high | 6.0 | 1 | Cyberattack |
| 5942 | CVE-2025-59789 (Uncontrolled Recursion / Stack Overflow in json2pb component) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5943 | Inadequate Internal Controls and Oversight | high | 6.0 | 1 | Insider Threat |
| 5944 | Insufficiently Secure Settings | high | 6.0 | 1 | Data Breach |
| 5945 | Exportable identity key in Chrome’s Cloud Authenticator | high | 6.0 | 1 | Vulnerability Exploitation |
| 5946 | Compromised Office 365 Account | high | 6.0 | 1 | Data Breach |
| 5947 | Human (phishing) | high | 6.0 | 1 | Phishing |
| 5948 | Website Configuration Error | high | 6.0 | 1 | Data Breach |
| 5949 | Bypassed payment authentication measures | high | 6.0 | 1 | Financial Fraud |
| 5950 | Employee Self Service system | high | 6.0 | 1 | Data Breach |
| 5951 | CVE-2026-15682 (filesystem junctions/reparse point abuse in Send Support Information feature) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5952 | Email Access | high | 6.0 | 1 | Business Email Compromise |
| 5953 | Weak ATM Security | high | 6.0 | 1 | Financial Fraud |
| 5954 | Hardcoded GitHub Token | high | 6.0 | 1 | Supply Chain Attack |
| 5955 | Citrix Remote Desktop Software Vulnerability | high | 6.0 | 1 | Unauthorized Access |
| 5956 | Lack of verification for payment changes (e.g., routing/banking number updates) | high | 6.0 | 1 | Fraud/Scam |
| 5957 | Legacy Access Controls, Identity Vulnerabilities | high | 6.0 | 1 | Data Breach |
| 5958 | Improper storage of login information on a personal device | high | 6.0 | 1 | Data Breach |
| 5959 | poor email filtering | high | 6.0 | 1 | phishing |
| 5960 | security risk analysis violations | high | 6.0 | 1 | regulatory_enforcement |
| 5961 | Employee System Credentials | high | 6.0 | 1 | Data Breach |
| 5962 | Android system permissions bypass | high | 6.0 | 1 | Vulnerability |
| 5963 | Insufficient oversight of contractor personnel with privileged access | high | 6.0 | 1 | Insider Threat |
| 5964 | Community sign-in tokens with excessive permissions | high | 6.0 | 1 | AI-driven exploit |
| 5965 | Human (Social Engineering) | high | 6.0 | 1 | Phishing |
| 5966 | Phishing/Email Compromise | high | 6.0 | 1 | Cyber Attack |
| 5967 | Loss of Physical Hard Drives | high | 6.0 | 1 | Data Breach |
| 5968 | Browsealoud Plugin | high | 6.0 | 1 | Cryptojacking |
| 5969 | End-of-life (EOL) software (Apache/2.4.52, Apache/2.4.6 with OpenSSL/1.0.2k-fips, etc.) | high | 6.0 | 1 | Phishing |
| 5970 | Legacy Credential | high | 6.0 | 1 | Supply Chain Attack |
| 5971 | Exposed ADB ports on internet-facing devices | high | 6.0 | 1 | DDoS-for-hire |
| 5972 | Data server configuration error | high | 6.0 | 1 | Data Breach |
| 5973 | Human Error / Policy Violation (Email Mismanagement) | high | 6.0 | 1 | Data Breach / Unauthorized Disclosure |
| 5974 | Corruptible local passkey state files (re-onboarding exploit) | high | 6.0 | 1 | Vulnerability Exploitation |
| 5975 | unsecured email systems | high | 6.0 | 1 | phishing |
| 5976 | Unknown Oracle E-Business System Vulnerability | high | 6.0 | 1 | Cyber Attack |
| 5977 | Lack of Cross-Border Data Transfer Compliance | high | 6.0 | 1 | Data Breach |
| 5978 | Unspecified vulnerability | high | 6.0 | 1 | Cyber Attack |
| 5979 | Lack of Risk Analysis | high | 6.0 | 1 | Data Breach |
| 5980 | Weak Authentication Controls | high | 6.0 | 1 | Data Breach |
| 5981 | Internal SharePoint Site | high | 6.0 | 1 | Data Breach |
| 5982 | Standard employee account credentials | high | 6.0 | 1 | Cyberattack |
| 5983 | WhatsApp screen-sharing feature (misuse) | high | 6.0 | 1 | social engineering |
| 5984 | Unmonitored DOM Changes (Lack of MutationObserver) | high | 6.0 | 1 | Data Breach |
| 5985 | Automated attack tools | high | 6.0 | 1 | DDoS |
| 5986 | Digitized navigation and operational systems | high | 6.0 | 1 | Cyberattack |
| 5987 | Unencrypted CouchDB installation | high | 6.0 | 1 | Data Leak |
| 5988 | Lack of Real-Time Email Authentication | high | 6.0 | 1 | Phishing |
| 5989 | Location tracking vulnerabilities | high | 6.0 | 1 | Data Collection Incident |
| 5990 | Third-party application vulnerability | high | 6.0 | 1 | Data Breach |
| 5991 | Unprotected RSYNC Server | high | 6.0 | 1 | Data Leak |
| 5992 | Employee Mailboxes | high | 6.0 | 1 | Data Breach |
| 5993 | Control deficiency in handling sensitive case data | high | 6.0 | 1 | Data Breach |
| 5994 | CVE-2026-81736 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5995 | Folio/IIN Integration Flaws | high | 6.0 | 1 | Data Breach |
| 5996 | Unsecured MongoDB Server | high | 6.0 | 1 | Data Exposure |
| 5997 | MOVEit Transfer platform vulnerability (likely CVE-2023-34362) | high | 6.0 | 1 | Data Breach |
| 5998 | Business Email Compromise | high | 6.0 | 1 | Data Breach |
| 5999 | Insider Tool Abuse | high | 6.0 | 1 | Account Takeover |
| 6000 | improper authentication | high | 6.0 | 1 | unauthorized access |
| 6001 | Website Payment Page | high | 6.0 | 1 | Data Breach |
| 6002 | Lack of Email Gateway HTML Attachment Blocking | high | 6.0 | 1 | Phishing |
| 6003 | Compromised Emails | high | 6.0 | 1 | Cyber Fraud |
| 6004 | weakness in AIS tampering detection | high | 6.0 | 1 | physical cyber convergence |
| 6005 | Inadvertent Permissions | high | 6.0 | 1 | Cyber Attack |
| 6006 | CVE-2025-33206 (CWE-78: Improper Neutralization of Special Elements in OS Commands) | high | 6.0 | 1 | Vulnerability |
| 6007 | Poor Employee Training | high | 6.0 | 1 | Data Leak |
| 6008 | Unauthorized access to WiFi management system | high | 6.0 | 1 | Cyber Attack |
| 6009 | Unpatched Public-Facing Servers | high | 6.0 | 1 | DDoS Attack |
| 6010 | DeFi Vulnerabilities | high | 6.0 | 1 | Market Manipulation |
| 6011 | Inadequate Multi-Factor Authentication (MFA) | high | 6.0 | 1 | Human Error |
| 6012 | Obfuscated Fake Context Alignment | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 6013 | Unencrypted Storage Devices | high | 6.0 | 1 | Data Breach |
| 6014 | Email Encryption | high | 6.0 | 1 | Data Breach |
| 6015 | Jailbroken AI (Google Gemini) | high | 6.0 | 1 | Fraud |
| 6016 | CVE-2025-61882, Oracle E-Business Suite (EBS) security flaws | high | 6.0 | 1 | Data Breach |
| 6017 | Unquoted Search Path Weakness in Plantronics Hub | high | 6.0 | 1 | Privilege Escalation |
| 6018 | Employee Malpractice | high | 6.0 | 1 | Data Breach |
| 6019 | Discord’s expired vanity URL reuse policy | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 6020 | Business Email Accounts | high | 6.0 | 1 | Data Breach |
| 6021 | Insufficient network segmentation between office and operational systems | high | 6.0 | 1 | Cyber Intrusion |
| 6022 | Low-and-slow request rate evasion of rate-limiting defenses | high | 6.0 | 1 | DDoS |
| 6023 | CitrixBleed | high | 6.0 | 1 | Data Breach |
| 6024 | Weak credential security (IT vendor account compromise) | high | 6.0 | 1 | unauthorized access |
| 6025 | Delayed Detection of Coordinated Trading Patterns | high | 6.0 | 1 | Financial Fraud |
| 6026 | npm package distribution, Dynamic script loading from external sources | high | 6.0 | 1 | Supply Chain Attack, DDoS Attack |
| 6027 | Employee Portal Accounts | high | 6.0 | 1 | Data Breach |
| 6028 | lack of package registry enforcement | high | 6.0 | 1 | supply chain attack |
| 6029 | Lack of Strict Marketplace Vetting | high | 6.0 | 1 | Malware Distribution |
