Top Exploited Vulnerabilities
The most actively exploited vulnerabilities across the companies tracked by Rankiteo. Aggregated from real incident data to help you prioritize patching.
5745
Vulnerabilities Tracked
4630
Critical Severity
665
High Severity
7,360
Total Exposures
Vulnerability Rankings
| # | Vulnerability | Severity | CVSS | Incidents | Attack Type |
|---|---|---|---|---|---|
| 1 | Human Error | critical | 10.0 | 147 | Social Engineering, phishing, Phishing |
| 2 | Unauthorized Access | critical | 10.0 | 79 | Data Exfiltration, Data Breach, Security Concerns |
| 3 | Email Account | critical | 8.5 | 54 | Data Breach, Phishing Scam |
| 4 | Lack of Multi-Factor Authentication (MFA) | critical | 10.0 | 42 | data breach, Cyber Attack, Credential Stuffing |
| 5 | Physical Security | critical | 10.0 | 40 | Data Breach, Data Theft |
| 6 | Human | critical | 10.0 | 31 | Phishing, Data Breach |
| 7 | Misconfiguration | critical | 10.0 | 30 | Supply Chain Attack, Data Exposure, worm-driven campaign |
| 8 | Email Account Compromise | critical | 10.0 | 28 | Data Breach |
| 9 | Improper Access Control | critical | 10.0 | 28 | Data Exposure, Data Breach, data breach |
| 10 | Employee Email Account | critical | 8.5 | 27 | Data Breach |
| 11 | Social Engineering | critical | 10.0 | 26 | Cryptocurrency Investment Scam (Pig Butchering/Romance Baiting), data breach, Phishing |
| 12 | Unauthorized Access to Email Account | critical | 10.0 | 21 | Data Breach, Data Theft |
| 13 | SQL Injection | critical | 10.0 | 19 | Cyber Attack, vulnerability_exploitation, Cyberattack |
| 14 | Insider Threat | critical | 10.0 | 18 | Insider Wrongdoing, Unauthorized Access, Data Breach |
| 15 | unpatched systems | critical | 10.0 | 18 | Surveillance, third-party breach, Ransomware |
| 16 | Weak Password | critical | 10.0 | 16 | Data Breach, Phishing, Data Breach, Ransomware, phishing |
| 17 | MOVEit software vulnerability | critical | 10.0 | 15 | Data Breach |
| 18 | Website Vulnerability | critical | 10.0 | 14 | Data Breach |
| 19 | Improper Data Handling | critical | 10.0 | 14 | Data Exposure, Data Breach, Fraud |
| 20 | Unsecured Database | critical | 10.0 | 13 | Data Exposure, Data Breach, Data Leak |
| 21 | Inadequate security measures | critical | 10.0 | 12 | Data Breach |
| 22 | Unencrypted Data | critical | 10.0 | 12 | data breach, Data Breach, ransomware |
| 23 | Human Error (Phishing Susceptibility) | critical | 10.0 | 12 | Phishing, Data Breach, Data Breach (Phishing) |
| 24 | CVE-2024-57727 | critical | 10.0 | 11 | ransomware, Supply-Chain Attack, Ransomware |
| 25 | Weak or Stolen Credentials | critical | 10.0 | 11 | Data Breach, Data Breach (General Discussion), ransomware |
| 26 | Lack of Physical Security | critical | 10.0 | 11 | Data Breach, cybercrime, Data Leak |
| 27 | Lack of Password Protection | critical | 10.0 | 11 | Data Exposure, Data Breach |
| 28 | Compromised Email Account | critical | 10.0 | 11 | Data Breach |
| 29 | Previously unknown vulnerability | critical | 10.0 | 10 | Ransomware Attack, Data Breach, Ransomware |
| 30 | Unsecured cloud environment | critical | 10.0 | 10 | Data Breach |
| 31 | Unpatched vulnerabilities | critical | 10.0 | 10 | Cyber Threat Alert, DDoS Attack, Espionage |
| 32 | Stolen Credentials | critical | 10.0 | 10 | Supply Chain Attack, Phishing, Ransomware |
| 33 | Human Error (Social Engineering) | critical | 10.0 | 10 | Cyber Extortion, spear-phishing, Phishing |
| 34 | Weak Access Controls | critical | 10.0 | 10 | cyber attack, Cyber Espionage, Cyber Attack |
| 35 | Unsecured Laptop | critical | 10.0 | 9 | Data Breach |
| 36 | Compromised credentials | critical | 10.0 | 9 | Quantum Computing Threat, Data Breach, Extortion, Source Code Theft |
| 37 | lack of access controls | critical | 10.0 | 9 | data breach, data exposure, Data Breach |
| 38 | MOVEit Transfer application vulnerability | critical | 8.5 | 9 | Data Breach |
| 39 | Unknown | critical | 10.0 | 8 | Malware, Cyberattack, Data Breach |
| 40 | Phishing | critical | 10.0 | 8 | Authentication Security Improvement, Data Theft, Phishing |
| 41 | Unencrypted Laptop | critical | 10.0 | 8 | Data Breach |
| 42 | Unprotected Database | critical | 10.0 | 8 | Data Exposure, Data Breach, Data Leak |
| 43 | Weak Password Policies | critical | 10.0 | 8 | Account Takeover (ATO), unauthorized access, DDoS Attack |
| 44 | Outdated software | critical | 10.0 | 8 | phishing, Espionage, Ransomware |
| 45 | MOVEit Transfer software vulnerability | critical | 8.5 | 8 | Data Breach |
| 46 | Unencrypted Data Storage | critical | 8.5 | 8 | Data Breach, Data Security Incident |
| 47 | Inadequately secured network | critical | 10.0 | 7 | Data Breach |
| 48 | Zero-day vulnerability | critical | 10.0 | 7 | Ransomware Attack, Cyber Attack, Data Breach |
| 49 | Lack of MFA | critical | 10.0 | 7 | Social Engineering, Data Breach, Ransomware |
| 50 | CVE-2025-55182 (React2Shell) | critical | 10.0 | 7 | Exploit Trends, Vulnerability Exploitation, Ransomware |
| 51 | MOVEit file transfer software | critical | 10.0 | 7 | Ransomware Attack, Data Breach, Ransomware |
| 52 | Unpatched vulnerability | critical | 10.0 | 7 | Ransomware, Ransomware Attack, Data Breach |
| 53 | Insufficient access controls | critical | 10.0 | 7 | Supply Chain Attack, data breach, Unauthorized Access |
| 54 | Weak authentication | critical | 10.0 | 7 | Cyber Breach, Cyber Espionage, Ransomware |
| 55 | Inadequate Access Controls | critical | 10.0 | 7 | unauthorized access, Data Breach Risk, Ransomware Attack |
| 56 | Lack of Network Segmentation | critical | 10.0 | 7 | Cyber Espionage, Cyber-Physical Attack, phishing |
| 57 | Email Compromise | critical | 8.5 | 7 | Data Breach |
| 58 | MOVEit Transfer software | critical | 8.5 | 7 | Data Breach |
| 59 | Configuration Error | critical | 8.5 | 7 | Data Breach, Data Leak |
| 60 | MOVEit Transfer application | critical | 10.0 | 6 | Data Breach |
| 61 | CVE-2024-57726 | critical | 10.0 | 6 | ransomware, Supply-Chain Attack, Ransomware |
| 62 | CVE-2024-57728 | critical | 10.0 | 6 | Ransomware, Supply-Chain Attack, ransomware |
| 63 | MOVEit file transfer software vulnerability | critical | 10.0 | 6 | Cyber Attack, Data Breach, Ransomware |
| 64 | CVE-2025-47812 | critical | 10.0 | 6 | Remote Code Execution, Remote Code Execution (RCE), Vulnerability Exploitation |
| 65 | Weak OAuth Token Security | critical | 10.0 | 6 | Supply Chain Attack, Data Breach |
| 66 | Software Vulnerability | critical | 10.0 | 6 | Cyber Attack, Data Breach |
| 67 | Lack of Multi-Factor Authentication (MFA) Enforcement | critical | 10.0 | 6 | phishing, Account Takeover (ATO), Phishing |
| 68 | Zero-day vulnerabilities | critical | 10.0 | 6 | Cyber Breach, Cyber Espionage, Data Theft |
| 69 | Human Factor | critical | 10.0 | 6 | Phishing Attack, Data Breach, Social Engineering, Ransomware |
| 70 | Lack of Multifactor Authentication (MFA) | critical | 10.0 | 6 | cyberespionage, Ransomware, Unauthorized Access |
| 71 | legacy systems | critical | 10.0 | 6 | Ransomware, Cyberattack, Data Breach |
| 72 | unpatched software | critical | 10.0 | 6 | general cybersecurity awareness, Ransomware, ransomware |
| 73 | Password Reuse | critical | 8.5 | 6 | Password Reuse Attack, Credential Leak, Credential Theft |
| 74 | MOVEit Transfer | critical | 8.5 | 6 | Cyber Attack, Data Breach |
| 75 | Weak or Reused Passwords | critical | 8.5 | 6 | Credential-Stuffing Attack, Data Breach, Account Compromise |
| 76 | Unauthorized Data Transfer | critical | 8.0 | 6 | Data Breach |
| 77 | CVE-2025-11953 | critical | 10.0 | 5 | OS Command Injection, Botnet Infection, Remote Code Execution (RCE) |
| 78 | React2Shell | critical | 10.0 | 5 | Ransomware, Data Breach, Malware Campaign |
| 79 | CVE-2025-61882 (Oracle E-Business Suite) | critical | 10.0 | 5 | Cybercriminal Alliance Formation, Data Breach, Ransomware, Data Breach |
| 80 | CVE-2023-27532 | critical | 10.0 | 5 | Ransomware Attack, Ransomware, Cyber Intrusion |
| 81 | Human Error (Phishing) | critical | 10.0 | 5 | Data Breach, Targeted Cyberattack, Targeted Attack |
| 82 | CVE-2025-61882 | critical | 10.0 | 5 | Cyberattack, Data Breach, ransomware |
| 83 | CVE-2023-34362 | critical | 10.0 | 5 | Data Breach and Ransomware Attack, Data Breach, Ransomware |
| 84 | Insecure Direct Object Reference (IDOR) | critical | 10.0 | 5 | unauthorized access, Data Breach, API Vulnerability |
| 85 | Online Payment System | critical | 10.0 | 5 | Data Breach |
| 86 | Default credentials | critical | 10.0 | 5 | DDoS Attack, Data Breach, Cyber Espionage |
| 87 | Unsecured cloud storage | critical | 10.0 | 5 | Data Exposure, Data Breach, data breach |
| 88 | Human Vulnerability | critical | 10.0 | 5 | Sex Trafficking and Deepfake Pornography, Phishing, Data Breach |
| 89 | MOVEit Transfer programme | critical | 8.5 | 5 | Data Breach |
| 90 | Lack of Encryption | critical | 8.5 | 5 | Data Breach |
| 91 | Lack of Authentication | critical | 8.5 | 5 | Data Exposure, Data Leak |
| 92 | Human (Employee Email Compromise) | critical | 8.5 | 5 | Data Breach |
| 93 | Inadequate data protection measures | critical | 8.5 | 5 | Data Breach |
| 94 | Lack of encryption and password protection | critical | 8.5 | 5 | Data Exposure, Data Breach, data breach |
| 95 | Email Phishing Scam | high | 6.0 | 5 | Data Breach |
| 96 | Email Phishing | high | 6.0 | 5 | Data Breach |
| 97 | CVE-2025-53770 | critical | 10.0 | 4 | Ransomware Attack, Cyberattack, Ransomware |
| 98 | Third-party software vulnerability | critical | 10.0 | 4 | Ransomware Attack, Data Breach |
| 99 | Inadequately secured systems | critical | 10.0 | 4 | Data Breach |
| 100 | SonicWall firewall vulnerability | critical | 10.0 | 4 | Data Breach, Ransomware |
| 101 | MOVEit | critical | 10.0 | 4 | Data Breach, Ransomware |
| 102 | Web Application Vulnerability | critical | 10.0 | 4 | Cyber Attack, Data Breach |
| 103 | Security breach on a third-party vendor | critical | 10.0 | 4 | Data Breach |
| 104 | Weak or Compromised Credentials | critical | 10.0 | 4 | Cyberattack, Data Breach |
| 105 | Internal Access | critical | 10.0 | 4 | Data Breach, Data Theft |
| 106 | Cloudbleed | critical | 10.0 | 4 | Data Breach |
| 107 | MOVEit Transfer tool | critical | 10.0 | 4 | Data Breach |
| 108 | Unknown vulnerability | critical | 10.0 | 4 | Ransomware Attack, Data Breach, Data Breach, Ransomware |
| 109 | CVE-2025-49704 | critical | 10.0 | 4 | Cyberattack, Cyber Espionage, Ransomware |
| 110 | human trust | critical | 10.0 | 4 | social engineering, fraud, phishing |
| 111 | CVE-2024-40711 | critical | 10.0 | 4 | ransomware, Vulnerability, Ransomware |
| 112 | Zero-day vulnerability in MOVEit Transfer programme | critical | 10.0 | 4 | Data Breach |
| 113 | CVE-2025-49706 | critical | 10.0 | 4 | Cyberattack, Cyber Espionage, Ransomware |
| 114 | Insufficient Employee Training | critical | 10.0 | 4 | Cyber Attack, Data Breach Risk, Data Breach |
| 115 | Network Vulnerability | critical | 10.0 | 4 | Ransomware Attack, Data Breach |
| 116 | MOVEit file transfer software vulnerabilities | critical | 10.0 | 4 | Ransomware Attack, Data Breach, Unauthorized Access, Data Breach |
| 117 | Publicly Accessible Server | critical | 10.0 | 4 | Data Exposure, data exposure, Data Breach |
| 118 | Employee credentials | critical | 10.0 | 4 | Data Breach, Data Breach, Phishing, Phishing Attack |
| 119 | Lack of multi-factor authentication | critical | 10.0 | 4 | general cybersecurity awareness, Data Breach, credential theft |
| 120 | Weak Identity Controls | critical | 10.0 | 4 | EDR/XDR Evasion, Data Exfiltration, Data Breach |
| 121 | Weak Credential Management | critical | 10.0 | 4 | Data Breach, credential theft |
| 122 | Cloud misconfiguration | critical | 10.0 | 4 | Cyber-Attack, Data Breach, Cloud Misconfiguration Exploitation |