| 6030 | Malware installation via phishing | high | 6.0 | 1 | Data Breach |
| 6031 | Default password ('1234') on wireless crosswalk buttons | high | 6.0 | 1 | Hacking |
| 6032 | Human trust in voice authentication | high | 6.0 | 1 | Vishing (Voice Phishing) |
| 6033 | Unknown Zero-Day Exploit (mentioned in Telegram chats) | high | 6.0 | 1 | Distributed Denial-of-Service (DDoS) Attack |
| 6034 | Legal Access via Emergency Order | high | 6.0 | 1 | Data Breach |
| 6035 | Social Engineering of Mobile Carriers | high | 6.0 | 1 | Account Takeover |
| 6036 | Inadequate Training Programs | high | 6.0 | 1 | Data Breach |
| 6037 | Unpatched flaws in TVT, Ruijie, TP-Link, ZTE devices | high | 6.0 | 1 | Botnet, DDoS |
| 6038 | Over-reliance on Limited Public Nodes (Centralization Risk) | high | 6.0 | 1 | Blockchain Security Breach |
| 6039 | JavaScript File Modification | high | 6.0 | 1 | Malware |
| 6040 | Unattended Property | high | 6.0 | 1 | Data Theft |
| 6041 | Psychological manipulation (urgency, authority impersonation) | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 6042 | Legacy banking systems | high | 6.0 | 1 | AI-generated exploits |
| 6043 | Compromise at a third party vendor's file servers | high | 6.0 | 1 | Data Breach |
| 6044 | Retired Internet Application | high | 6.0 | 1 | Data Breach |
| 6045 | Compromised official Belgian Grand Prix email account | high | 6.0 | 1 | Multi-vector attack |
| 6046 | Human error (successful phishing attack) | high | 6.0 | 1 | Data Breach |
| 6047 | Bug in open-source library | high | 6.0 | 1 | Data Leak |
| 6048 | privileged access controls | high | 6.0 | 1 | insider threat |
| 6049 | Human Trust in Email Communication | high | 6.0 | 1 | Phishing |
| 6050 | ADT Pulse Software Vulnerabilities | high | 6.0 | 1 | Unauthorized Access |
| 6051 | Insecure IoT devices | high | 6.0 | 1 | DDoS |
| 6052 | MIME type and filename extension mismatches | high | 6.0 | 1 | Vulnerability Exploit |
| 6053 | Weak Authentication (SMS-based 2FA) | high | 6.0 | 1 | Social Engineering |
| 6054 | Failure to Protect Sensitive Location Data | high | 6.0 | 1 | Physical Security Breach |
| 6055 | Unauthorized access to an employee email account | high | 6.0 | 1 | Data Breach |
| 6056 | improper use of email fields (To/CC instead of BCC) | high | 6.0 | 1 | data breach |
| 6057 | lack of bulk email security measures | high | 6.0 | 1 | data breach |
| 6058 | Unsecured Deleted Cloud Storage Buckets | high | 6.0 | 1 | Data Breach |
| 6059 | Unauthorized access to sensitive employee records | high | 6.0 | 1 | Data Breach |
| 6060 | developer reliance on third-party dependencies | high | 6.0 | 1 | supply chain attack |
| 6061 | AI-related blind spots | high | 6.0 | 1 | Data Breach |
| 6062 | CVE-2025-0128 | high | 6.0 | 1 | Denial of Service (DoS) |
| 6063 | Weak Security Questions | high | 6.0 | 1 | Data Breach |
| 6064 | Browser and plugin vulnerabilities | high | 6.0 | 1 | Malvertising |
| 6065 | Human trust in fake USPS parcel delivery messages | high | 6.0 | 1 | Smishing Campaign |
| 6066 | Human Carelessness | high | 6.0 | 1 | Human Error |
| 6067 | Email Privacy Misconfigurations | high | 6.0 | 1 | Data Breach |
| 6068 | Insufficient User Awareness Training | high | 6.0 | 1 | Phishing |
| 6069 | Faiblesse dans les procédures de vérification d'identité | high | 6.0 | 1 | Cyberattaque |
| 6070 | Google Business Profile verification loophole | high | 6.0 | 1 | defacement |
| 6071 | Weak URL validation in RecursiveUrlLoader (String.startsWith() check) and lack of private IP range validation | high | 6.0 | 1 | Server-Side Request Forgery (SSRF) |
| 6072 | Skill Gaps in Workforce | high | 6.0 | 1 | Data Breach |
| 6073 | User trust in brand communications; exploitation of psychological urgency and fear tactics. No technical vulnerabilities in LastPass, Bitwarden, or 1Password systems were exploited. | high | 6.0 | 1 | Phishing |
| 6074 | Reused/Weak Passwords (Phishing) | high | 6.0 | 1 | DDoS Attack |
| 6075 | Password Reset Token Leak | high | 6.0 | 1 | Account Hijacking |
| 6076 | Unencrypted Email | high | 6.0 | 1 | Data Breach |
| 6077 | Loss of Physical Control (Stolen Laptop) | high | 6.0 | 1 | Data Breach (Theft of Device) |
| 6078 | Human (Insider Trust) | high | 6.0 | 1 | Unauthorized Disclosure |
| 6079 | Three additional undisclosed vulnerabilities (details not specified) | high | 6.0 | 1 | Spoofing |
| 6080 | Microsoft Exchange email servers | high | 6.0 | 1 | Data Breach |
| 6081 | Donation Page | high | 6.0 | 1 | Data Breach |
| 6082 | CVE-2025-53770 (Microsoft SharePoint, CVSS 9.8) | high | 6.0 | 1 | Data Breach |
| 6083 | Lack of Physical Security Measures at ATM | high | 6.0 | 1 | Data Breach (Card Skimming) |
| 6084 | Microsoft OAuth 2.0 Device Authorization Flow | high | 6.0 | 1 | Credential Theft |
| 6085 | Microsoft Azure Tenant | high | 6.0 | 1 | Data Breach |
| 6086 | Publicly accessible Elasticsearch instance | high | 6.0 | 1 | Data Breach |
| 6087 | Stolen payment data | high | 6.0 | 1 | Financial Fraud |
| 6088 | weak identity verification for wallet transfers | high | 6.0 | 1 | cyber theft |
| 6089 | Backdoor in the system | high | 6.0 | 1 | Fraud |
| 6090 | Human Trust in Official-Looking Communications | high | 6.0 | 1 | Phishing |
| 6091 | Human error leading to unauthorized access | high | 6.0 | 1 | Phishing |
| 6092 | Zero-Day Vulnerability in ESG Equipment | high | 6.0 | 1 | Data Theft |
| 6093 | Unsecured Wi-Fi network | high | 6.0 | 1 | Malware |
| 6094 | Unauthorized access to Workday payroll accounts | high | 6.0 | 1 | Data Breach |
| 6095 | Error in resetting network settings | high | 6.0 | 1 | Data Breach |
| 6096 | Unauthorized access to payment card data | high | 6.0 | 1 | Data Breach |
| 6097 | Base64 Obfuscation Bypass | high | 6.0 | 1 | Prompt Injection |
| 6098 | Software vulnerability at vendor Infosys McCamish Systems LLC | high | 6.0 | 1 | Data Breach |
| 6099 | Excessive OAuth Token Scopes | high | 6.0 | 1 | Unauthorized Access |
| 6100 | Weak passwords (e.g., 'LOUVRE', 'THALES') | high | 6.0 | 1 | Security Audit Findings |
| 6101 | Muted Fake Context Alignment | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 6102 | Weak password encryption (unsalted MD5 and SHA-1) | high | 6.0 | 1 | Data Breach |
| 6103 | Human Trust in IT Support Impersonation | high | 6.0 | 1 | Data Breach |
| 6104 | Inadvertent public exposure of live surveillance feeds | high | 6.0 | 1 | Data Leak |
| 6105 | CMS vulnerability | high | 6.0 | 1 | Data Breach |
| 6106 | Trust in unsolicited communications | high | 6.0 | 1 | Scam |
| 6107 | multilingual social engineering gaps | high | 6.0 | 1 | phishing |
| 6108 | Changes introduced in the 2026 roadmap update, including sharding and execution environment enhancements | high | 6.0 | 1 | Security Breach |
| 6109 | Unauthorized Access due to Program Glitch | high | 6.0 | 1 | Data Breach |
| 6110 | Unconfirmed zero-day vulnerability in Metabase (CVE not specified) | high | 6.0 | 1 | Data Breach |
| 6111 | Default/weak credentials | high | 6.0 | 1 | Botnet, DDoS |
| 6112 | Unmanaged Secrets in CI/CD Pipelines | high | 6.0 | 1 | Credential Theft |
| 6113 | Payment Card Network | high | 6.0 | 1 | Data Breach |
| 6114 | Developer oversight leading to token exposure in public repositories | high | 6.0 | 1 | credential compromise |
| 6115 | Cached Credentials | high | 6.0 | 1 | Data Security Incident |
| 6116 | Weak Password/Credential Management | high | 6.0 | 1 | Data Breach |
| 6117 | Server vulnerability of a former IT service provider | high | 6.0 | 1 | Data Breach |
| 6118 | Insufficient Access Controls for High-Risk Secrets | high | 6.0 | 1 | Credential Theft |
| 6119 | Bypass of macOS Gatekeeper via direct Terminal input | high | 6.0 | 1 | Social Engineering, Malware |
| 6120 | Employee Credentials and Laptop | high | 6.0 | 1 | Data Breach |
| 6121 | Weak or compromised email account security | high | 6.0 | 1 | Data Breach |
| 6122 | Inherited extension reputation, Unicode spoofing, remote phishing page | high | 6.0 | 1 | Phishing |
| 6123 | Browser Fetch API Override | high | 6.0 | 1 | Cryptocurrency Theft |
| 6124 | Lack of cybersecurity awareness | high | 6.0 | 1 | Scam |
| 6125 | Unsecured IoT Devices (DVRs, WiFi Routers) | high | 6.0 | 1 | DDoS Attack |
| 6126 | Outdated website and aging IT infrastructure | high | 6.0 | 1 | Cybersecurity Breach |
| 6127 | Human Error (Falling for Spoofed Email) | high | 6.0 | 1 | Data Breach |
| 6128 | Improper handling of sensitive documents | high | 6.0 | 1 | Data Breach |
| 6129 | Compromised e-mail account | high | 6.0 | 1 | Data Breach |
| 6130 | Improper Client Segregation | high | 6.0 | 1 | Data Breach |
| 6131 | publicly available personal data (for voice cloning) | high | 6.0 | 1 | phishing |
| 6132 | Lack of Real-Time Verification for High-Risk Transactions | high | 6.0 | 1 | Social Engineering |
| 6133 | Weak password hashing (SHA-256) | high | 6.0 | 1 | Data Breach |
| 6134 | gaps in visibility | high | 6.0 | 1 | phishing |
| 6135 | Abuse of legitimate platform features (email parsing, merchant workflows, or input validation gaps) | high | 6.0 | 1 | Phishing / Social Engineering |
| 6136 | Lack of user awareness, perceived trustworthiness of FaceTime, screen-sharing access | high | 6.0 | 1 | Social Engineering / Phishing Scam |
| 6137 | Improperly secured MongoDB database | high | 6.0 | 1 | Data Breach |
| 6138 | Human factor - employees providing login credentials | high | 6.0 | 1 | Data Breach |
| 6139 | Lack of Data Redaction/Validation in FOI Process | high | 6.0 | 1 | Data Breach (Unintentional Disclosure) |
| 6140 | Weak Data Access Controls | high | 6.0 | 1 | Data Exposure |
| 6141 | human trust in FIFA branding | high | 6.0 | 1 | phishing |
| 6142 | Human Trust in Branded Communications / Lack of Multi-Channel Verification | high | 6.0 | 1 | Phishing / Social Engineering |
| 6143 | weak governance | high | 6.0 | 1 | phishing |
| 6144 | Unrelated software bugs in vendor’s trading software | high | 6.0 | 1 | Hacking, Software Bug |
| 6145 | Session Cookie Theft | medium | 5.0 | 1 | Security Breach |
| 6146 | Misconfiguration in test setup | medium | 5.0 | 1 | AI Model Breach |
| 6147 | CVE-2025-9242 (Out-of-bounds Write in 'iked' process) | medium | 5.0 | 1 | Vulnerability |
| 6148 | initramfs debug shell access during boot failures | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6149 | Exposed credentials from earlier data breaches | medium | 5.0 | 1 | Credential Stuffing |
| 6150 | URL Redirection | medium | 5.0 | 1 | Vulnerability Exploit |
| 6151 | Compromised npm maintainer account | medium | 5.0 | 1 | Supply Chain Attack |
| 6152 | Improper Access Control (Publicly Accessible File) | medium | 5.0 | 1 | Data Exposure / Unauthorized Access |
| 6153 | CVE-2025-61884 (potential, patched later) | medium | 5.0 | 1 | Data Breach |
| 6154 | Progress Software's MOVEit file transfer software | medium | 5.0 | 1 | Data Breach |
| 6155 | Ignoring Robots Exclusion Protocol | medium | 5.0 | 1 | Data Scraping |
| 6156 | Internal Logging Mechanism | medium | 5.0 | 1 | Data Exposure |
| 6157 | Database Misconfiguration | medium | 5.0 | 1 | Data Breach |
| 6158 | Insecure transmission of payment card data | medium | 5.0 | 1 | Payment Card Breach |
| 6159 | Credentials left on GitHub | medium | 5.0 | 1 | Data Breach |
| 6160 | Bug | medium | 5.0 | 1 | Data Leak |
| 6161 | Social Engineering (Impersonation of Trusted Mod) | medium | 5.0 | 1 | Malware Distribution |
| 6162 | Firewall bypass | medium | 5.0 | 1 | Penetration Test Exceeding Scope |
| 6163 | Progress Software's MOVEit software vulnerability | medium | 5.0 | 1 | Data Breach |
| 6164 | Unsecured Public Trello Boards | medium | 5.0 | 1 | Data Leak |
| 6165 | Improper third-party data sharing | medium | 5.0 | 1 | Data Breach |
| 6166 | Slack's link-rendering logic flaw (misinterpreting text as domains when missing spaces after punctuation) | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6167 | Outdated security measures, vulnerable CMS, weak authentication, inadequate monitoring | medium | 5.0 | 1 | SEO Poisoning |
| 6168 | Misconfigured or unpatched hosting infrastructure | medium | 5.0 | 1 | Data Breach |
| 6169 | Open database without authentication | medium | 5.0 | 1 | Data Breach |
| 6170 | Sorting Error | medium | 5.0 | 1 | Data Breach |
| 6171 | Poor access controls | medium | 5.0 | 1 | Data Breach |
| 6172 | Microsoft Power Apps portal configuration error | medium | 5.0 | 1 | Data Breach |
| 6173 | Unknown Third Party Credential Leak | medium | 5.0 | 1 | Credential Stuffing |
| 6174 | Trust in AI-assisted development tools | medium | 5.0 | 1 | Supply Chain Attack |
| 6175 | Bug in the GMX platform | medium | 5.0 | 1 | Cryptocurrency Theft |
| 6176 | Technical Setting in Tracking Technology | medium | 5.0 | 1 | Data Breach |
| 6177 | Data Entry Error | medium | 5.0 | 1 | Data Breach |
| 6178 | Weak SaaS Integration Controls | medium | 5.0 | 1 | Data Breach |
| 6179 | Improper Account Use | medium | 5.0 | 1 | Data Breach |
| 6180 | Older servers | medium | 5.0 | 1 | Data Breach |
| 6181 | Reused Usernames and Passwords | medium | 5.0 | 1 | Account Compromise |
| 6182 | Improper Access Restrictions | medium | 5.0 | 1 | Data Breach |
| 6183 | Unprotected Excel Spreadsheet | medium | 5.0 | 1 | Data Breach |
| 6184 | Exposed backup firewall preference files in MySonicWall cloud service | medium | 5.0 | 1 | Data Exposure |
| 6185 | Inappropriate email handling | medium | 5.0 | 1 | Data Breach |
| 6186 | Compromised Python SDK versions (4.87.1, 4.87.2) | medium | 5.0 | 1 | Supply Chain Attack |
| 6187 | CVE-2025-22245: Stored XSS in Router Port Configurations | medium | 5.0 | 1 | Vulnerability |
| 6188 | CVE-2023-2533 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6189 | Insufficient Data Protection Measures | medium | 5.0 | 1 | Data Breach |
| 6190 | OAuth Tokens | medium | 5.0 | 1 | Data Breach |
| 6191 | Device administrator access escalation | medium | 5.0 | 1 | ransomware |
| 6192 | Failure to redact information properly | medium | 5.0 | 1 | Data Breach |
| 6193 | Human error (password/authentication process manipulation) | medium | 5.0 | 1 | Cyberattack |
| 6194 | Denial of Service (DoS) | medium | 5.0 | 1 | Data Breach, Denial of Service (DoS) |
| 6195 | CVE-2025-48989 (HTTP/2 'Made You Reset' Memory Exhaustion) | medium | 5.0 | 1 | Vulnerability |
| 6196 | Archived website hosted by a now-former third-party vendor | medium | 5.0 | 1 | Data Breach |
| 6197 | Unsecured Vehicle | medium | 5.0 | 1 | Physical Theft |
| 6198 | GiveWP WordPress Plugin Flaw | medium | 5.0 | 1 | Data Breach |