| 123 | Third-party risks | critical | 10.0 | 4 | Data Breach, credential theft, AI-driven vulnerability exploitation |
| 124 | Weak email security | critical | 10.0 | 4 | Cyberattack, Data Breach, defacement |
| 125 | Point-of-Sale System | critical | 10.0 | 4 | Data Breach |
| 126 | Inadequate employee training | critical | 10.0 | 4 | phishing, Data Breach, Data Leakage |
| 127 | Reused Passwords | critical | 10.0 | 4 | data breach (unverified), Data Breach, Account Compromise |
| 128 | Coding Error | critical | 8.5 | 4 | Data Breach |
| 129 | MOVEit Transfer vulnerability | critical | 8.5 | 4 | Data Breach |
| 130 | Unauthorized Access by Former Employee | critical | 8.5 | 4 | Data Breach |
| 131 | Compromised login credentials | critical | 8.5 | 4 | Data Breach |
| 132 | Unsecured Server | critical | 8.5 | 4 | Data Breach, Data Leak |
| 133 | Compromised Employee Email Account | critical | 8.5 | 4 | Data Breach |
| 134 | Lack of two-factor authentication | critical | 8.5 | 4 | Cyber Attack, Data Breach |
| 135 | Publicly accessible database | critical | 8.5 | 4 | Data Exposure, Data Breach, Data Leak |
| 136 | Weak or Reused Credentials | critical | 10.0 | 3 | Unauthorized Access, Data Breach |
| 137 | CVE-2026-23760 | critical | 10.0 | 3 | Ransomware Attack, Remote Code Execution (RCE), Ransomware |
| 138 | Excessive Permissions | critical | 10.0 | 3 | Data Breach, Malware Infiltration |
| 139 | CVE-2024-7029 | critical | 10.0 | 3 | Malware, Botnet |
| 140 | CVE-2023-27351 (PaperCut) | critical | 10.0 | 3 | ransomware, Ransomware |
| 141 | Lack of Role-Based Access Control (RBAC) | critical | 10.0 | 3 | Data Breach Risk, Data Breach |
| 142 | CVE-2021-36942 (PetitPotam) | critical | 10.0 | 3 | Cyber Espionage |
| 143 | Supply chain vulnerabilities | critical | 10.0 | 3 | Data Breach, Ransomware |
| 144 | CVE-2025-5777 | critical | 10.0 | 3 | ransomware, Vulnerability Exploitation, Ransomware |
| 145 | Weak Password Security | critical | 10.0 | 3 | Data Breach |
| 146 | External System Breach | critical | 10.0 | 3 | Data Breach |
| 147 | CVE-2025-53521 | critical | 10.0 | 3 | Vulnerability Exploitation, Remote Code Execution (RCE) |
| 148 | CVE-2017-11882 | critical | 10.0 | 3 | cyber espionage, Cyber Espionage |
| 149 | CVE-2026-31431 (Copy Fail) | critical | 10.0 | 3 | Privilege Escalation |
| 150 | null | critical | 10.0 | 3 | DDoS, Data Breach and Ransomware, Data Breach |
| 151 | Lack of Oversight | critical | 10.0 | 3 | Data Breach (Alleged), Data Breach, Unauthorized Disclosure |
| 152 | Stolen Employee Credentials | critical | 10.0 | 3 | Data Breach |
| 153 | Zero-day vulnerability in Oracle’s E-Business Suite | critical | 10.0 | 3 | Data Breach, Ransomware |
| 154 | SQL Injection Flaws | critical | 10.0 | 3 | Data Breach |
| 155 | Unauthorized Access to Sensitive Data | critical | 10.0 | 3 | Data Breach, Extortion |
| 156 | Weak Authentication System | critical | 10.0 | 3 | Data Breach |
| 157 | Lack of Data Encryption | critical | 10.0 | 3 | Data Breach |
| 158 | CVE-2026-21509 | critical | 10.0 | 3 | Zero-Day Vulnerability, Zero-day exploitation |
| 159 | CVE-2024-40766 | critical | 10.0 | 3 | Ransomware |
| 160 | CVE-2025-53771 | critical | 10.0 | 3 | Ransomware Attack, Ransomware |
| 161 | Microsoft Exchange Server | critical | 10.0 | 3 | Security Breach, Cyber Espionage, Ransomware |
| 162 | CVE-2026-20963 | critical | 10.0 | 3 | Cyberespionage, Vulnerability Exploitation, Remote Code Execution (RCE) |
| 163 | React2Shell vulnerability | critical | 10.0 | 3 | Data Breach, Ransomware |
| 164 | CVE-2025-5777 (Citrix Bleed 2) | critical | 10.0 | 3 | Ransomware |
| 165 | Weak/Stolen Credentials | critical | 10.0 | 3 | Data Breach |
| 166 | weak endpoint security | critical | 10.0 | 3 | data breach, Data Breach, ransomware |
| 167 | Default passwords | critical | 10.0 | 3 | Exposure of Critical Infrastructure, espionage, Data Exposure |
| 168 | Sandbox escape | critical | 10.0 | 3 | Exploit Kit, Exploit Kit / Cyber Espionage, Espionage |
| 169 | outdated systems | critical | 10.0 | 3 | data breach, Ransomware, ransomware |
| 170 | credential harvesting | critical | 10.0 | 3 | Phishing-as-a-Service (PhaaS), wire fraud, ransomware |
| 171 | Third-Party Integration Risks | critical | 10.0 | 3 | Supply Chain Attack, Data Breach, third-party breach |
| 172 | Improper Email Handling | critical | 10.0 | 3 | Data Breach |
| 173 | Zero-Day Exploit | critical | 10.0 | 3 | Data Breach, Ransomware, Compliance Failure |
| 174 | Lack of cybersecurity expertise | critical | 10.0 | 3 | Data Breach, ransomware |
| 175 | Poor network segmentation | critical | 10.0 | 3 | cyber attack, Ransomware |
| 176 | Misconfigured Amazon S3 bucket | critical | 9.0 | 3 | Data Breach |
| 177 | Security Vulnerability | critical | 8.5 | 3 | Data Breach |
| 178 | Physical Theft | critical | 8.5 | 3 | Data Breach |
| 179 | MOVEit Transfer solution | critical | 8.5 | 3 | Data Breach |
| 180 | MOVEit Transfer server | critical | 8.5 | 3 | Data Breach |
| 181 | Point of Sale Systems | critical | 8.5 | 3 | Data Breach |
| 182 | human trust (social engineering) | critical | 8.5 | 3 | phishing, cyber theft, Malware |
| 183 | Third-party service provider | critical | 8.5 | 3 | Data Breach |
| 184 | Server Misconfiguration | critical | 8.5 | 3 | Data Breach, Botnet |
| 185 | MOVEit file transfer application | critical | 8.5 | 3 | Data Breach |
| 186 | Weak security controls | critical | 8.5 | 3 | Data Breach, Ransomware |
| 187 | Third-party vendor vulnerability | critical | 8.5 | 3 | Data Breach |
| 188 | Payment Processing System | critical | 8.5 | 3 | Data Breach |
| 189 | Email Misconfiguration | high | 6.0 | 3 | Data Breach |
| 190 | Unauthorized Data Access | high | 6.0 | 3 | Data Exfiltration, Data Breach |
| 191 | Weak or Stolen Password | high | 6.0 | 3 | Data Breach (Unauthorized Access), Data Breach, Authentication Security Improvement |
| 192 | Insider Access | low | 0.0 | 3 | Data Breach, Insider Threat |
| 193 | Cross-Site Scripting (XSS) | critical | 10.0 | 2 | Vulnerability |
| 194 | Old vulnerabilities | critical | 10.0 | 2 | Spyware, Data Theft |
| 195 | Unpatched IoT Devices | critical | 10.0 | 2 | Data Breach, Distributed Denial-of-Service (DDoS) Attack |
| 196 | CVE-2025-48827 | critical | 10.0 | 2 | Remote Code Execution, Vulnerability Exploitation |
| 197 | Outdated infrastructure | critical | 10.0 | 2 | GPS spoofing, Ransomware |
| 198 | CVE-2026-23760 (SmarterMail) | critical | 10.0 | 2 | ransomware, Ransomware |
| 199 | CVE-2017-17215 | critical | 10.0 | 2 | Malware, Botnet |
| 200 | MOVEit Transfer software zero-day vulnerability | critical | 10.0 | 2 | Data Breach |
| 201 | Unauthorized access to an employee’s email account | critical | 10.0 | 2 | Data Breach |
| 202 | CVE-2025-53770 (ToolShell) | critical | 10.0 | 2 | Cyber Espionage |
| 203 | CVE-2025-8088 | critical | 10.0 | 2 | Zero-day exploitation, Phishing, Malware installation, Cyberespionage |
| 204 | MFA bypass | critical | 10.0 | 2 | ransomware, Phishing-as-a-Service (PhaaS) |
| 205 | CVE-2023-3519 (Citrix NetScaler) | critical | 10.0 | 2 | cyberespionage, Ransomware |
| 206 | Weak OAuth Token Management | critical | 10.0 | 2 | Data Breach |
| 207 | Leaked credentials | critical | 10.0 | 2 | Phishing, Cloud Misconfiguration Exploitation |
| 208 | Network infrastructure | critical | 10.0 | 2 | Data Breach, Cyber Sabotage |
| 209 | CVE-2025-55182 | critical | 10.0 | 2 | Supply Chain Attack, Remote Code Execution (RCE) |
| 210 | Inadequate cybersecurity measures | critical | 10.0 | 2 | Data Breach |
| 211 | Phished login credentials | critical | 10.0 | 2 | Hack, Cyber Attack |
| 212 | CVE-2025-54309 | critical | 10.0 | 2 | Zero-Day Exploitation, Zero-Day Vulnerability |
| 213 | Oracle eBusiness Suite security flaw | critical | 10.0 | 2 | Data Breach |
| 214 | CVE-2025-20362 | critical | 10.0 | 2 | Vulnerability Exploitation, Data Breach, Persistent Malware, Unauthorized Access |
| 215 | CVE-2017-0199 | critical | 10.0 | 2 | cyber espionage, Cyber Espionage |
| 216 | CVE-2021-44026 | critical | 10.0 | 2 | Data Breach, Cyberespionage |
| 217 | Improper Credential Management | critical | 10.0 | 2 | Supply Chain Attack, Credential Exposure |
| 218 | WordPress vulnerabilities | critical | 10.0 | 2 | Website Defacement, Botnet |
| 219 | CVE-2023-27350 (PaperCut) | critical | 10.0 | 2 | ransomware, Ransomware |
| 220 | Email System | critical | 10.0 | 2 | Data Breach |
| 221 | Infostealer Malware | critical | 10.0 | 2 | Data Breach |
| 222 | CI/CD pipeline compromise | critical | 10.0 | 2 | Supply Chain Attack, supply chain attack |
| 223 | Poor Data Governance | critical | 10.0 | 2 | Data Breach |
| 224 | Microsoft Exchange Server vulnerabilities (HAFNIUM campaign) | critical | 10.0 | 2 | Cyber Espionage |
| 225 | CVE-2026-4480 | critical | 10.0 | 2 | Vulnerability Exploitation, Remote Code Execution (RCE) |
| 226 | Unencrypted, non-password-protected database | critical | 10.0 | 2 | Data Leak |
| 227 | CVE-2024-55956 | critical | 10.0 | 2 | Data Breach, Ransomware |
| 228 | CVE-2024-55591 | critical | 10.0 | 2 | Cyber-Attack, Ransomware |
| 229 | lack of user awareness | critical | 10.0 | 2 | phishing, social engineering |
| 230 | CVE-2026-34980 | critical | 10.0 | 2 | Zero-Day Vulnerability, Vulnerability Exploitation |
| 231 | CVE-unknown (MOVEit Transfer zero-day) | critical | 10.0 | 2 | Data Breach, ransomware |
| 232 | CVE-2024-27198 (JetBrains TeamCity) | critical | 10.0 | 2 | Ransomware, ransomware |
| 233 | CVE-2024-1086 | critical | 10.0 | 2 | vulnerability exploitation, Privilege Escalation |
| 234 | CVE-2023-4966 | critical | 10.0 | 2 | Vulnerability Exploitation, Ransomware |
| 235 | CVE-2025-33053 | critical | 10.0 | 2 | Remote Code Execution, Advanced Persistent Threat (APT) |
| 236 | Lack of Multi-Factor Authentication (MFA) (implied) | critical | 10.0 | 2 | Ransomware Attack, Phishing |
| 237 | Email System Vulnerability | critical | 10.0 | 2 | Data Breach |
| 238 | Remote code execution | critical | 10.0 | 2 | Espionage, Data Privacy and Cybersecurity Advisory |
| 239 | Arbitrary Code Execution | critical | 10.0 | 2 | Misconfiguration, Vulnerability Exploitation |
| 240 | Cleo file transfer software | critical | 10.0 | 2 | Ransomware |
| 241 | CVE-2024-50623 | critical | 10.0 | 2 | Data Breach, Ransomware |
| 242 | CVE-2025-33073 | critical | 10.0 | 2 | Ransomware, Privilege Escalation |
| 243 | CVE-2025-7775 (Citrix NetScaler) | critical | 10.0 | 2 | Ransomware |
| 244 | Known vulnerability not patched in time | critical | 10.0 | 2 | Data Breach, Ransomware |
| 245 | CVE-2023-21529 (Microsoft Exchange) | critical | 10.0 | 2 | ransomware, Ransomware |
| 246 | EternalBlue | critical | 10.0 | 2 | Ransomware |
| 247 | CVE-2025-3248 | critical | 10.0 | 2 | Remote Code Execution, Vulnerability Exploitation |
| 248 | Citrix Vulnerability | critical | 10.0 | 2 | Cyberattack |
| 249 | Code Vulnerability | critical | 10.0 | 2 | Data Breach |
| 250 | Weak Password Management | critical | 10.0 | 2 | Data Breach, Malware Infection |
| 251 | CVE-2024-21887 | critical | 10.0 | 2 | Zero-Day Exploit, Ransomware |
| 252 | CVE-2026-0920 | critical | 10.0 | 2 | Backdoor |
| 253 | CVE-2025-48828 | critical | 10.0 | 2 | Remote Code Execution, Vulnerability Exploitation |
| 254 | CVE-2024-36401 | critical | 10.0 | 2 | Malware Distribution and Data Exfiltration, Exploitation of Vulnerability |
| 255 | Lack of Employee Awareness | critical | 10.0 | 2 | Data Breach, Human Error |
| 256 | Human (Help Desk Personnel) | critical | 10.0 | 2 | Ransomware and Data Breach, Ransomware and Data Theft |
| 257 | CVE-2008-4128 | critical | 10.0 | 2 | Cross-Site Request Forgery (CSRF), Ransomware |
| 258 | CVE-2026-24291 (RegPwn) | critical | 10.0 | 2 | Privilege Escalation |
| 259 | human vulnerability (social engineering) | critical | 10.0 | 2 | phishing, data breach |
| 260 | Known vulnerability that had not been patched | critical | 10.0 | 2 | Data Breach, Ransomware |
| 261 | CVE-2025-8110 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 262 | inadequate network segmentation | critical | 10.0 | 2 | ransomware |
| 263 | Lack of Encryption (Data at Rest/In Transit) | critical | 10.0 | 2 | Data Breach (General Discussion), Data Breach |
| 264 | Zero-day vulnerability in Oracle PeopleSoft | critical | 10.0 | 2 | Data Breach, Data Breach, Extortion |
| 265 | Known software vulnerabilities | critical | 10.0 | 2 | Cyber Espionage, Sabotage, Vulnerability Exploitation |
| 266 | Oracle eBusiness Suite vulnerability | critical | 10.0 | 2 | Data Breach |
| 267 | Improper security configuration | critical | 10.0 | 2 | Data Breach |
| 268 | Default or Weak Credentials | critical | 10.0 | 2 | Cyberattack, Cloud Security Breach |
| 269 | Human vulnerability through impersonation | critical | 10.0 | 2 | Data Breach, Social Engineering Attack |
| 270 | Internal Account Compromise | critical | 10.0 | 2 | Data Breach |
| 271 | MOVEit Transfer zero-day vulnerability | critical | 10.0 | 2 | Data Breach |
| 272 | CVE-2025-59528 | critical | 10.0 | 2 | Code Injection, Remote Code Execution (RCE) |
| 273 | CVE-2025-4322 | critical | 10.0 | 2 | Privilege Escalation |
| 274 | CVE-2026-42271 | critical | 10.0 | 2 | Command Injection, Remote Code Execution (RCE) |
| 275 | Oracle EBS vulnerability | critical | 10.0 | 2 | Data Breach |
| 276 | CVE-2025-49113 | critical | 10.0 | 2 | Remote Code Execution (RCE) |
| 277 | CVE-2025-6543 | critical | 10.0 | 2 | Cyber Attack, Zero-day exploitation |
| 278 | CVE-2024-21412 | critical | 10.0 | 2 | Cyberattack, Ransomware |
| 279 | SonicWall firewall | critical | 10.0 | 2 | Ransomware Attack, Data Breach |
| 280 | Signature-Based Detection Gaps | critical | 10.0 | 2 | Supply Chain Attack, Operational Risk |
| 281 | CVE-2024-1708 (ConnectWise ScreenConnect) | critical | 10.0 | 2 | ransomware, Ransomware |
| 282 | CVE-2026-20131 (Cisco Secure Firewall Management Center) | critical | 10.0 | 2 | Ransomware, ransomware |
| 283 | API vulnerabilities | critical | 10.0 | 2 | Quantum Computing Threat, Data Breach |
| 284 | Human vulnerability through phishing | critical | 10.0 | 2 | Phishing, Ransomware |
| 285 | CVE-2026-20253 | critical | 10.0 | 2 | Data Breach, Vulnerability Exploitation |
| 286 | CVE-2026-22678 | critical | 10.0 | 2 | Stored Cross-Site Scripting (XSS), XSS |
| 287 | Non-password protected database | critical | 10.0 | 2 | Data Breach |
| 288 | CVE-2026-34990 | critical | 10.0 | 2 | Zero-Day Vulnerability, Vulnerability Exploitation |
| 289 | CVE-2025-1268 | critical | 10.0 | 2 | Vulnerability, Vulnerability and Potential Breach |
| 290 | CVE-2026-48710 | critical | 10.0 | 2 | Command Injection, Remote Code Execution (RCE) |
| 291 | CVE-2024-1709 (ConnectWise ScreenConnect) | critical | 10.0 | 2 | Ransomware, ransomware |
| 292 | CVE-2018-0171 | critical | 10.0 | 2 | Vulnerability Exploitation, Ransomware |
| 293 | Weak SSH credentials | critical | 10.0 | 2 | DDoS, DDoS Attack |
| 294 | CVE-2024-9680 | critical | 10.0 | 2 | Zero-Day Exploit, Cyber Espionage |
| 295 | CVE-2024-49039 | critical | 10.0 | 2 | Zero-Day Exploit, Cyber Espionage |
| 296 | Unattended Devices | critical | 10.0 | 2 | Insider Threat, Awareness Campaign |
| 297 | Legacy IT Systems | critical | 10.0 | 2 | Ransomware Attack, Cyber Attack |
| 298 | Zero-day vulnerability in SonicWall SSL VPN | critical | 10.0 | 2 | Ransomware |
| 299 | SQL injection vulnerability in MOVEit Transfer | critical | 10.0 | 2 | Ransomware |
| 300 | Brute force attacks | critical | 10.0 | 2 | Authentication Security Improvement, Extortion / Data Leak Threat |
| 301 | Privilege escalation | critical | 10.0 | 2 | Vulnerability Exploitation, Ransomware |
| 302 | Social Engineering / Phishing | critical | 10.0 | 2 | Spear Phishing, Business Email Compromise (BEC) |
| 303 | Remote access vulnerabilities | critical | 10.0 | 2 | ransomware, Ransomware |
| 304 | Lack of Multifactor Authentication | critical | 10.0 | 2 | Supply Chain Breach, Awareness Campaign |
| 305 | weak authentication mechanisms | critical | 10.0 | 2 | Data Breach, cybercrime |
| 306 | network vulnerabilities | critical | 10.0 | 2 | Ransomware, ransomware |
| 307 | lack of signal authentication | critical | 10.0 | 2 | spoofing, Data Interception |
| 308 | Compromised Vendor Credentials | critical | 10.0 | 2 | Phishing, Malware Distribution, Data Breach |
| 309 | Delayed Patch Management | critical | 10.0 | 2 | Data Breach, Ransomware |
| 310 | Misconfigured access controls | critical | 10.0 | 2 | Data Breach, Data Privacy and Cybersecurity Advisory |
| 311 | Microsoft Exchange server vulnerabilities | critical | 10.0 | 2 | Vulnerability Exploitation, Ransomware |
| 312 | Fortinet vulnerabilities | critical | 10.0 | 2 | Vulnerability Exploitation, Ransomware |
| 313 | Misconfigured MongoDB database | critical | 10.0 | 2 | Data Exposure, Data Breach |
| 314 | Legacy Infrastructure | critical | 10.0 | 2 | AI-Powered Cyberattack, Ransomware |
| 315 | poor security practices | critical | 10.0 | 2 | Data Breach, espionage |
| 316 | Citrix NetScaler ADC/Gateway vulnerabilities | critical | 10.0 | 2 | Vulnerability Exploitation, Ransomware |
| 317 | Misconfigured deployments | critical | 10.0 | 2 | Misconfiguration, Ransomware |
| 318 | CVE-2025-61884 (Oracle E-Business Suite Zero-Day) | critical | 10.0 | 2 | data breach, Data Breach |
| 319 | ATM Network Processing | critical | 10.0 | 2 | Data Breach |
| 320 | Online Payment System Vulnerability | critical | 10.0 | 2 | Data Breach |
| 321 | Misconfigured cloud storage | critical | 10.0 | 2 | Data Breach |
| 322 | lack of employee training | critical | 10.0 | 2 | phishing, Ransomware |
| 323 | Public-Facing Application Vulnerabilities | critical | 10.0 | 2 | Data Breach, ransomware |
| 324 | Phishing Email | critical | 10.0 | 2 | Data Breach |
| 325 | Cloud Storage Service Vulnerability | critical | 10.0 | 2 | Data Breach |
| 326 | Lack of phishing-resistant MFA | critical | 10.0 | 2 | Data Breach, Extortion |
| 327 | Lack of Package Integrity Verification | critical | 10.0 | 2 | Supply Chain Attack, supply-chain attack |
| 328 | weak identity management | critical | 10.0 | 2 | Data Breach, identity-related breach |
| 329 | Known vulnerability | critical | 10.0 | 2 | Ransomware Attack, Data Leak |
| 330 | Outdated operating systems | critical | 10.0 | 2 | data breach, Cyberattack |
| 331 | unknown security gap | critical | 10.0 | 2 | ransomware |
| 332 | Human error (social engineering susceptibility) | critical | 10.0 | 2 | Data Breach, Ransomware |
| 333 | lack_of_MFA | critical | 10.0 | 2 | ransomware, data_breach |
| 334 | Remote code execution vulnerability | critical | 10.0 | 2 | Remote Code Execution, Remote Code Execution (RCE) |
| 335 | weak MFA | critical | 10.0 | 2 | Data Breach, data_breach |
| 336 | Hardcoded credentials | critical | 10.0 | 2 | Cyber Attack, Misconfiguration |
| 337 | Misconfigured system | critical | 10.0 | 2 | Alleged Data Breach, Data Breach |
| 338 | System Misconfiguration | critical | 10.0 | 2 | Data Breach, AI-driven cyberattack |
| 339 | User Trust in App Store | critical | 10.0 | 2 | Malware |
| 340 | poor password hygiene | critical | 10.0 | 2 | Human Error, ransomware |
| 341 | Oracle E-Business Suite software vulnerability | critical | 8.5 | 2 | Data Breach |
| 342 | Poor data visibility settings | critical | 8.5 | 2 | Data Exposure |
| 343 | Social Engineering, Trust Exploitation | critical | 8.5 | 2 | Phishing |
| 344 | Software Coding Issue | critical | 8.5 | 2 | Data Breach |
| 345 | CVE-2025-47813 | critical | 8.5 | 2 | Vulnerability Exploitation, Information Disclosure, Remote Code Execution |
| 346 | CVE-2026-39813 | critical | 8.5 | 2 | Data Breach, OS command injection |
| 347 | CVE-2026-26110 (Type Confusion - CWE-843) | critical | 8.5 | 2 | Vulnerability, Remote Code Execution (RCE) |
| 348 | Okta SSO Credentials | critical | 8.5 | 2 | Data Breach |
| 349 | Lack of Identity Verification | critical | 8.5 | 2 | Data Breach, Fraud |
| 350 | Access Control | critical | 8.5 | 2 | Data Breach |
| 351 | CVE-2025-41244 | critical | 8.5 | 2 | Privilege Escalation |
| 352 | CVE-2026-21510 | critical | 8.5 | 2 | Zero-Day Vulnerability |
| 353 | CVE-2026-8925 | critical | 8.5 | 2 | Vulnerability Disclosure, Vulnerability Exploitation |
| 354 | Unsecured MongoDB Database | critical | 8.5 | 2 | Data Breach |
| 355 | CVE-2026-12957 | critical | 8.5 | 2 | Supply Chain Attack, Arbitrary Code Execution |
| 356 | Critical security flaw in License Express system | critical | 8.5 | 2 | Data Security Failure, Data Breach |
| 357 | Code Injection | critical | 8.5 | 2 | Data Breach |
| 358 | Misconfigured Elasticsearch Database | critical | 8.5 | 2 | Data Exposure, Data Leak |
| 359 | CVE-2026-9547 | critical | 8.5 | 2 | Vulnerability Disclosure, Vulnerability Exploitation |
| 360 | CVE-2026-12958 | critical | 8.5 | 2 | Supply Chain Attack, Arbitrary Code Execution |
| 361 | inadequate vendor oversight | critical | 8.5 | 2 | data breach, ransomware |
| 362 | Incorrect privacy settings on a public mapping website | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 363 | CVE-2026-22218 | critical | 8.5 | 2 | Data Breach, Vulnerability Exploitation |
| 364 | CVE-2026-3909 | critical | 8.5 | 2 | Zero-day Exploitation, Zero-Day Vulnerability Exploitation |
| 365 | MOVEit web transfer application vulnerability | critical | 8.5 | 2 | Data Breach |
| 366 | CVE-2026-34621 (Adobe Acrobat Reader) | critical | 8.5 | 2 | Data Breach, Vulnerability Exploitation |
| 367 | CVE-2025-54309 (CrushFTP) | critical | 8.5 | 2 | Exploit Trends, Ransomware |
| 368 | Insufficient Multi-Factor Authentication (MFA) | critical | 8.5 | 2 | Data Breach |
| 369 | CVE-2026-2413 | critical | 8.5 | 2 | SQL Injection |
| 370 | HTML rendering race condition | critical | 8.5 | 2 | Data Exfiltration, Vulnerability Exploitation |
| 371 | Overprivileged Access | critical | 8.5 | 2 | Data Breach |
| 372 | missing authentication | critical | 8.5 | 2 | data breach |
| 373 | CVE-2026-3910 | critical | 8.5 | 2 | Zero-day Exploitation, Zero-Day Vulnerability Exploitation |
| 374 | CVE-2026-23795 | critical | 8.5 | 2 | Supply Chain Attack, XXE (XML External Entity) Vulnerability |
| 375 | Inadvertent Disclosure | critical | 8.5 | 2 | Data Breach |
| 376 | Progress Software's MOVEit Transfer software | critical | 8.5 | 2 | Data Breach |
| 377 | Compromised User Account | critical | 8.5 | 2 | Data Breach |
| 378 | Unprotected Server | critical | 8.5 | 2 | Data Breach |
| 379 | CVE-2025-66376 | critical | 8.5 | 2 | Cyberespionage, Phishing, Espionage |
| 380 | CVE-2026-20262 | critical | 8.5 | 2 | Zero-Day Exploitation, Data Breach |
| 381 | System Configuration Error | critical | 8.5 | 2 | Data Breach |
| 382 | Information Disclosure | critical | 8.5 | 2 | Data Breach, Data Leak |
| 383 | Broken Access Control | critical | 8.5 | 2 | API Vulnerability, Vulnerability Exploitation |
| 384 | CVE-2026-32201 (Improper Input Validation - CWE-20) | critical | 8.5 | 2 | Zero-Day Exploitation, Zero-Day Vulnerability |
| 385 | Inadequate Vendor Vetting | critical | 8.5 | 2 | Data Breach |
| 386 | Unpatched network devices | critical | 8.5 | 2 | DDoS, Malware |
| 387 | Insufficient security measures | critical | 8.5 | 2 | Data Breach |
| 388 | Weak email account security | critical | 8.5 | 2 | Data Breach |
| 389 | Human Error (Falling for Phishing Scam) | critical | 8.5 | 2 | Data Breach, Data Breach (Phishing) |
| 390 | CVE-2026-22219 | critical | 8.5 | 2 | Data Breach, Vulnerability Exploitation |