| 6199 | Misconfigured security protocols or automated password reset systems | medium | 5.0 | 1 | Potential Data Exposure |
| 6200 | Lack of Output Encoding in Email Templates | medium | 5.0 | 1 | Email Spoofing |
| 6201 | Microsoft Exchange vulnerability | medium | 5.0 | 1 | Ransomware |
| 6202 | Third-Party Vendor Security Gaps | medium | 5.0 | 1 | Data Breach |
| 6203 | Compromised email login credentials | medium | 5.0 | 1 | Data Breach |
| 6204 | Indirect prompt injection (IPI) | medium | 5.0 | 1 | Vulnerability Exploit |
| 6205 | Lack of access controls, Unauthorized third-party server usage | medium | 5.0 | 1 | Data Misuse, Election Interference, Unauthorized Data Access |
| 6206 | Click2Gov System | medium | 5.0 | 1 | Data Breach, Fraud |
| 6207 | Unsecured Paper Files | medium | 5.0 | 1 | Data Breach |
| 6208 | Improper Disclosure of Research Funding | medium | 5.0 | 1 | Data Privacy Incident |
| 6209 | Third-party contractor’s laptop | medium | 5.0 | 1 | Data Breach |
| 6210 | Policy Violation | medium | 5.0 | 1 | Data Breach |
| 6211 | Insufficient input validation | medium | 5.0 | 1 | Cross-Site Scripting (XSS) |
| 6212 | Accidental Sharing of Data | medium | 5.0 | 1 | Data Breach |
| 6213 | Third-party vendor misconfiguration | medium | 5.0 | 1 | Data Breach |
| 6214 | CVE-2025-59489 (Unity Engine Arbitrary Code Execution) | medium | 5.0 | 1 | Vulnerability Disclosure |
| 6215 | Improper website data handling | medium | 5.0 | 1 | Data Breach (Accidental Disclosure) |
| 6216 | Outdated Routers with Remote Administration Enabled | medium | 5.0 | 1 | Cyber Attack |
| 6217 | Data Mishandling | medium | 5.0 | 1 | Data Breach |
| 6218 | Improper output encoding | medium | 5.0 | 1 | Cross-Site Scripting (XSS) |
| 6219 | Weak administrator password, lack of Multi-Factor Authentication, exposed remote access | medium | 5.0 | 1 | Ransomware |
| 6220 | Printing Error | medium | 5.0 | 1 | Data Breach |
| 6221 | Weak Username and Password Combinations | medium | 5.0 | 1 | Data Breach |
| 6222 | Accellion file sharing platform | medium | 5.0 | 1 | Data Breach |
| 6223 | Improper Data Disposal | medium | 5.0 | 1 | Data Breach |
| 6224 | CVE-2025-46176 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6225 | Insufficient access controls and monitoring in office suites | medium | 5.0 | 1 | Physical Security Breach, Theft |
| 6226 | Human Factor (Insider Access Abuse) | medium | 5.0 | 1 | Insider Threat |
| 6227 | Compromised wallet | medium | 5.0 | 1 | Data Breach |
| 6228 | CVE-2025-45080 | medium | 5.0 | 1 | Vulnerability |
| 6229 | Open Server | medium | 5.0 | 1 | Data Exposure |
| 6230 | AI Algorithm Inefficiency | medium | 5.0 | 1 | System Malfunction |
| 6231 | Email Indexing and Unsubscribe Vulnerability | medium | 5.0 | 1 | Data Exposure |
| 6232 | Design flaw in chat feature | medium | 5.0 | 1 | Data Exposure |
| 6233 | CVE-2025-11001 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6234 | Remote Access through Third-Party POS Vendor | medium | 5.0 | 1 | Payment Card Breach |
| 6235 | Vbulletin CMS Flaw | medium | 5.0 | 1 | Data Breach |
| 6236 | Instant Quote Platform | medium | 5.0 | 1 | Data Breach |
| 6237 | CVE-2019-9621 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6238 | Human Error (Mistaken Disclosure) | medium | 5.0 | 1 | Data Breach (Unauthorized Disclosure) |
| 6239 | Metadata Harvesting in Salesforce | medium | 5.0 | 1 | Data Breach |
| 6240 | Human error (misconfigured download link) | medium | 5.0 | 1 | Extortion |
| 6241 | Poor governance, lack of controls in records management, and inadequate note-taking practices | medium | 5.0 | 1 | Data Breach (Unauthorized Disclosure) |
| 6242 | CVE-2025-52891 | medium | 5.0 | 1 | Denial-of-Service |
| 6243 | Third-party software library vulnerability | medium | 5.0 | 1 | Data Breach |
| 6244 | Open Database Platform | medium | 5.0 | 1 | Data Exposure |
| 6245 | Data Handling Error | medium | 5.0 | 1 | Data Breach |
| 6246 | Weak cybersecurity measures | medium | 5.0 | 1 | Data Breach |
| 6247 | Vulnerability in Drift application’s Salesforce integration | medium | 5.0 | 1 | third-party breach |
| 6248 | Microsoft 365 Email Account | medium | 5.0 | 1 | Data Breach |
| 6249 | Poor physical installation of hardware | medium | 5.0 | 1 | Hardware Security Oversight |
| 6250 | Typosquatting (Visual Deception) | medium | 5.0 | 1 | Phishing |
| 6251 | Public-facing website | medium | 5.0 | 1 | Data Breach |
| 6252 | Customer service software misconfiguration | medium | 5.0 | 1 | Data Breach |
| 6253 | CVE-2026-5708 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 6254 | Out-of-Bounds Write (CWE-787) | medium | 5.0 | 1 | Denial-of-Service (DoS) |
| 6255 | Samsung.com | medium | 5.0 | 1 | Data Breach |
| 6256 | Gmail 'dot trick' combined with unsanitized HTML input in Robinhood's signup flow | medium | 5.0 | 1 | Phishing Attack |
| 6257 | Human Error (Inadvertent Disclosure) | medium | 5.0 | 1 | Data Breach |
| 6258 | Patient Billing System | medium | 5.0 | 1 | Data Breach |
| 6259 | Computer Programming Error | medium | 5.0 | 1 | Data Breach |
| 6260 | Outdated Windows software (including video surveillance systems) | medium | 5.0 | 1 | Physical Burglary |
| 6261 | Stored HTML Injection via Budget Name Input Field | medium | 5.0 | 1 | Email Spoofing |
| 6262 | Privileged credentials | medium | 5.0 | 1 | Data Breach |
| 6263 | User Account | medium | 5.0 | 1 | Data Breach |
| 6264 | Unprotected test environment, missing robots.txt file | medium | 5.0 | 1 | Data Exposure |
| 6265 | CVE-2025-22243: Stored XSS Vulnerability in NSX Manager UI | medium | 5.0 | 1 | Vulnerability |
| 6266 | Point-of-Sale (POS) Systems | medium | 5.0 | 1 | Data Breach |
| 6267 | Web Page Configuration | medium | 5.0 | 1 | Data Breach |
| 6268 | Remote Code Execution (RCE) in misconfigured Jenkins servers | medium | 5.0 | 1 | DDoS Botnet |
| 6269 | Progress Software's MOVEit Transfer | medium | 5.0 | 1 | Data Breach |
| 6270 | Byte Pair Encoding (BPE) or WordPiece tokenization weaknesses in LLMs | medium | 5.0 | 1 | AI/ML Vulnerability Exploitation |
| 6271 | CVE-2025-11002 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6272 | Flaw in proxy link handling | medium | 5.0 | 1 | Information Disclosure |
| 6273 | CVE-2025-27915 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6274 | CVE-2026-5709 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 6275 | Security hole in the in-house web application | medium | 5.0 | 1 | Data Breach |
| 6276 | Incorrect fax number | medium | 5.0 | 1 | Data Breach |
| 6277 | Snowflake data warehouse misconfiguration/weakness | medium | 5.0 | 1 | Data Breach |
| 6278 | Browser Cache Storage | medium | 5.0 | 1 | Data Breach |
| 6279 | Computer Error | medium | 5.0 | 1 | Data Breach |
| 6280 | Improper configuration of the website | medium | 5.0 | 1 | Data Breach |
| 6281 | Information Sharing Program | medium | 5.0 | 1 | Data Breach |
| 6282 | Inadequate data erasure protocols | medium | 5.0 | 1 | Data Handling Incident |
| 6283 | WordPress plugins | medium | 5.0 | 1 | Website Defacement |
| 6284 | Trust in Urgent Requests | medium | 5.0 | 1 | Awareness Campaign |
| 6285 | Service request lookup tool flaw allowing unauthorized access via bot | medium | 5.0 | 1 | Data Breach |
| 6286 | Lateral Movement via Stolen Credentials | medium | 5.0 | 1 | Supply Chain Attack |
| 6287 | abuse of legitimate Windows binaries (LOLBins - mshta.exe) | medium | 5.0 | 1 | ransomware |
| 6288 | CVE-2024-6914 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6289 | Shared infrastructure flaw | medium | 5.0 | 1 | Data Breach |
| 6290 | Insufficient Email Client-Side Sanitization | medium | 5.0 | 1 | Email Spoofing |
| 6291 | Inadequate data security program | medium | 5.0 | 1 | Data Breach |
| 6292 | Lack of verification of driver credentials and shipping paperwork | medium | 5.0 | 1 | Cyber Cargo Theft (Fictitious Pickup) |
| 6293 | CVE-2025-61882 (critical zero-day in Oracle E-Business Suite allowing remote system control without authentication) | medium | 5.0 | 1 | ransomware |
| 6294 | CVE-2025-22244: Stored XSS in Gateway Firewall Response Pages | medium | 5.0 | 1 | Vulnerability |
| 6295 | Email Security | medium | 5.0 | 1 | Data Breach |
| 6296 | Inconsistent data retention policy enforcement | medium | 5.0 | 1 | Data Breach |
| 6297 | Malicious JavaScript injection through API call | medium | 5.0 | 1 | Supply Chain Attack |
| 6298 | CVE-2026-24489 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6299 | Insecure Transport | medium | 5.0 | 1 | Data Leak |
| 6300 | Weakness in Drift-Salesforce integration security | medium | 5.0 | 1 | data breach |
| 6301 | Website Programming Change | medium | 5.0 | 1 | Data Breach |
| 6302 | MOVEit file transfer tool vulnerability | medium | 5.0 | 1 | Data Breach |
| 6303 | Typeform Vulnerability | medium | 5.0 | 1 | Data Breach |
| 6304 | Publicly accessible internal file | medium | 5.0 | 1 | Data Breach |
| 6305 | Incorrect Privacy Settings | medium | 5.0 | 1 | Data Breach |
| 6306 | Fragmented data governance | medium | 5.0 | 1 | Data Breach |
| 6307 | Bug in Vine | medium | 5.0 | 1 | Data Breach |
| 6308 | Improper disposal of electronic devices | medium | 5.0 | 1 | Data Breach |
| 6309 | CVE-2025-48384 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 6310 | Human Trust / Lack of Verification | medium | 5.0 | 1 | Social Engineering |
| 6311 | Improper Handling of Physical Records | medium | 5.0 | 1 | Data Breach |
| 6312 | Online appointment functionality failure | medium | 5.0 | 1 | Data Leak |
| 6313 | Unauthorized Biometric Data Collection | medium | 5.0 | 1 | Privacy Breach |
| 6314 | Online quote system | medium | 5.0 | 1 | Data Breach |
| 6315 | CVE-2024-41710 | medium | 5.0 | 1 | DDoS Botnet |
| 6316 | User Credentials from an Unrelated Site | medium | 5.0 | 1 | Data Breach |
| 6317 | Mistakenly attached sensitive information to email | medium | 5.0 | 1 | Data Breach |
| 6318 | Unauthorized access to secrets during pull request process | medium | 5.0 | 1 | Unauthorized Access |
| 6319 | CVE-2026-6296 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 6320 | Home internet connection access via VPN | medium | 5.0 | 1 | Security Breach |
| 6321 | Public Exposure of Sensitive Information | medium | 5.0 | 1 | Data Breach |
| 6322 | Improper truncation of payment card information on receipts | medium | 5.0 | 1 | Data Exposure |
| 6323 | Physical Loss of Storage Device | medium | 5.0 | 1 | Data Breach |
| 6324 | Unchecked third-party access, improper configurations, over-permissioned tools | medium | 5.0 | 1 | Data Exposure |
| 6325 | CVE-2025-0520 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 6326 | Unsecured Browser-Stored Passwords/Cookies | medium | 5.0 | 1 | Data Breach |
| 6327 | Supply-chain attack via npm ecosystem | medium | 5.0 | 1 | Infostealer |
| 6328 | Lack of physical security controls for confidential documents | medium | 5.0 | 1 | Data Breach |
| 6329 | Improper OAuth Token Security | medium | 5.0 | 1 | Data Breach |
| 6330 | Android Accessibility abuse | medium | 5.0 | 1 | ransomware |
| 6331 | Weak IAM credential security, lack of multifactor authentication (MFA) | medium | 5.0 | 1 | Cryptocurrency Mining |
| 6332 | CVE-2026-5707 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 6333 | CVE-2025-13223 (V8 JavaScript engine flaw) | medium | 5.0 | 1 | Zero-day vulnerability |
| 6334 | Software Glitch | medium | 5.0 | 1 | Data Breach |
| 6335 | Known vulnerabilities in Microsoft SharePoint | low | 2.5 | 1 | Cyberattack |
| 6336 | human_error | low | 2.5 | 1 | data_breach |
| 6337 | CVE-2025-12420 | low | 2.5 | 1 | Privilege Escalation |
| 6338 | Weak cybersecurity defenses and high AI-driven automation in attacks | low | 2.5 | 1 | botnets |
| 6339 | Misconfigured/unsecured server | low | 2.5 | 1 | Phishing (AiTM) |
| 6340 | Weaknesses in cloud security, insufficient encryption, inadequate identity management, lack of network segmentation | low | 2.5 | 1 | AI System Targeting, Cloud Infrastructure Exploitation |
| 6341 | CVE-2026-7323 | low | 2.5 | 1 | Vulnerability Patch |
| 6342 | CVE-2026-43284 (Dirty Frag) | low | 2.5 | 1 | Malware (Botnet) |
| 6343 | Realtek routers via port 52869 | low | 2.5 | 1 | DDoS-for-Hire Botnet |
| 6344 | CVE-2025-5678 | low | 2.5 | 1 | DDoS |
| 6345 | Website Search Function | low | 2.5 | 1 | Data Breach |
| 6346 | Improper conversation/message ID verification | low | 2.5 | 1 | Vulnerability Exploitation |
| 6347 | Device Tracking Vulnerabilities | low | 2.5 | 1 | Surveillance Investigation |
| 6348 | Identical authentication certificates, prolonged certificate validity (10 years), inadequate network access controls | low | 2.5 | 1 | Data Breach, Unauthorised Transactions, Malware Infection |
| 6349 | CVE-2025-7724 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6350 | Faulty fuel injector | low | 2.5 | 1 | Product Recall |
| 6351 | Remote access to car's specialized computers | low | 2.5 | 1 | Cyberattack |
| 6352 | Software Error | low | 2.5 | 1 | Data Breach |
| 6353 | CVE-2025-34028 | low | 2.5 | 1 | Path Traversal Vulnerability |
| 6354 | Insufficient policy enforcement in the WebView tag | low | 2.5 | 1 | Security Bypass |
| 6355 | Trust-based P2P protocol without authentication | low | 2.5 | 1 | Botnet Disruption |
| 6356 | Unattended Vehicle | low | 2.5 | 1 | Data Breach |
| 6357 | Web Server | low | 2.5 | 1 | Data Breach |
| 6358 | Reflected cross site scripting (XSS) | low | 2.5 | 1 | Vulnerability Exploitation |
| 6359 | CVE-2024-45432 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6360 | Exploitation of IoT and Android devices | low | 2.5 | 1 | DDoS |
| 6361 | Microsoft Teams TURN Servers | low | 2.5 | 1 | Malware Implant Framework |
| 6362 | CVE-2025-3699 | low | 2.5 | 1 | Vulnerability |
| 6363 | Improper Access Control in fepblue Mobile App | low | 2.5 | 1 | Data Breach (Unauthorized Access) |
| 6364 | CVE-2024-45433 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6365 | Unauthenticated LLM endpoints | low | 2.5 | 1 | Reconnaissance Scanning |
| 6366 | Microsoft Graph API | low | 2.5 | 1 | Malware Implant Framework |
| 6367 | External control of file paths | low | 2.5 | 1 | Data Breach |
| 6368 | 12 new exploits targeting D-Link, Huawei, NETGEAR, TP-Link, and other devices | low | 2.5 | 1 | DDoS-for-Hire Botnet |
| 6369 | Mailing Processes | low | 2.5 | 1 | Data Breach |
| 6370 | CVE-2025-24091 | low | 2.5 | 1 | Denial of Service (DoS) |
| 6371 | Temporary API code misconfiguration | low | 2.5 | 1 | Data Breach |
| 6372 | Printing Software Vulnerability | low | 2.5 | 1 | Data Breach |
| 6373 | CVE-2025-54957 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6374 | Misconfigured PAM (pam_exec module) | low | 2.5 | 1 | Backdoor |