| 391 | CVE-2025-55177 (WhatsApp incomplete authorization) | critical | 8.5 | 2 | Zero-day exploit, Zero-day vulnerability |
| 392 | Compromised employee account | critical | 8.5 | 2 | Data Breach |
| 393 | Oracle PeopleSoft vulnerability | critical | 8.5 | 2 | Data Breach, Ransomware |
| 394 | MOVEit Transfer (CVE-2023-34362 or related) | critical | 8.5 | 2 | Data Breach |
| 395 | CVE-2026-39808 | critical | 8.5 | 2 | Data Breach, OS command injection |
| 396 | Parameter-to-prompt (P2P) injection | critical | 8.5 | 2 | Data Exfiltration, Vulnerability Exploitation |
| 397 | Unsecured MongoDB instance | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 398 | Oracle E-Business Suite (EBS) vulnerability | critical | 8.5 | 2 | Data Breach |
| 399 | Inadequate Data Security Measures | critical | 8.5 | 2 | Data Breach |
| 400 | Misconfigured Elasticsearch instance | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 401 | Salesforce Misconfiguration | critical | 8.5 | 2 | Data Breach |
| 402 | Lack of Physical Security for Sensitive Device | critical | 8.5 | 2 | Data Breach (Physical Theft) |
| 403 | weak email security controls | critical | 8.5 | 2 | data breach, Data Breach |
| 404 | Unsecured Elasticsearch cluster | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 405 | Unsecured Amazon S3 Bucket | critical | 8.5 | 2 | Data Breach |
| 406 | lack of awareness | critical | 8.5 | 2 | data breach, Awareness Campaign |
| 407 | Improper Access Controls on Amazon S3 Bucket | critical | 8.5 | 2 | Data Breach |
| 408 | Access Credentials | critical | 8.5 | 2 | Data Breach |
| 409 | Long-lived tokens | critical | 8.5 | 2 | Data Breach |
| 410 | CVE-2025-21043 (Out-of-Bounds Write in libimagecodec.quram.so) | critical | 8.5 | 2 | Vulnerability Exploitation |
| 411 | Unauthorized code injection | critical | 8.5 | 2 | Data Breach |
| 412 | Missing Access Controls | critical | 8.5 | 2 | Data Exposure, Unauthorized Access |
| 413 | Misconfigured Rsync Server | critical | 8.5 | 2 | Data Exposure, Data Breach |
| 414 | Credential Theft | critical | 8.5 | 2 | Data Breach, Malware |
| 415 | unencrypted sensitive data | critical | 8.5 | 2 | data breach, Quantum Computing Threat |
| 416 | improper access controls (publicly accessible database) | critical | 8.5 | 2 | data breach, Data Leak |
| 417 | Unsecured Flash Drive | critical | 8.5 | 2 | Data Breach |
| 418 | Compromised employee credentials | critical | 8.5 | 2 | Data Breach |
| 419 | GoAnywhere Zero-Day Vulnerability | critical | 8.5 | 2 | Data Breach, Ransomware, Ransomware |
| 420 | Publicly available data | critical | 8.5 | 2 | Data Breach |
| 421 | Identity Theft | critical | 8.0 | 2 | Data Breach, Identity Theft |
| 422 | Technical Glitch | critical | 8.0 | 2 | Data Breach |
| 423 | Improper Disposal of Sensitive Information | critical | 8.0 | 2 | Data Breach |
| 424 | Unauthorized Data Sharing | critical | 8.0 | 2 | Data Breach |
| 425 | Inadequate Physical Security | high | 7.5 | 2 | physical cyber convergence, Data Breach |
| 426 | Human Error/Insider Threat | high | 6.0 | 2 | Data Breach |
| 427 | Compromised Account Credentials | high | 6.0 | 2 | Unauthorized Access, DNS Manipulation, Data Breach |
| 428 | Loss of Physical Media | high | 6.0 | 2 | Data Breach |
| 429 | Corporate Email Account | high | 6.0 | 2 | Data Breach |
| 430 | Inadvertent Email | high | 6.0 | 2 | Data Breach |
| 431 | Unencrypted Payment Card Information | high | 6.0 | 2 | Data Breach |
| 432 | MOVEit Transfer service | high | 6.0 | 2 | Data Breach |
| 433 | ATM Security | high | 6.0 | 2 | Data Breach, ATM Skimming/Shimming |
| 434 | Website Misconfiguration | high | 6.0 | 2 | Data Exposure, Data Breach |
| 435 | CVE-2018-3952 | high | 6.0 | 2 | Vulnerability Exploit, Vulnerability Exploitation |
| 436 | Unauthorized Access to Employee Email Account | high | 6.0 | 2 | Data Breach |
| 437 | Point-of-Sale Device | high | 6.0 | 2 | Data Breach |
| 438 | lack of multi-factor authentication (MFA) on Slack | high | 6.0 | 2 | data breach, Data Breach |
| 439 | Compromised Microsoft Office 365 account | high | 6.0 | 2 | Business Email Compromise (BEC), Data Breach |
| 440 | Tax Filing Software | medium | 5.0 | 2 | Data Breach |
| 441 | Improper Disposal | medium | 5.0 | 2 | Data Breach |
| 442 | MOVEit Transfer software vulnerabilities | medium | 5.0 | 2 | Data Breach |
| 443 | Reused Credentials | medium | 5.0 | 2 | Data Breach |
| 444 | HTML Injection | medium | 5.0 | 2 | Vulnerability Exploitation, Prompt Injection |
| 445 | CVE-2026-0049 | low | 2.5 | 2 | Vulnerability |
| 446 | CVE-2024-7399 | low | 2.5 | 2 | Botnet Infection, Vulnerability Exploitation |
| 447 | Unsecured Physical Records | low | 2.5 | 2 | Data Breach |
| 448 | CVE-2026-1504 | low | 2.5 | 2 | Vulnerability |
| 449 | Citrix Bleed | critical | 10.0 | 1 | Ransomware Attack |
| 450 | Unencrypted POS devices | critical | 10.0 | 1 | Data Breach |
| 451 | CVE-2025-27816 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 452 | Compromised software supply chain | critical | 10.0 | 1 | Supply Chain Attack |
| 453 | Shared operator accounts | critical | 10.0 | 1 | Cyber Espionage |
| 454 | Website Software | critical | 10.0 | 1 | Data Breach |
| 455 | CVE-2026-27966 | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 456 | Authentication keys | critical | 10.0 | 1 | Cyberattack |
| 457 | Default password in Unitronics programmable logic controllers (PLCs) | critical | 10.0 | 1 | Cyberattack |
| 458 | Phone data hijacking via malicious vCard | critical | 10.0 | 1 | Vulnerability Exploitation |
| 459 | compromised backup configurations (SonicWall cloud breach) | critical | 10.0 | 1 | ransomware |
| 460 | inadequate least-privilege access controls | critical | 10.0 | 1 | cyberespionage |
| 461 | Progress Software MOVEit Transfer SQL Injection Vulnerability (CVE-2023-34362) | critical | 10.0 | 1 | Data Breach |
| 462 | Mismanagement of data storage | critical | 10.0 | 1 | Data Breach |
| 463 | Geopolitical protections for cybercriminals | critical | 10.0 | 1 | Ransomware |
| 464 | Poorly Secured ICS Components (PLCs, SCADA, HMIs, Industrial IoTs) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 465 | Human Trust in Browser Update Prompts | critical | 10.0 | 1 | Malware Infection |
| 466 | Unchanged credentials | critical | 10.0 | 1 | Ransomware |
| 467 | Unsecured ElasticSearch Database | critical | 10.0 | 1 | Data Exposure |
| 468 | Improper input sanitization in virtuser_query plugin (preg_replace backslash escape bypass) | critical | 10.0 | 1 | SQL Injection |
| 469 | Lack of authentication/logging in OT systems | critical | 10.0 | 1 | Ransomware, Cyber Espionage, Industrial Sabotage |
| 470 | Compromised digital certificate, trusted update infrastructure | critical | 10.0 | 1 | Supply Chain Attack |
| 471 | CVE-2021-35587 | critical | 10.0 | 1 | Data Breach |
| 472 | CVE-2026-7473 | critical | 10.0 | 1 | Zero-Day Exploit |
| 473 | compromised laptop (physical or logical access) | critical | 10.0 | 1 | data breach |
| 474 | Security flaw in SonicWall’s systems | critical | 10.0 | 1 | Ransomware |
| 475 | Human Vulnerability (Insider Threat) | critical | 10.0 | 1 | Insider Threat (Attempted) |
| 476 | Dormant Service Accounts | critical | 10.0 | 1 | Data Breach |
| 477 | Network segmentation flaws or disabled/unmonitored logs | critical | 10.0 | 1 | Data Breach |
| 478 | Improper Data Handling Practices | critical | 10.0 | 1 | Data Breach |
| 479 | Inadequate Data Anonymization in AI Features (e.g., Grok AI) | critical | 10.0 | 1 | Data Breach |
| 480 | Weak Caller Verification Processes | critical | 10.0 | 1 | Social Engineering |
| 481 | Stolen secret code for cookie generation | critical | 10.0 | 1 | Data Breach |
| 482 | CVE-2025-49154 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 483 | SVG animate elements in HTML sanitizer | critical | 10.0 | 1 | SQL Injection |
| 484 | Unhashed Passwords | critical | 10.0 | 1 | Data Breach |
| 485 | Plaintext Credential Storage | critical | 10.0 | 1 | Vulnerability Exploitation |
| 486 | Gaps in Endpoint Detection and Response (EDR) | critical | 10.0 | 1 | Domain Hijacking |
| 487 | CVE-2025-49158 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 488 | CVE-2025-7544 | critical | 10.0 | 1 | Botnet Campaign |
| 489 | Unsecured communication channels (WhatsApp) | critical | 10.0 | 1 | Data Breach |
| 490 | Gaps in GDPR Data Protection for Vehicle-Generated Data | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 491 | Unsecured databases exposed to the public internet | critical | 10.0 | 1 | Ransomware/Extortion |
| 492 | Decentralized App Ecosystem (Shadow IT, Unmanaged SaaS) | critical | 10.0 | 1 | Browser-Based Attack |
| 493 | Weakness in GPS navigation systems (susceptibility to spoofing) | critical | 10.0 | 1 | GPS spoofing |
| 494 | CVE-2025-30232 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 495 | NtQuerySystemInformation abuse (SystemCodeFlowTransition parameter) | critical | 10.0 | 1 | Supply Chain Attack |
| 496 | End-of-life (EOL) and end-of-support (EOS) Microsoft IIS servers | critical | 10.0 | 1 | Vulnerability Exposure |
| 497 | Output Messenger | critical | 10.0 | 1 | Cyberespionage |
| 498 | Lack of proactive threat detection and centralized incident response | critical | 10.0 | 1 | Cyber Espionage |
| 499 | Malicious APKs | critical | 10.0 | 1 | Cryptocurrency Scam |
| 500 | Security software vulnerability | critical | 10.0 | 1 | Ransomware |
| 501 | CVE-2026-34909 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 502 | Login bypass vulnerability, improper access controls | critical | 10.0 | 1 | Data Leak, Unauthorized Access, Remote Exploitation |
| 503 | Lack of Multi-Factor Authentication (MFA) for remote hires | critical | 10.0 | 1 | Espionage |
| 504 | Remote Code Execution (RCE) zero-day in Oracle E-Business Suite (versions 12.2.3-12.2.14) | critical | 10.0 | 1 | ransomware |
| 505 | CVE-2026-20131 (Insecure Deserialization - CWE-502) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 506 | Insufficient anti-jam technology | critical | 10.0 | 1 | GPS spoofing |
| 507 | Insecure Third-Party Integration Controls | critical | 10.0 | 1 | Data Breach |
| 508 | Poor Kubernetes configurations | critical | 10.0 | 1 | Cloud Infrastructure Compromise |
| 509 | Insufficient Employee Training on Vishing | critical | 10.0 | 1 | Data Breach |
| 510 | Neterbit routers | critical | 10.0 | 1 | DDoS Attack |
| 511 | Lack of physical security for sensitive data display | critical | 10.0 | 1 | Data Breach |
| 512 | Legacy Authentication Methods (Password-Only Logins) | critical | 10.0 | 1 | Browser-Based Attack |
| 513 | Phishing Domains | critical | 10.0 | 1 | Cryptocurrency Scam |
| 514 | Passive Storage Component Treatment (Missing Threat Signals) | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 515 | Single-character coding error | critical | 10.0 | 1 | Cryptocurrency Theft |
| 516 | Exposed Database | critical | 10.0 | 1 | Ransomware Attack |
| 517 | weak encryption key management practices | critical | 10.0 | 1 | ransomware |
| 518 | Human Vulnerability (Phishing/Social Engineering Susceptibility) | critical | 10.0 | 1 | Account Compromise |
| 519 | lack of 2FA for publisher accounts | critical | 10.0 | 1 | supply chain attack |
| 520 | Remote Code Execution (RCE) in AhsayCBS backup system | critical | 10.0 | 1 | Remote Code Execution |
| 521 | Outsourced Business Process Provider Vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 522 | Unmonitored Devices | critical | 10.0 | 1 | Domain Hijacking |
| 523 | CVE-2025-27920 (directory traversal in Output Messenger) | critical | 10.0 | 1 | cyberespionage |
| 524 | CVE-2026-20230 (Improper input validation in HTTP requests, CWE-918) | critical | 10.0 | 1 | SSRF (Server-Side Request Forgery) |