| 6375 | CVE-2026-11856 | low | 2.5 | 1 | Vulnerability Disclosure |
| 6376 | CVE-2024-45434 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6377 | Unpatched vulnerabilities (31% of breaches) | low | 2.5 | 1 | data_breach |
| 6378 | CVE-2026-2441 (use-after-free in CSS component) | low | 2.5 | 1 | Zero-Day Vulnerability |
| 6379 | CVE-2024-22774 (Uncontrolled search path element) | low | 2.5 | 1 | Privilege Escalation |
| 6380 | Database Configuration Error | low | 2.5 | 1 | Data Breach |
| 6381 | Unauthorized network access | low | 2.5 | 1 | Physical and Logical Security Breach |
| 6382 | Fortinet EMS (CVE-2023-48788) | low | 2.5 | 1 | Ransomware |
| 6383 | Heap-based buffer overflows | low | 2.5 | 1 | Data Breach |
| 6384 | Unpatched firmware in home routers/cameras | low | 2.5 | 1 | Distributed Denial of Service (DDoS) |
| 6385 | CVE-2025-50054 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6386 | Public-facing website misconfiguration | low | 2.5 | 1 | Data Breach |
| 6387 | CVE-2025-22234 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6388 | High Volume Access Requests | low | 2.5 | 1 | Misconfiguration |
| 6389 | Writable MFGSTAT.zip file with incorrect permissions | low | 2.5 | 1 | Vulnerability Exploitation |
| 6390 | CWE-400 | low | 2.5 | 1 | Uncontrolled Resource Consumption |
| 6391 | Barracuda Networks email application vulnerability | low | 2.5 | 1 | Data Breach |
| 6392 | CVE-2024-21762 (FortiGate SSL-VPN RCE, CVSS 9.8) | low | 2.5 | 1 | Cyber Intrusion |
| 6393 | Lack of verification for AI crawler traffic | low | 2.5 | 1 | Scanning/Probing |
| 6394 | Legacy /sse endpoints | low | 2.5 | 1 | Reconnaissance Scanning |
| 6395 | Vulnerability in a third-party application | low | 2.5 | 1 | Unauthorized Access |
| 6396 | Authentication Flaw in cPanel Login Mechanisms | low | 2.5 | 1 | Authentication Vulnerability |
| 6397 | CVE-2026-7343 (Views) | low | 2.5 | 1 | Vulnerability Patch |
| 6398 | Unspecified | low | 2.5 | 1 | Phishing |
| 6399 | Compromised internal operations wallet | low | 2.5 | 1 | Security Breach |
| 6400 | PHP Exploit in MyBB Codebase | low | 2.5 | 1 | Infrastructure Disruption |
| 6401 | Unauthorized access to source code repository | low | 2.5 | 1 | Data Breach |
| 6402 | CVE-2026-3483 (CWE-749 - Exposed Dangerous Method) | low | 2.5 | 1 | Privilege Escalation |
| 6403 | Easily Exploitable Vulnerabilities | low | 2.5 | 1 | Vulnerability Exploitation |
| 6404 | CVE-2026-20841 (CWE-77: Command Injection) | low | 2.5 | 1 | Remote Code Execution (RCE) |
| 6405 | Lack of email authentication for Google AppSheet, social engineering (credential harvesting, 2FA bypass) | low | 2.5 | 1 | Phishing |
| 6406 | MOVEit secure file transfer application | low | 2.5 | 1 | Data Breach |
| 6407 | USBAnywhere | low | 2.5 | 1 | Remote Attack Vector |
| 6408 | Accidental Disclosure | low | 2.5 | 1 | Data Breach |
| 6409 | Lack of Awareness (pre-training) | low | 2.5 | 1 | Security Awareness |
| 6410 | Lack of authentication on C2 panel, weak SSH credentials, exposed services (RDP, SMB, WinRM) | low | 2.5 | 1 | Credential Stuffing |
| 6411 | Improper privilege management in Windows WalletService (CVE-2026-49176) | low | 2.5 | 1 | Privilege Escalation |
| 6412 | 2022 API Vulnerability | low | 2.5 | 1 | Credential-Stuffing Attack |
| 6413 | MOVEit Transfer tool vulnerability | low | 2.5 | 1 | Data Breach |
| 6414 | Improper fax transmission | low | 2.5 | 1 | Data Breach |
| 6415 | Publicly Accessible S3 Bucket | low | 2.5 | 1 | Data Breach |
| 6416 | DNS misconfiguration (lame delegation), browser notification permissions | low | 2.5 | 1 | Push-Notification Scam |
| 6417 | X11 clipboard functionality | low | 2.5 | 1 | Malware |
| 6418 | CVE-2025-48651 | low | 2.5 | 1 | Vulnerability |
| 6419 | Use-after-free flaws | low | 2.5 | 1 | Data Breach |
| 6420 | Microsoft SharePoint vulnerabilities (patched in mid-July) | low | 2.5 | 1 | Cyberattack |
| 6421 | Exposed credentials, misconfigured test environment | low | 2.5 | 1 | AI-driven unauthorized access |
| 6422 | Logic error in handling Authorization objects in ACME service, allowing improper reuse of domain validation data | low | 2.5 | 1 | Certificate Misissuance |
| 6423 | Memory leak in embedded JavaScript engine | low | 2.5 | 1 | Resource Exhaustion |
| 6424 | CVE-2025-65606 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6425 | Vulnerability in the outage app | low | 2.5 | 1 | Data Breach |
| 6426 | CVE-2025-34142 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6427 | Residential proxy services infiltration | low | 2.5 | 1 | Botnet, DDoS |
| 6428 | CVE-2025-36537 | low | 2.5 | 1 | Vulnerability |
| 6429 | DLL sideloading (log4net.dll), BYOVD (Bring Your Own Vulnerable Driver) techniques | low | 2.5 | 1 | Ransomware |
| 6430 | CVE-2026-40176 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6431 | Improper link resolution in Windows Update Stack (CVE-2025-21204) | low | 2.5 | 1 | Privilege Escalation |
| 6432 | Secure Email Account | low | 2.5 | 1 | Data Breach |
| 6433 | Lack of phishing controls, Unrestricted RMM tool usage, Insufficient EDR monitoring | low | 2.5 | 1 | Phishing, Social Engineering, RMM Abuse |
| 6434 | Stack-based buffer overflow | low | 2.5 | 1 | Vulnerability Exploitation |
| 6435 | CVE-2026-35273 (CVSS 9.8, unauthenticated remote code execution in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62) | low | 2.5 | 1 | Data Breach |
| 6436 | GeminiJack | low | 2.5 | 1 | Zero-Click Exploit |
| 6437 | Vendor's Software Flaw | low | 2.5 | 1 | Data Breach |
| 6438 | CVE-2025-34143 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6439 | CVE-2025-4230 | low | 2.5 | 1 | Command Injection |
| 6440 | Data Security Vulnerabilities | low | 2.5 | 1 | Data Security Vulnerability |
| 6441 | OS command injection | low | 2.5 | 1 | vulnerability_exploitation |
| 6442 | Imperfect Process | low | 2.5 | 1 | Data Breach |
| 6443 | Admin password bypass | low | 2.5 | 1 | Authentication Bypass |
| 6444 | Critical Telnet vulnerability allowing unauthorized access | low | 2.5 | 1 | Vulnerability Exploitation |
| 6445 | CVE-2025-50165 (Uninitialized function pointer dereference in WindowsCodecs.dll) | low | 2.5 | 1 | Remote Code Execution (RCE) |
| 6446 | Unprotected IoT Devices | low | 2.5 | 1 | IoT Device Hack |
| 6447 | Debug code in production builds causing routing failure | low | 2.5 | 1 | Vulnerability |
| 6448 | DMARC authentication bypass, trusted infrastructure abuse | low | 2.5 | 1 | Phishing |
| 6449 | Lack of contextual awareness in AI systems | low | 2.5 | 1 | AI-related data exposure |
| 6450 | CVE-2025-53506 | low | 2.5 | 1 | Denial of Service (DoS) |
| 6451 | Stored XSS in Zimbra Classic Web Client | low | 2.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 6452 | zero-click vulnerabilities | low | 2.5 | 1 | vulnerability_exploitation |
| 6453 | MOVEit Transfer tool vulnerabilities | low | 2.5 | 1 | Data Breach |
| 6454 | Misconfigured web application firewall in cloud infrastructure | low | 2.5 | 1 | Data Breach |
| 6455 | Dark-Web Datasets | low | 2.5 | 1 | Credential-Stuffing Attack |
| 6456 | Serial number extraction | low | 2.5 | 1 | Authentication Bypass |
| 6457 | Incompatible resource access | low | 2.5 | 1 | Data Breach |