| 525 | CVE-2025-52691 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 526 | Spear-phishing campaigns | critical | 10.0 | 1 | Data Breach |
| 527 | exposed remote services | critical | 10.0 | 1 | Ransomware |
| 528 | Blind Spots in Monitoring | critical | 10.0 | 1 | Ransomware |
| 529 | Exposed long-term IAM user credentials, Lambda function code injection | critical | 10.0 | 1 | Cloud Breach |
| 530 | Employee Theft | critical | 10.0 | 1 | Data Breach |
| 531 | CVE-2017-12637 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 532 | CVE-2023-3595 | critical | 10.0 | 1 | Cyber Espionage |
| 533 | Cybersecurity Staffing Shortages | critical | 10.0 | 1 | Collaborative Initiative |
| 534 | default weak password policies (privileged accounts <14 characters) | critical | 10.0 | 1 | ransomware |
| 535 | Lack of continuous vendor monitoring | critical | 10.0 | 1 | Ransomware |
| 536 | Unauthorized access to Tetra mobile device signals, lack of robust signal authentication | critical | 10.0 | 1 | Radio Signal Spoofing |
| 537 | CVE-2024-8300 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 538 | Internet-exposed databases | critical | 10.0 | 1 | Ransomware |
| 539 | Trusted third-party SDK distribution (websdk.appsflyer.com) | critical | 10.0 | 1 | Supply-Chain Attack |
| 540 | Malicious form injection | critical | 10.0 | 1 | Data Breach |
| 541 | Lack of Endpoint Detection and Response (EDR) in Some Systems | critical | 10.0 | 1 | Malware Infection |
| 542 | Credential harvesting via malicious links/impersonation | critical | 10.0 | 1 | Cyber Espionage |
| 543 | Weak access controls, lack of data classification protocols, unencrypted data, unrestricted physical access to devices, absence of audit logs | critical | 10.0 | 1 | Data Leak |
| 544 | Insecure Default Settings | critical | 10.0 | 1 | Vulnerability Exploitation |
| 545 | CVE-2025-47950 | critical | 10.0 | 1 | Vulnerability |
| 546 | weak/default credentials | critical | 10.0 | 1 | cyberattack |
| 547 | CVE-2025-53521 (F5 BIG-IP APM) | critical | 10.0 | 1 | ransomware |
| 548 | Previously unknown vulnerability in the payment processing system | critical | 10.0 | 1 | Data Breach |
| 549 | Lack of Compliance Oversight | critical | 10.0 | 1 | Data Breach |
| 550 | CVE-2024-37079 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 551 | Flaw in smart contract calls | critical | 10.0 | 1 | DeFi Exploit |
| 552 | Unsecured directory with unrestricted access | critical | 10.0 | 1 | Data Leak |
| 553 | Microsoft Entra ID Enterprise Applications (mail.read, full_access_as_app scopes) | critical | 10.0 | 1 | Espionage |
| 554 | Apache Struts CVE-2017-5638 | critical | 10.0 | 1 | Data Breach |
| 555 | Improper GitHub Access Controls | critical | 10.0 | 1 | Supply Chain Attack |
| 556 | Poor OAuth Protections | critical | 10.0 | 1 | Data Breach |
| 557 | Improper handling of the `--exec` flag in `git rebase` during 'Rebase before merging' operations | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 558 | Server flaw identified via network traffic analysis | critical | 10.0 | 1 | Unauthorized Access |
| 559 | Previously unknown vulnerability in data transfer software | critical | 10.0 | 1 | Data Breach |
| 560 | CVE-2025-47167 (Windows KDC Proxy Service Use-After-Free) | critical | 10.0 | 1 | Patch Release |
| 561 | Absence of Privacy-Enhancing Technologies (PETs) | critical | 10.0 | 1 | Data Breach |
| 562 | Dependence on GPS/GNSS signals for navigation; lack of spoofing-resistant safeguards | critical | 10.0 | 1 | GNSS spoofing |
| 563 | Supply chain compromise of open-source security tool | critical | 10.0 | 1 | Supply Chain Attack |
| 564 | Previously unidentified vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 565 | Four zero-days | critical | 10.0 | 1 | Exploit Kit / Cyber Espionage |
| 566 | Human Error (Credential Sharing/System Access Granted via Deception) | critical | 10.0 | 1 | Data Breach |
| 567 | Lack of identity controls | critical | 10.0 | 1 | AI-driven breach |
| 568 | Legitimate account compromise | critical | 10.0 | 1 | Ransomware |
| 569 | Public-facing nodes and databases with inadequate security controls | critical | 10.0 | 1 | Research Study |
| 570 | Encrypted master key printed in plain, unencrypted digital language | critical | 10.0 | 1 | Data Breach |
| 571 | CVE-2017-7921 (Hikvision - authentication bypass) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 572 | weak SCADA system security | critical | 10.0 | 1 | cyber-physical attack |
| 573 | Default Authentication Bypasses | critical | 10.0 | 1 | Vulnerability Exploitation |
| 574 | CVE-2023-41346 | critical | 10.0 | 1 | botnet |
| 575 | Lack of Standardized Controls | critical | 10.0 | 1 | Collaborative Initiative |
| 576 | Stolen credentials from 2023 Salesloft Drift breach, weak credential management, lack of MFA enforcement | critical | 10.0 | 1 | Data Breach |
| 577 | Open-source LD_PRELOAD rootkit (Medusa) repurposed for malicious use | critical | 10.0 | 1 | Rootkit |
| 578 | visibility gap in EDR/SIEM logs | critical | 10.0 | 1 | ransomware |
| 579 | Unsecured BIM/cloud platforms | critical | 10.0 | 1 | Ransomware |
| 580 | Exposed credentials in public repository | critical | 10.0 | 1 | Data Exposure |
| 581 | NPM package dependency trust model | critical | 10.0 | 1 | supply chain attack |
| 582 | CVE (CVSS 9.7) - Lack of origin validation, authentication tokens, and CORS protections in WebSocket listener | critical | 10.0 | 1 | Vulnerability Exploitation |
| 583 | CVE-2026-6644 | critical | 10.0 | 1 | Zero-Day Exploit |
| 584 | CVE-2026-42945 (NGINX) | critical | 10.0 | 1 | Zero-day Exploit |
| 585 | Unpatched VPN software | critical | 10.0 | 1 | Ransomware |
| 586 | CVE-2025-23320 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 587 | Unmonitored API Queries (Graph, Teams) | critical | 10.0 | 1 | Social Engineering |
| 588 | Potential zero-day in F5 products | critical | 10.0 | 1 | Data Breach |
| 589 | mismanaged certificates | critical | 10.0 | 1 | third-party breach |
| 590 | Type Confusion via Memory Reuse | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 591 | Insufficient access controls, lack of root account protection | critical | 10.0 | 1 | Data Destruction |
| 592 | Lack of encryption, inadequate access controls, no multifactor authentication, insufficient intrusion detection and network monitoring | critical | 10.0 | 1 | Data Breach |
| 593 | Novel method | critical | 10.0 | 1 | Ransomware |
| 594 | Website Security | critical | 10.0 | 1 | Data Breach |
| 595 | Zero-Authentication (Zero-Auth) Flaw | critical | 10.0 | 1 | Data Breach |
| 596 | Supply Chain Weaknesses | critical | 10.0 | 1 | Domain Hijacking |
| 597 | Unknown vulnerability in file transfer software | critical | 10.0 | 1 | Ransomware |
| 598 | CVE-2026-50751 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 599 | Insufficient MFA Enforcement (Ghost Logins, SSO Gaps) | critical | 10.0 | 1 | Browser-Based Attack |
| 600 | Well-known attack vector (unspecified) | critical | 10.0 | 1 | Data Breach |
| 601 | Incorrect host/guest network separation (allowed privilege escalation from guest to host) | critical | 10.0 | 1 | Ransomware |
| 602 | Oracle E-Business Suite vulnerability | critical | 10.0 | 1 | Ransomware |
| 603 | Third-party breaches | critical | 10.0 | 1 | Supply Chain Attack, Extortion Campaign |
| 604 | Unmonitored AI Data Flows | critical | 10.0 | 1 | Data Breach |
| 605 | CVE-2026-20223 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 606 | Potential vulnerability in Citrix NetScaler | critical | 10.0 | 1 | Cyberattack |
| 607 | Misconfigured WAF | critical | 10.0 | 1 | Data Breach |
| 608 | Inadequate Backup Protection | critical | 10.0 | 1 | Ransomware Attack |
| 609 | Plaintext access to JSON payloads in AI agent tool calls, lack of cryptographic verification for tool-call integrity | critical | 10.0 | 1 | Supply Chain Attack |
| 610 | BlueHammer | critical | 10.0 | 1 | Zero-Day Exploitation |
| 611 | Improper Public Access Configuration | critical | 10.0 | 1 | Data Exposure |
| 612 | Procedural errors by Special Agent Aaron Spivack; unsecured server in child exploitation forensic lab | critical | 10.0 | 1 | Data Breach |
| 613 | Lack of global standards for D2D services | critical | 10.0 | 1 | Cyber-Physical Threat |
| 614 | weak identity management systems | critical | 10.0 | 1 | cyberespionage |
| 615 | CVE-2026-2256 (Inadequate input sanitization in MS-Agent's 'Shell tool') | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 616 | Misconfigured AWS Bucket | critical | 10.0 | 1 | Data Exposure |
| 617 | Legacy system vulnerabilities (some dating back to 2013) | critical | 10.0 | 1 | Ransomware |
| 618 | Provider Edge (PE) routers | critical | 10.0 | 1 | Cyber Espionage |
| 619 | Insecure data storage and handling | critical | 10.0 | 1 | Data Breach |
| 620 | Funnel Builder vulnerability | critical | 10.0 | 1 | Zero-day Exploit |
| 621 | CVE-2026-55200 (Integer overflow leading to buffer overflow in libssh2) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 622 | CVE-2024-36401 (Critical RCE in GeoServer) | critical | 10.0 | 1 | Cyber Espionage |
| 623 | Misconfigured cloud databases | critical | 10.0 | 1 | Ransomware |
| 624 | Unauthorized access to security credentials | critical | 10.0 | 1 | Financial Fraud, Insider Threat |
| 625 | Unpatched software, firmware, and operating systems | critical | 10.0 | 1 | Ransomware |
| 626 | Recently discovered vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 627 | Outdated Cryptographic Protocols | critical | 10.0 | 1 | Data Breach |
| 628 | CVE-2025-64175 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 629 | CVE-2025-48595 (Integer Overflow - CWE-190) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 630 | 2,000 previously unknown vulnerabilities across major operating systems | critical | 10.0 | 1 | AI-Driven Vulnerability Discovery and Exploitation |
| 631 | Unpatched or zero-day flaws in technology platforms | critical | 10.0 | 1 | Ransomware |
| 632 | Banking security systems | critical | 10.0 | 1 | Malware |
| 633 | Visual Redaction Without Data Removal | critical | 10.0 | 1 | Data Leak |
| 634 | Weaknesses in SolarWinds' Orion platform | critical | 10.0 | 1 | Supply Chain Attack |
| 635 | Unsecured RDP | critical | 10.0 | 1 | Ransomware |
| 636 | Dirty Frag (CVE-2026-31431) | critical | 10.0 | 1 | Privilege Escalation |
| 637 | Human error (help desk staff tricked into resetting credentials) | critical | 10.0 | 1 | Cyberattack |
| 638 | SHA-1 | critical | 10.0 | 1 | Data Breach |
| 639 | CVE-2026-41089 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 640 | Google Docs | critical | 10.0 | 1 | Data Leak |
| 641 | Lack of oversight in outsourcing, contractual violations | critical | 10.0 | 1 | Data Breach |
| 642 | Dependency confusion / Typosquatting | critical | 10.0 | 1 | Supply Chain Attack |
| 643 | Accellion File Transfer Appliance (FTA) vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 644 | Disguised Malicious Commands as Benign Requests | critical | 10.0 | 1 | Espionage |
| 645 | Unpatched APIs | critical | 10.0 | 1 | Cyberattack Surge |
| 646 | Compromised credentials, unsegmented networks, unlogged firewall activity, administrative credentials stored in plain text, insecure remote access tools | critical | 10.0 | 1 | Data Breach, Potential Ransomware |
| 647 | Unencrypted and unprotected data accessible on the network | critical | 10.0 | 1 | Data Breach, Ransomware |
| 648 | tasks.json file execution | critical | 10.0 | 1 | Financial Theft |
| 649 | poor cyber defenses in supplier systems | critical | 10.0 | 1 | supply chain attack |
| 650 | Outdated Software (e.g., Iranian oil tankers) | critical | 10.0 | 1 | Ransomware |