| 6458 | Social engineering, malware-laced coding assignments | low | 2.5 | 1 | Cryptocurrency Theft |
| 6459 | Unencrypted Hard Drive | low | 2.5 | 1 | Data Breach |
| 6460 | CVE-2026-20805 | low | 2.5 | 1 | Information Disclosure |
| 6461 | Unsecured Computer Server | low | 2.5 | 1 | Data Breach |
| 6462 | Android APK vulnerabilities | low | 2.5 | 1 | DDoS Attack |
| 6463 | Known loopholes in SonicWall VPN | low | 2.5 | 1 | Exploitation of Vulnerability |
| 6464 | CVE-2025-34141 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6465 | Vendor Service (Accellion) | low | 2.5 | 1 | Data Breach |
| 6466 | Phishing Susceptibility | low | 2.5 | 1 | Security Awareness |
| 6467 | Unauthorized access to historical emails | low | 2.5 | 1 | Data Breach |
| 6468 | CVE-2024-11857 | low | 2.5 | 1 | Vulnerability |
| 6469 | CVE-2025-7206 | low | 2.5 | 1 | Vulnerability |
| 6470 | Insecure remote administration access | low | 2.5 | 1 | Security Breach |
| 6471 | Mali GPU vulnerabilities (memory access violations, kernel information leaks) | low | 2.5 | 1 | Vulnerability Disclosure |
| 6472 | CVE-2026-7324 | low | 2.5 | 1 | Vulnerability Patch |
| 6473 | Hardcoded trust exception in authentication flow (2FA bypass) | low | 2.5 | 1 | Zero-Day Exploit |
| 6474 | Trust in employment process | low | 2.5 | 1 | Insider Threat |
| 6475 | OAuth consent prompts, user behavior | low | 2.5 | 1 | Phishing |
| 6476 | CVE-2026-45502 | low | 2.5 | 1 | SSRF (Server-Side Request Forgery) |
| 6477 | Server setup error | low | 2.5 | 1 | Data Breach |
| 6478 | Damaged mailing | low | 2.5 | 1 | Data Breach |
| 6479 | Lack of proper access controls and oversight in AI systems | low | 2.5 | 1 | Data Breach |
| 6480 | Improper error handling | low | 2.5 | 1 | Misconfiguration |
| 6481 | Automatic execution of tasks.json in VS Code/Cursor, lack of user interaction requirement in Cursor | low | 2.5 | 1 | Phishing, Malware, Credential Theft, Cryptocurrency Theft |
| 6482 | Vulnerability on older game websites | low | 2.5 | 1 | Data Breach |
| 6483 | Weak credentials/default passwords in IoT devices | low | 2.5 | 1 | Distributed Denial of Service (DDoS) |
| 6484 | CVE-2026-11586 | low | 2.5 | 1 | Vulnerability Disclosure |
| 6485 | Improperly secured GitHub secrets (long-lived PyPI tokens stored in workflows) | low | 2.5 | 1 | supply chain attack |
| 6486 | CVE-2025-26147 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6487 | CVE-2026-45586 (Improper Link Resolution - CWE-59) | low | 2.5 | 1 | Privilege Escalation |
| 6488 | CVE-2025-27387 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6489 | Hard-coded secret values | low | 2.5 | 1 | Vulnerability Exploitation |
| 6490 | OAuth Token Leak via URL Parameters | low | 2.5 | 1 | Data Breach |
| 6491 | CVE-2026-0227 | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 6492 | CVE-2026-20029 | low | 2.5 | 1 | Information Disclosure |
| 6493 | CVE-2026-9079 | low | 2.5 | 1 | Vulnerability Disclosure |
| 6494 | Insufficient intrusion detection | low | 2.5 | 1 | Ransomware |
| 6495 | CVE-2025-5138 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6496 | AI assistant configuration files | low | 2.5 | 1 | Reconnaissance Scanning |
| 6497 | Hiring Process | low | 2.5 | 1 | State-Sponsored Hacker Infiltration |
| 6498 | Exploit in Trinity wallet app | low | 2.5 | 1 | Cryptocurrency Wallet Exploit |
| 6499 | Active session cookies (bypassing MFA) | low | 2.5 | 1 | Ransomware Enablement via Infostealer Malware |
| 6500 | Human error in server configuration | low | 2.5 | 1 | Unauthorized Access |
| 6501 | CVE-2025-13348 | low | 2.5 | 1 | Vulnerability |
| 6502 | CVE-2026-26127 (Out-of-bounds read weakness, CWE-125) | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 6503 | Previously undetected vulnerability in the Productivity Commission's website | low | 2.5 | 1 | Email Spoofing |
| 6504 | CVE-2025-6029 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6505 | Bug introduced during an update of the email system | low | 2.5 | 1 | Data Leak |
| 6506 | CVE-2026-45492 | low | 2.5 | 1 | Vulnerability |
| 6507 | Misconfigured internet access, overlapping test/real-world entity names, weak authentication controls (password reuse, lack of rate-limiting) | low | 2.5 | 1 | AI-driven security misconfiguration |
| 6508 | CVE-2026-46300 (Fragnesia) | low | 2.5 | 1 | Malware (Botnet) |
| 6509 | MOVEit server vulnerability | low | 2.5 | 1 | Data Breach |
| 6510 | Out-of-bounds reads | low | 2.5 | 1 | Data Breach |
| 6511 | CVE-2026-23600 | low | 2.5 | 1 | Authentication Bypass |
| 6512 | CVE-2025-24813 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6513 | CVE-2025-34140 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6514 | Nvidia Triton Inference Server vulnerabilities (DoS, information disclosure) | low | 2.5 | 1 | Vulnerability Disclosure |
| 6515 | SSH password capture | low | 2.5 | 1 | Data Breach |
| 6516 | CVE-2026-8927 | low | 2.5 | 1 | Vulnerability Disclosure |
| 6517 | Fake Firmware | low | 2.5 | 1 | Supply Chain Attack |
| 6518 | CVE-2026-48770 | low | 2.5 | 1 | Arbitrary Code Execution |
| 6519 | CVE-2026-9545 | low | 2.5 | 1 | Vulnerability Disclosure |
| 6520 | CVE-2026-3008 (String injection in FindInFiles functionality) | low | 2.5 | 1 | Vulnerability |
| 6521 | Exposed MCP servers | low | 2.5 | 1 | Reconnaissance Scanning |
| 6522 | CVE-2025-37103 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6523 | CVE-2026-23869 (Deserialization of untrusted data - CWE-502, Uncontrolled resource consumption - CWE-400) | low | 2.5 | 1 | Denial of Service (DoS) |
| 6524 | CVE-2026-48778 | low | 2.5 | 1 | Arbitrary Code Execution |
| 6525 | Data Transfer Error | low | 2.5 | 1 | Data Breach |
| 6526 | Zero-day vulnerability in Oracle’s eBusiness Suite | low | 2.5 | 1 | Data Breach |
| 6527 | Vulnerabilities in Cleo's platform | low | 2.5 | 1 | Data Breach |
| 6528 | ConnectWise ScreenConnect (CVE-2024-1709) | low | 2.5 | 1 | Ransomware |
| 6529 | CVE-2025-13878 | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 6530 | Unmonitored lateral movement | low | 2.5 | 1 | Cyber Breach |
| 6531 | CVE-2025-32756 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6532 | Exposed .env files | low | 2.5 | 1 | Reconnaissance Scanning |
| 6533 | CVE-2026-43603 (NULL pointer dereference) | low | 2.5 | 1 | Vulnerability Disclosure |
| 6534 | Vulnerability in data storage system | low | 2.5 | 1 | Data Breach |
| 6535 | CVE-2025-2761 | low | 2.5 | 1 | Software Vulnerability |
| 6536 | CVE-2026-2636 (Improper flag validation in CLFS.sys) | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 6537 | Programming Code Error | low | 2.5 | 1 | Data Breach |
| 6538 | Mobile app API | low | 2.5 | 1 | Data Breach |
| 6539 | Improper Storage of Sensitive Information | low | 2.5 | 1 | Data Breach |
| 6540 | CVE-2025-1234 | low | 2.5 | 1 | DDoS |
| 6541 | Rowhammer | low | 2.5 | 1 | Vulnerability Exploitation |
| 6542 | Third-party vendor sub-system | low | 2.5 | 1 | Data Transmission Anomaly |
| 6543 | CVE-2025-55188 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6544 | Unsecured FTP Server | low | 2.5 | 1 | Data Breach |
| 6545 | Lack of Backup Procedure | low | 2.5 | 1 | Data Loss |
| 6546 | Malformed ZIP archives evading security tools, native Windows unarchiving utility exploitation | low | 2.5 | 1 | Malware Campaign |
| 6547 | CVE-2025-59718 | low | 2.5 | 1 | Authentication Bypass |