| 651 | Lack of Monitoring for Renamed Binaries | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 652 | Lack of backup systems | critical | 10.0 | 1 | Ransomware |
| 653 | CVE-2025-1727 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 654 | Zero-day vulnerability in Oracle E-Business Suite (advisory issued 2025-10-04) | critical | 10.0 | 1 | Data Breach |
| 655 | Unauthorized access due to offshoring of IT and cybersecurity functions, bypassed consent protocols | critical | 10.0 | 1 | Data Breach |
| 656 | Poorly protected and vulnerable government websites | critical | 10.0 | 1 | Cyberattack, Website Defacement, Data Compromise |
| 657 | API code change flaw, predictable device serial numbers, unencrypted MFA scratch codes | critical | 10.0 | 1 | Ransomware |
| 658 | Active Directory vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 659 | privileged credential abuse | critical | 10.0 | 1 | ransomware |
| 660 | Lapse of CISA 2015 liability protections | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 661 | administrator privilege escalation | critical | 10.0 | 1 | phishing |
| 662 | CVE-2026-9256 (nginx-poolslip) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 663 | 161 distinct CVEs in H1 2025 (up from 136 in H1 2024) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 664 | Unsecured Database Accessible Without Authentication | critical | 10.0 | 1 | Data Breach |
| 665 | Fragmented accountability among OEMs, MNOs, and satellite operators | critical | 10.0 | 1 | Cyber-Physical Threat |
| 666 | CVE-2025-53770 (ToolShell, patch bypass for CVE-2025-49704/CVE-2025-49706) | critical | 10.0 | 1 | Cyber Espionage |
| 667 | publicly available data misrepresented as 'secret' (hallucination exploit) | critical | 10.0 | 1 | cyberespionage |
| 668 | Authentication Mechanisms | critical | 10.0 | 1 | Data Breach |
| 669 | Undisclosed BIG-IP Vulnerabilities (under investigation) | critical | 10.0 | 1 | Supply Chain Attack |
| 670 | third-party cybersecurity dependencies | critical | 10.0 | 1 | cyberattack |
| 671 | Vulnerabilities in the email system | critical | 10.0 | 1 | Data Breach |
| 672 | Weak passwords, lack of two-factor authentication (2FA) | critical | 10.0 | 1 | Ransomware |
| 673 | Credential leaks (reused passwords) | critical | 10.0 | 1 | Extortion |
| 674 | Over-permissioning | critical | 10.0 | 1 | AI-driven breach |
| 675 | Security issue with Haltdos | critical | 10.0 | 1 | Data Breach |
| 676 | CVE-2025-20333 (Cisco ASA/Firepower - RCE) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 677 | Oracle E-Business Suite | critical | 10.0 | 1 | Ransomware |
| 678 | Human Trust in Help-Desk Processes | critical | 10.0 | 1 | Cyberattack |
| 679 | Lack of Granular Network Segmentation | critical | 10.0 | 1 | EDR/XDR Evasion |
| 680 | Unknown network vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 681 | SCADA system vulnerabilities | critical | 10.0 | 1 | DDoS |
| 682 | CVE-2024-12912 | critical | 10.0 | 1 | botnet |
| 683 | unmanaged systems (for data theft and ransomware deployment) | critical | 10.0 | 1 | ransomware |
| 684 | Cisco Smart Install feature vulnerabilities | critical | 10.0 | 1 | Cyber Espionage, Critical Infrastructure Attack |
| 685 | Non-shard-isolated user directory, unencrypted public chat rooms | critical | 10.0 | 1 | Data Breach |
| 686 | Lack of API Key Monitoring | critical | 10.0 | 1 | Influence Operation |
| 687 | Limited staffing | critical | 10.0 | 1 | Cyberattack |
| 688 | Interception and editing of RF signals | critical | 10.0 | 1 | Vulnerability |
| 689 | Outdated software (EOL Windows versions) | critical | 10.0 | 1 | Exposed Servers |
| 690 | supply-chain weakness | critical | 10.0 | 1 | data breach |
| 691 | End-of-life and end-of-service network devices, outdated infrastructure | critical | 10.0 | 1 | Ransomware |
| 692 | CVE-2025-69264 (CVSS 8.8) | critical | 10.0 | 1 | Supply Chain Attack |
| 693 | Salesloft’s Drift AI Chat Integration (OAuth Token Theft) | critical | 10.0 | 1 | Data Breach |
| 694 | Outdated Operating Systems/Applications | critical | 10.0 | 1 | Malware |
| 695 | CVE-2026-21571 | critical | 10.0 | 1 | OS Command Injection |
| 696 | CVE-2024-36904 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 697 | Remote login vulnerability exacerbated by increased remote work during the pandemic | critical | 10.0 | 1 | Ransomware |
| 698 | Citrix device vulnerabilities (specific CVE not disclosed) | critical | 10.0 | 1 | Cyberattack |
| 699 | BDU-2025-10116 (CVSS 9.8) - Command injection | critical | 10.0 | 1 | Cyber Espionage |
| 700 | CVE-2024-21410 (Privilege Escalation), CVE-2024-21413 | critical | 10.0 | 1 | Zero-Day Exploit |
| 701 | CVE-2026-35616 (CWE-284: Improper Access Control) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 702 | CVE-2025-1449 | critical | 10.0 | 1 | Vulnerability Exploit |
| 703 | Lack of OT Asset Management | critical | 10.0 | 1 | Ransomware |
| 704 | myCare Integrity EMR system | critical | 10.0 | 1 | Data Breach |
| 705 | Poorly configured firewalls | critical | 10.0 | 1 | Ransomware |
| 706 | Veeam Backup & Replication (VBR) servers | critical | 10.0 | 1 | Ransomware |
| 707 | CVE-2024-56325 | critical | 10.0 | 1 | Vulnerability Exploit |
| 708 | weak_or_reused_passwords | critical | 10.0 | 1 | ransomware |
| 709 | systemic weaknesses in data protection | critical | 10.0 | 1 | data breach |
| 710 | Shadow AI | critical | 10.0 | 1 | Data Breach |
| 711 | lack of network segmentation (allowed lateral movement) | critical | 10.0 | 1 | ransomware |
| 712 | Trusted partner relationships, fake Okta login pages, clipboard data theft | critical | 10.0 | 1 | Data Theft Extortion |
| 713 | Lack of monitoring for east-west traffic in cloud environments | critical | 10.0 | 1 | Ransomware |
| 714 | CVE-2026-0755 (ZDI-26-021, ZDI-CAN-27783) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 715 | Misconfiguration or compromise in Okta SSO and Salesforce Marketing Cloud | critical | 10.0 | 1 | Phishing / Scam |
| 716 | Unspecified Adobe ColdFusion Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 717 | Unknown vulnerability in the company's network | critical | 10.0 | 1 | Data Breach |
| 718 | Protection relays | critical | 10.0 | 1 | Cyber Sabotage |
| 719 | Human operational error | critical | 10.0 | 1 | GPS spoofing (disputed) |
| 720 | Human-Machine Interfaces (HMIs) | critical | 10.0 | 1 | Cyber Sabotage |
| 721 | Malicious code injection in legitimate packages | critical | 10.0 | 1 | Supply Chain Attack |
| 722 | Oracle PeopleSoft applications | critical | 10.0 | 1 | Data Breach |
| 723 | Delayed Breach Detection (avg. 276 days per IBM 2025 report) | critical | 10.0 | 1 | Supply Chain Attack |
| 724 | CVE-2025-64328 | critical | 10.0 | 1 | Webshell Deployment |
| 725 | Unidentified network vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 726 | Insufficient ESXi Logging Configurations | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 727 | Known Exploited Vulnerabilities (CISA Catalog) | critical | 10.0 | 1 | System Intrusion |
| 728 | Poor IoT device oversight/management | critical | 10.0 | 1 | Ransomware |
| 729 | CVE-2026-5027 (Path Traversal) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 730 | API misconfiguration | critical | 10.0 | 1 | Data Breach |
| 731 | static credential storage | critical | 10.0 | 1 | fraud |
| 732 | CVE-2025-48595 (CWE-190 - Integer Overflow) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 733 | legacy systems in healthcare and critical infrastructure | critical | 10.0 | 1 | ransomware |
| 734 | unrestricted access to GitHub Actions environment variables | critical | 10.0 | 1 | supply chain attack |
| 735 | DLL sideloading | critical | 10.0 | 1 | Supply Chain Attack |
| 736 | CitrixBleed (CVE-2023-4966) - CVSS 9.3 in Netscaler ADC and Gateway (Session Token Theft, MFA Bypass) | critical | 10.0 | 1 | Data Breach |
| 737 | unmonitored vendor access to sensitive data | critical | 10.0 | 1 | supply chain attack |
| 738 | Absence of Multifactor Authentication | critical | 10.0 | 1 | Ransomware |
| 739 | Default/Weak Admin Credentials | critical | 10.0 | 1 | Data Breach |
| 740 | lack of backups | critical | 10.0 | 1 | data breach |
| 741 | CVE-2026-46242 (Use-after-free and race condition in epoll subsystem) | critical | 10.0 | 1 | Privilege Escalation |
| 742 | CVE-2023-48788 (Fortinet EMS) | critical | 10.0 | 1 | Ransomware |
| 743 | Hidden registration form, JSESSIONID manipulation, and lack of server-side token validation | critical | 10.0 | 1 | Privilege Escalation, Remote Code Execution |
| 744 | Ageing infrastructure, shared IT systems, lack of network segmentation | critical | 10.0 | 1 | Data Breach |
| 745 | CVE-2024-55591 (FortiOS/FortiProxy Race Condition Authentication Bypass) | critical | 10.0 | 1 | Unauthorized Access |
| 746 | Weakness in mobile payment verification system (KT) | critical | 10.0 | 1 | Data Breach |
| 747 | CVE-2025-8943 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 748 | LLM Susceptibility to Prompt Injection | critical | 10.0 | 1 | Prompt Injection |
| 749 | Weak VPN authentication | critical | 10.0 | 1 | Data Breach |
| 750 | CVE-2024-21410 | critical | 10.0 | 1 | Zero-Day Exploit |
| 751 | CrushFTP servers | critical | 10.0 | 1 | Supply Chain Attack |
| 752 | Lack of two-factor authentication (2FA), persistent access to Aeroflot’s infrastructure | critical | 10.0 | 1 | Supply-Chain Attack |
| 753 | weak security in satellite communication systems | critical | 10.0 | 1 | cyberattack |
| 754 | Trello | critical | 10.0 | 1 | Data Leak |
| 755 | Weak Password in Remote-Control System | critical | 10.0 | 1 | Cyberattack |
| 756 | Inadequate Cybersecurity Defenses | critical | 10.0 | 1 | Data Breach |
| 757 | Complacency in High-Turnover Workforces | critical | 10.0 | 1 | Data Breach |
| 758 | File transfer tool vulnerability | critical | 10.0 | 1 | Ransomware |
| 759 | At least 20 exploited vulnerabilities | critical | 10.0 | 1 | Data Breach, Cyberattack, AI-Enabled Attack |
| 760 | OAuth vulnerability | critical | 10.0 | 1 | Exploit |
| 761 | Known security gaps in domestic agencies | critical | 10.0 | 1 | Data Breach |
| 762 | Corporate Virtual Desktop Infrastructure (VDI) | critical | 10.0 | 1 | Data Theft Extortion |
| 763 | Unmanaged Credentials | critical | 10.0 | 1 | Data Breach |
| 764 | Critical vulnerabilities within the ESXi platform | critical | 10.0 | 1 | Ransomware |
| 765 | CVE-2025-2171 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 766 | Four-Faith industrial routers | critical | 10.0 | 1 | DDoS Attack |
| 767 | Lack of Visibility into Privileged Account Usage | critical | 10.0 | 1 | Data Breach |
| 768 | AI Model Jailbreak (Disguised Malicious Tasks as Benign) | critical | 10.0 | 1 | Espionage |
| 769 | CitrixBleed2 (CVE not explicitly mentioned but inferred as Citrix NetScaler vulnerability) | critical | 10.0 | 1 | data breach |
| 770 | Cleo software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 771 | high market value of copper | critical | 10.0 | 1 | infrastructure vulnerability |
| 772 | Automated execution during `npm install`, GitHub Actions environment targeting | critical | 10.0 | 1 | Supply Chain Attack |
| 773 | Non-public information disclosure | critical | 10.0 | 1 | Bribery and Fraud |
| 774 | Log4Shell (CVE-2021-44228) | critical | 10.0 | 1 | Ransomware Attack |
| 775 | Lack of Zero-Trust Architecture | critical | 10.0 | 1 | Cyber Espionage |
| 776 | subdomain vulnerabilities | critical | 10.0 | 1 | data breach |
| 777 | Implicit TLS | critical | 10.0 | 1 | Cross-protocol Application Layer Desynchronization |
| 778 | Previously unknown software flaw (zero-day) | critical | 10.0 | 1 | Cyber Espionage |
| 779 | Inadequate Risk Management Exercises | critical | 10.0 | 1 | Data Breach |
| 780 | weaknesses in distributed enforcement synchronization | critical | 10.0 | 1 | data breach |
| 781 | BDU:2025-10114 (CVSS 7.5) - Insufficient access control | critical | 10.0 | 1 | Cyber Espionage |
| 782 | CVE-2025-20333 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 783 | Oracle WebLogic (unidentified flaw) | critical | 10.0 | 1 | Ransomware Attack |
| 784 | SharePoint Permissions Issue | critical | 10.0 | 1 | Data Breach |
| 785 | ProxyNotShell (Microsoft Exchange) | critical | 10.0 | 1 | Cyber Espionage |
| 786 | Lack of Network Segmentation in Targeted Systems | critical | 10.0 | 1 | Distributed Denial of Service (DDoS) |
| 787 | Insecure ICS Protocols (Plaintext Traffic) | critical | 10.0 | 1 | Exposure of Vulnerable Systems |
| 788 | Malicious code injection | critical | 10.0 | 1 | Data Breach |
| 789 | lack of threat detection tuning | critical | 10.0 | 1 | ransomware |
| 790 | User Trust in Popular Repositories | critical | 10.0 | 1 | Malware Distribution and Phishing |
| 791 | Exposed SMB ports with weak or compromised credentials | critical | 10.0 | 1 | Ransomware |
| 792 | Microsoft Office Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 793 | Unpatched Cisco ASA device (last patched in 2024) | critical | 10.0 | 1 | Cyberwarfare |
| 794 | Unclear Accountability Frameworks | critical | 10.0 | 1 | Data Privacy Violation |
| 795 | Misconfigured public repository | critical | 10.0 | 1 | Data Leak |
| 796 | CVE-2025-7742 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 797 | Satellite Communication Systems | critical | 10.0 | 1 | Cyber Attack |
| 798 | Design flaw in VSCode’s webview security model (Window.postMessage() API misuse), lack of CSRF protections in github.dev, unrestricted Node.js API access in extensions | critical | 10.0 | 1 | Vulnerability Exploitation |
| 799 | React2Shell vulnerability in React frontend application | critical | 10.0 | 1 | Data Breach |
| 800 | Improper handling of configuration objects in the `mergeConfig` function (CVE-2026-25639) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 801 | CVE-2023-41348 | critical | 10.0 | 1 | botnet |
| 802 | Unsecured Elasticsearch Server | critical | 10.0 | 1 | Data Breach |
| 803 | Trust in .gov/.police Domain Emails (Bypassing Technical Filters) | critical | 10.0 | 1 | Account Compromise |
| 804 | Fortinet Fortigate | critical | 10.0 | 1 | Supply Chain Attack |
| 805 | Design Flaw in 'SAVE' Feature | critical | 10.0 | 1 | Data Leak |
| 806 | Vulnerability in Cleo's file transfer products | critical | 10.0 | 1 | Ransomware |
| 807 | CVE-2025-3052 | critical | 10.0 | 1 | Secure Boot Bypass |
| 808 | Inadequate monitoring for suspicious activity | critical | 10.0 | 1 | Data Breach |
| 809 | Delayed Threat Response | critical | 10.0 | 1 | Operational Risk |
| 810 | CVE-2026-32746 (Buffer Overflow in GNU InetUtils telnetd) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 811 | Over-reliance on single-source supply chain (China) | critical | 10.0 | 1 | Geopolitical Risk |
| 812 | Stolen Credentials/API Tokens | critical | 10.0 | 1 | Data Breach |
| 813 | Linux Kernel bug (Fragnesia) | critical | 10.0 | 1 | Zero-day Exploit |
| 814 | remote access security | critical | 10.0 | 1 | Ransomware |
| 815 | Potential Salesforce Misconfigurations | critical | 10.0 | 1 | Data Breach |
| 816 | Open academic networks | critical | 10.0 | 1 | Data Breach |
| 817 | Accidental transmission of private key information | critical | 10.0 | 1 | Data Breach |
| 818 | Unauthorized Access by Ex-Employee | critical | 10.0 | 1 | Data Breach |
| 819 | Lack of Multi-Factor Authentication (Assumed) | critical | 10.0 | 1 | Ransomware |
| 820 | Thousands of zero-day vulnerabilities | critical | 10.0 | 1 | AI-driven cyber attack |
| 821 | XSS vulnerability in StealC control panel | critical | 10.0 | 1 | malware |
| 822 | Unauthorized Admin Role Assignments | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 823 | Inadequate safeguards for sensitive data | critical | 10.0 | 1 | Data Breach |
| 824 | Insufficient sanitization in serialize and compileMDX functions (CVE-2026-0969) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 825 | Apache Log4j vulnerability | critical | 10.0 | 1 | Cyberattack (Reconnaissance Campaign) |
| 826 | lack of behavioral monitoring | critical | 10.0 | 1 | data_breach |
| 827 | CVE-2026-53435 | critical | 10.0 | 1 | Deserialization Vulnerability |
| 828 | Email Spoofing, Unsecured Computer System | critical | 10.0 | 1 | Hacking |
| 829 | CVE-2026-42945 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 830 | GenAI data exfiltration | critical | 10.0 | 1 | Session Hijacking |
| 831 | Canvas Free for Teacher service vulnerability | critical | 10.0 | 1 | Data Breach |
| 832 | Apache Log4j2 | critical | 10.0 | 1 | Reconnaissance |
| 833 | improper access controls on cloud storage (public bucket setting) | critical | 10.0 | 1 | data breach |
| 834 | Unpatched vulnerability in the network defenses | critical | 10.0 | 1 | Ransomware |
| 835 | unauthorized remote access | critical | 10.0 | 1 | cyber-physical attack |
| 836 | Weaknesses in detection-focused security tools like EDR/XDR | critical | 10.0 | 1 | Ransomware |
| 837 | Insider Threat, Social Engineering | critical | 10.0 | 1 | Espionage, Data Breach |
| 838 | Microsoft IIS | critical | 10.0 | 1 | Supply Chain Attack |
| 839 | End-of-Life (EoL) Hardware with No Security Updates | critical | 10.0 | 1 | Cyber Espionage |
| 840 | Inadequate security controls in femtocell management system, disabled end-to-end encryption | critical | 10.0 | 1 | Malware |
| 841 | Lack of Syslog Forwarding to External Systems | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 842 | Use-After-Free (UAF) | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 843 | CVE-2025-20362 (Cisco ASA/Firepower - Privilege Escalation) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 844 | Known vulnerability in database software | critical | 10.0 | 1 | Data Breach |
| 845 | CVE-2026-43284 | critical | 10.0 | 1 | Privilege Escalation |
| 846 | undersea cable physical exposure | critical | 10.0 | 1 | sabotage |
| 847 | Single Point of Failure in Critical Workflows | critical | 10.0 | 1 | Supply Chain Attack |
| 848 | poor segmentation of payment systems | critical | 10.0 | 1 | ransomware |
| 849 | Human Weakness | critical | 10.0 | 1 | Data Breach |
| 850 | Insufficient Code Review for Open-Source Dependencies | critical | 10.0 | 1 | Supply Chain Attack |
| 851 | PhantomRPC (CVE not specified) | critical | 10.0 | 1 | Privilege Escalation |
| 852 | Undetected intrusion due to oversight lapses | critical | 10.0 | 1 | Data Breach |
| 853 | unsecured legacy data storage | critical | 10.0 | 1 | fraud |
| 854 | underfunded IT security | critical | 10.0 | 1 | ransomware |
| 855 | CVE-2025-55241 (Token Validation Failure in Microsoft Entra ID / Azure AD Graph API) | critical | 10.0 | 1 | Privilege Escalation |
| 856 | CVE-2024-13804 | critical | 10.0 | 1 | Vulnerability Exploit |
| 857 | Windows OS vulnerability (unspecified programming bug) | critical | 10.0 | 1 | malware |
| 858 | CVE-2024-20359 (Privilege Escalation: Admin → Root) | critical | 10.0 | 1 | Cyberattack |
| 859 | Previously unknown vulnerability in file transfer software | critical | 10.0 | 1 | Data Breach |
| 860 | delayed patching | critical | 10.0 | 1 | phishing |
| 861 | SonicWall SSLVPN misconfigurations | critical | 10.0 | 1 | ransomware |
| 862 | Outdated Industrial Control Systems (ICS) | critical | 10.0 | 1 | Cyber Espionage |
| 863 | CVE-2026-48558 | critical | 10.0 | 1 | Authentication Bypass |
| 864 | Client-side file type restrictions without server-side validation | critical | 10.0 | 1 | Cloud Account Takeover |
| 865 | Authentication Bypass in Python.org’s release management API | critical | 10.0 | 1 | Authentication Bypass |
| 866 | Poor Access Controls for Sensitive Data | critical | 10.0 | 1 | Data Breach |
| 867 | CVE-2025-53770 (ToolShell SharePoint Flaw) | critical | 10.0 | 1 | Cyber Espionage |
| 868 | Unpatched Web Applications | critical | 10.0 | 1 | AI-Powered Cyberattack |
| 869 | Outdated encryption, weak cryptographic practices, poor key management | critical | 10.0 | 1 | Cyber Threat Warning |
| 870 | insecure communication protocols | critical | 10.0 | 1 | unauthorized access |
| 871 | CVE-2025-10035 (GoAnywhere MFT) | critical | 10.0 | 1 | ransomware |
| 872 | Slow Detection Capabilities | critical | 10.0 | 1 | Data Breach |
| 873 | third-party compromises (35.5% of breaches in 2024) | critical | 10.0 | 1 | ransomware |
| 874 | Oracle Cloud Infrastructure Flaw (from March 2025 breach) | critical | 10.0 | 1 | Data Breach |
| 875 | GPS signal susceptibility to jamming | critical | 10.0 | 1 | GPS jamming |
| 876 | Unpatched Web Browser/Plugin Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 877 | insufficient user education on phishing/social engineering | critical | 10.0 | 1 | cyber espionage |
| 878 | NPM package integrity weakness | critical | 10.0 | 1 | supply chain attack |
| 879 | Excessive Privileges in Connected Applications | critical | 10.0 | 1 | Data Breach |
| 880 | Exposed Presence/Status Data | critical | 10.0 | 1 | Social Engineering |
| 881 | CVE-2025-7029 | critical | 10.0 | 1 | Firmware Vulnerability |
| 882 | Lack of access controls on an API used in customer onboarding | critical | 10.0 | 1 | Data Breach |
| 883 | Publicly exposed cloud buckets with critical vulnerabilities and highly privileged data | critical | 10.0 | 1 | Data Exposure |
| 884 | token-based publishing model | critical | 10.0 | 1 | supply chain attack |
| 885 | Known vulnerability in the network | critical | 10.0 | 1 | Ransomware Attack |
| 886 | CVE-2025-26512 | critical | 10.0 | 1 | Privilege Escalation |
| 887 | CVE-2025-49157 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 888 | Unchecked external input in workflow scripts | critical | 10.0 | 1 | Supply Chain Attack |
| 889 | CVE-2025-27363 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 890 | AI-Enabled Attacks (industrial scale) | critical | 10.0 | 1 | Cyberattack |
| 891 | Exposed Boot Guard private keys | critical | 10.0 | 1 | Security Breach |
| 892 | CVE-2025-47953 (Microsoft Office Heap-Based Buffer Overflow) | critical | 10.0 | 1 | Patch Release |
| 893 | IT-OT convergence risks | critical | 10.0 | 1 | Ransomware |
| 894 | CVE-2026-22719 (CWE-77 - Command Injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 895 | Default or Weak ESXi Authentication Mechanisms | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 896 | Microsoft Hyper-V virtualization | critical | 10.0 | 1 | Cyber Espionage |
| 897 | Vulnerabilities in interconnected operational systems | critical | 10.0 | 1 | Cyberattack |
| 898 | CVE-2025-43200 | critical | 10.0 | 1 | Spyware |
| 899 | Legacy protocols misconfigurations | critical | 10.0 | 1 | Exposed Servers |
| 900 | Stolen personal data (Social Security numbers, birthdates, account credentials) | critical | 10.0 | 1 | Data Breach, Identity Fraud, Account Takeover |
| 901 | Insufficient Real-Time Monitoring | critical | 10.0 | 1 | Insider Threat |
| 902 | Mobile device and app security weaknesses | critical | 10.0 | 1 | Cyber Espionage |
| 903 | AI integrations with applications (e.g., Google Calendar, Zoom) | critical | 10.0 | 1 | AI Exploitation |
| 904 | Unsecured Email Channels | critical | 10.0 | 1 | Data Breach (General Discussion) |
| 905 | High-risk extension permissions | critical | 10.0 | 1 | Session Hijacking |
| 906 | Architectural flaws in perimeter defenses, lack of segmentation and monitoring | critical | 10.0 | 1 | Data Breach |
| 907 | aging infrastructure | critical | 10.0 | 1 | ransomware |
| 908 | Flawed ChaCha20-IETF encryption routine (discarding nonces) | critical | 10.0 | 1 | Ransomware (Data Wiper) |