| 6548 | Flaw in HTML sanitizer (rcube_washtml) failing to block <feImage> SVG element | low | 2.5 | 1 | Privacy Bypass |
| 6549 | Misprinting of personal information | low | 2.5 | 1 | Data Breach |
| 6550 | Use-after-free in Linux kernel’s STP timer lifecycle (CVE not specified) | low | 2.5 | 1 | Vulnerability Exploitation |
| 6551 | Inconsistent cybersecurity protections, budget constraints | low | 2.5 | 1 | Cyberattack |
| 6552 | CVE-2025-5601 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6553 | Vulnerability in third-party firewall software | low | 2.5 | 1 | Data Breach |
| 6554 | CVE-2026-20824 | low | 2.5 | 1 | Security Feature Bypass |
| 6555 | CVE-2025-1087 | low | 2.5 | 1 | Template Injection |
| 6556 | CVE-2025-24016 (Unsafe Deserialization) | low | 2.5 | 1 | Botnet Exploitation |
| 6557 | Weak message validation | low | 2.5 | 1 | Vulnerability Exploitation |
| 6558 | Shared File Location | low | 2.5 | 1 | Data Breach |
| 6559 | MOVEit file transfer program vulnerability | low | 2.5 | 1 | Data Breach |
| 6560 | XSS in *Software Acquisition Guide: Supplier Response Web Tool* | low | 2.5 | 1 | Vulnerability |
| 6561 | Misconfigured permissions | low | 2.5 | 1 | Cyber Breach |
| 6562 | Unauthorized physical access | low | 2.5 | 1 | Physical and Logical Security Breach |
| 6563 | CVE-2026-48800 | low | 2.5 | 1 | Arbitrary Code Execution |
| 6564 | Malicious QR Code | low | 2.5 | 1 | Supply Chain Attack |
| 6565 | Unsecured Storage of Usernames and Passwords | low | 2.5 | 1 | Data Breach |
| 6566 | Poor password practices | low | 2.5 | 1 | Ransomware |
| 6567 | CVE-2026-32185 | low | 2.5 | 1 | Spoofing |
| 6568 | CVE-2026-7320 (Audio/Video) | low | 2.5 | 1 | Vulnerability Patch |
| 6569 | Remote Code Execution (RCE) in auto-updater software | low | 2.5 | 1 | Vulnerability Exploitation |
| 6570 | CVE-2026-7322 | low | 2.5 | 1 | Vulnerability Patch |
| 6571 | Third-party software vendor (MOVEit) | low | 2.5 | 1 | Data Breach |
| 6572 | CVE-2026-7344 (Accessibility) | low | 2.5 | 1 | Vulnerability Patch |
| 6573 | Exposed .env file with database credentials | low | 2.5 | 1 | Data Exposure, Potential DoS Attack |
| 6574 | Counterfeit Hardware | low | 2.5 | 1 | Supply Chain Attack |
| 6575 | Potential link to ShieldBreak (CVE-2026-50656 bypass) | low | 2.5 | 1 | Software Failure |
| 6576 | Broken Access Control (Insecure Direct Object References - IDOR) | low | 2.5 | 1 | API Security Vulnerability Exploitation |
| 6577 | Mailing Label Printing Error | low | 2.5 | 1 | Data Breach |
| 6578 | Credentials obtained from another website | low | 2.5 | 1 | Data Breach |
| 6579 | Exposed phone numbers from data breaches or leaked marketing databases | low | 2.5 | 1 | Phishing (SMS-based) |
| 6580 | Low entropy in database metadata retrieval | low | 2.5 | 1 | Privacy Vulnerability |
| 6581 | Arbitrary File Upload (CVE-2025-64374) | low | 2.5 | 1 | Vulnerability Exploitation |
| 6582 | Unpatched IoT/ARC processor vulnerabilities | low | 2.5 | 1 | DDoS Attack |
| 6583 | CVE-2025-59719 | low | 2.5 | 1 | Authentication Bypass |
| 6584 | Unsecured AWS S3 bucket (lack of password protection and encryption) | low | 2.5 | 1 | Data Breach |
| 6585 | Exposed RDP server | low | 2.5 | 1 | Ransomware |
| 6586 | CVE-2025-20701 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6587 | Human psychology (trust in job applications), abuse of trusted cloud infrastructure (AWS EC2/S3) | low | 2.5 | 1 | Phishing/Social Engineering, Malware Delivery |
| 6588 | Insufficient file authentication in the updater mechanism | low | 2.5 | 1 | Software Vulnerability |
| 6589 | MFA Fatigue | low | 2.5 | 1 | Social Engineering |
| 6590 | CVE-2026-45494 | low | 2.5 | 1 | Vulnerability |
| 6591 | Misuse of AI tools for malicious automation, lack of forensic trails in in-memory Python HTTP server | low | 2.5 | 1 | Botnet / C&C Infrastructure |
| 6592 | CVE-2026-45495 | low | 2.5 | 1 | Vulnerability |
| 6593 | CVE-Unassigned (ASLR Bypass via NSKeyedArchiver Serialization Pointer Leak) | low | 2.5 | 1 | Vulnerability Disclosure |
| 6594 | CVE-2025-4563 | low | 2.5 | 1 | Vulnerability |
| 6595 | CVE-2025-46789 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6596 | Evasion of rate-limiting defenses via 'low and slow' fragmentation | low | 2.5 | 1 | DDoS |
| 6597 | Unmonitored networks | low | 2.5 | 1 | Ransomware |
| 6598 | CVE-2024-45431 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6599 | Compromised IoT devices (routers, IP cameras, digital video recorders) | low | 2.5 | 1 | DDoS Attack |
| 6600 | Unsecured attic access, potential food attractants | low | 2.5 | 1 | Physical Intrusion (Non-Cyber) |
| 6601 | Missing portable data storage device | low | 2.5 | 1 | Data Breach |
| 6602 | Critical Issues | low | 2.5 | 1 | Vulnerability Exploitation |
| 6603 | Stolen GitHub credentials | low | 2.5 | 1 | Source Code Theft |
| 6604 | CVE-2025-7723 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6605 | Psychological manipulation (urgency, stress, perceived authority) | low | 2.5 | 1 | Phishing/Scam |
| 6606 | CVE-2026-20803 | low | 2.5 | 1 | Elevation of Privilege |
| 6607 | CVE-2026-33825 (Insufficient access-control granularity - CWE-1220) | low | 2.5 | 1 | Privilege Escalation |
| 6608 | Social Engineering (Legitimate Appearance), Dynamic Payload Updates, Stolen AI Infrastructure | low | 2.5 | 1 | Malicious Package / Data Exfiltration |
| 6609 | CVE-2025-9101 | low | 2.5 | 1 | DDoS |
| 6610 | Third-party file transfer software | low | 2.5 | 1 | Data Breach |
| 6611 | Impersonation, Forged Documentation, Lack of Verification | low | 2.5 | 1 | Social Engineering / Business Email Compromise (BEC) |
| 6612 | Flaw in ASUS DriverHub | low | 2.5 | 1 | Vulnerability Exploit |
| 6613 | Cloned Phishing Site | low | 2.5 | 1 | Supply Chain Attack |
| 6614 | Path traversal flaw in file download mechanism and guardrail bypass via prompt manipulation | low | 2.5 | 1 | Vulnerability Exploitation |
| 6615 | SharePoint Online | low | 2.5 | 1 | Malware Implant Framework |
| 6616 | unpatched_software | low | 2.5 | 1 | data_breach |
| 6617 | CVE-2025-49464 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6618 | Shared authentication systems, privileged access management gaps | low | 2.5 | 1 | Credential Exposure |
| 6619 | ADB enabled on port 5555 | low | 2.5 | 1 | Botnet, DDoS |
| 6620 | Human vulnerability (social engineering), potential WordPress plugin flaw (authentication bypass) | low | 2.5 | 1 | Social Engineering |
| 6621 | CVE-2026-40261 | low | 2.5 | 1 | Vulnerability Exploitation |
| 6622 | CVE-2026-7363 (Canvas) | low | 2.5 | 1 | Vulnerability Patch |
| 6623 | CVE-2026-7361 (iOS) | low | 2.5 | 1 | Vulnerability Patch |
| 6624 | Compromised developer account, abuse of npm publishing mechanism | low | 2.5 | 1 | Supply-Chain Attack |
| 6625 | CVE-2025-2760 | low | 2.5 | 1 | Software Vulnerability |
| 6626 | Obsolete servers exposed to the internet | low | 2.5 | 1 | Cyberattack |
| 6627 | Unsafe GitHub Actions expression interpolation in `jira_issue.yml` workflow | low | 2.5 | 1 | Command Injection |
| 6628 | CVE-2025-49825 | low | 2.5 | 1 | Vulnerability Exploit |
| 6629 | vBulletin’s reliance on PHP’s Reflection API for its custom Model-View-Controller (MVC) framework and API system | low | 2.5 | 1 | Remote Code Execution (RCE) |