| 909 | CVE-2024-3721 | critical | 10.0 | 1 | Malware |
| 910 | CVE-2025-24893 (Critical RCE in XWiki) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 911 | Visual Studio Code extension compromise | critical | 10.0 | 1 | ransomware |
| 912 | Orion Software Vulnerability | critical | 10.0 | 1 | Software Exploitation |
| 913 | Stolen Private Key | critical | 10.0 | 1 | Cryptocurrency Theft |
| 914 | CVE-2025-61882 (CVSS 9.8) - Oracle E-Business Suite Concurrent Processing Component | critical | 10.0 | 1 | Data Breach |
| 915 | CVE-2022-37055 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 916 | Misconfigured firewalls | critical | 10.0 | 1 | APT Attack |
| 917 | BYOD Environments | critical | 10.0 | 1 | Data Theft Extortion |
| 918 | Legitimate Windows driver *truesight.sys* (Adlice Software’s RogueKiller) with IOCTL command abuse | critical | 10.0 | 1 | ransomware |
| 919 | Unencrypted Linux Partition in Dual-Boot Configuration | critical | 10.0 | 1 | Vulnerability Exploitation |
| 920 | BootROM keys extraction | critical | 10.0 | 1 | Data Breach / Unauthorized Access |
| 921 | OWASSRF | critical | 10.0 | 1 | Ransomware Attack |
| 922 | Typosquatting | critical | 10.0 | 1 | Cyber Theft |
| 923 | Typosquatted dependency (easy-day-js) with weaponized postinstall hook | critical | 10.0 | 1 | Supply Chain Attack |
| 924 | Software Infrastructure Vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 925 | CVE-2026-20127 (CVSS 10.0) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 926 | Network | critical | 10.0 | 1 | Data Breach |
| 927 | Hardcoded cryptographic keys in Unitree’s G1 humanoid | critical | 10.0 | 1 | Privacy Breach |
| 928 | Embedded credentials/API keys in source code | critical | 10.0 | 1 | Supply Chain Compromise |
| 929 | CVE-2025-32434 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 930 | Systemic weaknesses in U.S. federal cybersecurity posture | critical | 10.0 | 1 | Cyber Espionage |
| 931 | CVE-2025-3935 | critical | 10.0 | 1 | Cyberattack |
| 932 | Absence of Automated Data Loss Prevention (DLP) Tools | critical | 10.0 | 1 | Data Breach |
| 933 | AIS protocol lack of authentication | critical | 10.0 | 1 | spoofing |
| 934 | Legacy Protocols (NTLM Enabled for Backward Compatibility) | critical | 10.0 | 1 | Data Breach |
| 935 | Inadequate HR and Compliance Monitoring | critical | 10.0 | 1 | Data Breach |
| 936 | Improperly exposed backend function (Convex framework's `downloads: increment` configured as public mutation) | critical | 10.0 | 1 | Supply-Chain Attack |
| 937 | Delayed access revocation for terminated employees | critical | 10.0 | 1 | Data Breach, Unauthorized Access, Data Deletion |
| 938 | Insecure Build Process | critical | 10.0 | 1 | Supply Chain Attack |
| 939 | Unpatched vulnerabilities in internet-facing applications | critical | 10.0 | 1 | Data Breach |
| 940 | Inadequate Training | critical | 10.0 | 1 | Data Breach |
| 941 | Weak administrator access controls | critical | 10.0 | 1 | Data Breach |
| 942 | Adversarial AI Tactics Against Defensive Models (ENISA 2025) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 943 | Lack of Third-Party Supplier Accountability | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 944 | Inconsistent authentication | critical | 10.0 | 1 | Data Breach |
| 945 | External content blocking bypass via CSS var() manipulation | critical | 10.0 | 1 | SQL Injection |
| 946 | limited financial resources for cybersecurity investments | critical | 10.0 | 1 | ransomware |
| 947 | CVE-2026-41940 | critical | 10.0 | 1 | Ransomware |
| 948 | Absence of MFA on Congruity’s virtual machines | critical | 10.0 | 1 | Ransomware |
| 949 | Customer misconfigurations (not AWS vulnerabilities) | critical | 10.0 | 1 | Cyber Espionage, Lateral Movement, Credential Harvesting |
| 950 | Systemic weaknesses in government cybersecurity | critical | 10.0 | 1 | Unauthorized Access |
| 951 | Misconfigured OIDC trust relationships | critical | 10.0 | 1 | Supply-Chain Attack |
| 952 | Weak login credentials | critical | 10.0 | 1 | Data Breach |
| 953 | CVE-2026-35616 (Fortinet flaw) | critical | 10.0 | 1 | Botnet, Cyber Espionage |
| 954 | Unauthorized access to sensitive databases, insecure data handling | critical | 10.0 | 1 | Data Breach |
| 955 | Improper Pointer Nullification | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 956 | CVE-2026-5174 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 957 | CVE-2025-14733 (Out-of-bounds write in iked process) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 958 | Azure Key Vault Compromise | critical | 10.0 | 1 | Data Exfiltration |
| 959 | Malicious Word documents | critical | 10.0 | 1 | Security Breach |
| 960 | AI-enabled attack vectors | critical | 10.0 | 1 | ransomware |
| 961 | macOS Backdoor | critical | 10.0 | 1 | State-Backed Surveillance & Hacking |
| 962 | Human Trust (Fake CAPTCHA Social Engineering) | critical | 10.0 | 1 | Social Engineering |
| 963 | Poor Access Controls (Lack of Tiered Admin Account Model) | critical | 10.0 | 1 | Data Breach |
| 964 | third-party ecosystem dependencies | critical | 10.0 | 1 | ransomware |
| 965 | Legacy Authentication Protocols (e.g., SAMLjacking) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 966 | Weak Cybersecurity Safeguards in Government Systems | critical | 10.0 | 1 | Data Privacy Violation |
| 967 | CVE-2026-24789 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 968 | GreenPlasma (Windows zero-day) | critical | 10.0 | 1 | Zero-day Exploit |
| 969 | CVE-2020-12812 | critical | 10.0 | 1 | Ransomware |
| 970 | Lack of Browser-Specific Security Controls | critical | 10.0 | 1 | Browser-Based Attack |
| 971 | CVE-2023-46604 (Apache ActiveMQ) | critical | 10.0 | 1 | Ransomware |
| 972 | Open USB ports | critical | 10.0 | 1 | APT Attack |
| 973 | CVE-2024-21887 (Ivanti Connect Secure) | critical | 10.0 | 1 | ransomware |
| 974 | Aging hardware | critical | 10.0 | 1 | Hardware Malfunction |
| 975 | Lack of IT/OT Security Maturity (65% misalignment with NIST CSF 2.0) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 976 | exploitation of maritime regulatory gaps | critical | 10.0 | 1 | AIS spoofing |
| 977 | over-reliance on vendors | critical | 10.0 | 1 | data breach |
| 978 | Adreno GPU Driver Vulnerabilities | critical | 10.0 | 1 | Vulnerability |
| 979 | unsecured GenAI prompts | critical | 10.0 | 1 | ransomware |
| 980 | Unspecified CVEs identified via Shodan/Censys scans | critical | 10.0 | 1 | Research Study |
| 981 | CVE-2024-20353 | critical | 10.0 | 1 | Zero-Day Exploit |
| 982 | CVE-2023-35082 | critical | 10.0 | 1 | Ransomware |
| 983 | Potential Weak MFA Implementation (2FA Prompt Bombing) | critical | 10.0 | 1 | Insider Threat (Attempted) |
| 984 | CVE-2025-21590 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 985 | CVE-2025-1055 | critical | 10.0 | 1 | Ransomware |
| 986 | SonicWall VPN RCE | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 987 | Previously unknown software vulnerability in network infrastructure | critical | 10.0 | 1 | Data Breach |
| 988 | Poor Training on Data Protection Protocols | critical | 10.0 | 1 | Data Breach |
| 989 | CVE-2025-32975 | critical | 10.0 | 1 | Authentication Bypass |
| 990 | CVE-2025-20363 (Cisco ASA VPN) | critical | 10.0 | 1 | Ransomware |
| 991 | Unsupervised automation | critical | 10.0 | 1 | AI-driven breach |
| 992 | Microsoft SharePoint Server Vulnerabilities (On-Premises) | critical | 10.0 | 1 | Data Breach |
| 993 | Vulnerable internet routers | critical | 10.0 | 1 | Cyber Espionage |
| 994 | Lack of User Awareness for Non-Email Threats | critical | 10.0 | 1 | Social Engineering |
| 995 | Legitimate Administrative Tools (ScreenConnect, AnyDesk, RMM Platforms) | critical | 10.0 | 1 | Social Engineering |
| 996 | Over-reliance on server-side WAFs/IDS for client-side threats | critical | 10.0 | 1 | Data Breach |
| 997 | Unpatched edge devices | critical | 10.0 | 1 | Cyber Espionage |
| 998 | High-severity software flaws (Mythos AI) | critical | 10.0 | 1 | AI-driven vulnerability exploitation |
| 999 | CVE-2026-20079 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1000 | Cloud management tools | critical | 10.0 | 1 | Ransomware |
| 1001 | Unsupported hardware | critical | 10.0 | 1 | Cyberattack |
| 1002 | Unspecified vulnerability in MOVEit file transfer platform (known to CL0P) | critical | 10.0 | 1 | Data Breach |
| 1003 | Low Digital Literacy in Business Software | critical | 10.0 | 1 | Ransomware Attack |
| 1004 | CVE-2026-24423 | critical | 10.0 | 1 | Ransomware |
| 1005 | Lack of IP Restrictions on Tokens | critical | 10.0 | 1 | Supply Chain Attack |
| 1006 | Open Redirect | critical | 10.0 | 1 | Redirect Attack |
| 1007 | CVE-2026-32746 (Buffer Overflow - CWE-120) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1008 | Misconfigured RDP ports | critical | 10.0 | 1 | Espionage |
| 1009 | Code block display bug (hiding malicious instructions) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1010 | Fortinet VPN vulnerabilities | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 1011 | Windows Safe Mode vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1012 | Mapped Network Drives | critical | 10.0 | 1 | Data Theft Extortion |
| 1013 | Progress Software's MOVEit Transfer vulnerability | critical | 10.0 | 1 | ransomware |
| 1014 | enterprise software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1015 | Unspecified vulnerability in third-party call center platform (linked to Salesforce customer management instances) | critical | 10.0 | 1 | Data Breach |
| 1016 | misconfigured multi-factor authentication (MFA) | critical | 10.0 | 1 | ransomware |
| 1017 | Legacy Authentication Protocols | critical | 10.0 | 1 | Social Engineering |
| 1018 | Exposed Firewall Configuration Backups (Encrypted but Sensitive) | critical | 10.0 | 1 | Unauthorized Access |
| 1019 | Unpatched flaw in a popular enterprise software platform | critical | 10.0 | 1 | Cyberattack |
| 1020 | CVE-2021-36942 (PetitPotam - Windows LSA Spoofing) | critical | 10.0 | 1 | Cyber Espionage |
| 1021 | Undisclosed (stolen vulnerability data) | critical | 10.0 | 1 | Data Breach |
| 1022 | Flaw in SecondFi’s native Cardano web wallet generation software | critical | 10.0 | 1 | Exploit |
| 1023 | zero-day vulnerability in Oracle EBusiness Suite | critical | 10.0 | 1 | data breach |
| 1024 | Service Accounts with Non-Expiring Passwords & Excessive Permissions | critical | 10.0 | 1 | Data Breach |
| 1025 | CVE-2017-0144 (EternalBlue) | critical | 10.0 | 1 | Ransomware |
| 1026 | Poorly Secured OT Systems (e.g., MV Dali electrical blackout) | critical | 10.0 | 1 | Ransomware |
| 1027 | CVE-2026-4681 (CWE-94) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1028 | CVE-2023-23397 | critical | 10.0 | 1 | Cyberespionage |
| 1029 | SimpleHelp RMM flaws | critical | 10.0 | 1 | Ransomware |
| 1030 | LogoFAIL flaws (CVE-2023-40238) | critical | 10.0 | 1 | UEFI Bootkit |
| 1031 | CVE-2025-48595 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1032 | CVE-2024-48248 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1033 | AnyDesk Remote Access Application | critical | 10.0 | 1 | Data Exfiltration |
| 1034 | Potential Weak Authentication (if credentials were shared) | critical | 10.0 | 1 | Insider Threat |
| 1035 | CVE-2025-25181 | critical | 10.0 | 1 | Security Breach |
| 1036 | AI supply chain threats (e.g., LangFlow RCE) | critical | 10.0 | 1 | Malware Framework |
| 1037 | lack of cyber-physical resilience in maritime navigation systems | critical | 10.0 | 1 | cyber deception |
| 1038 | Weak password policy (single compromised password) | critical | 10.0 | 1 | Ransomware |
| 1039 | SSO Misconfigurations (e.g., Microsoft Entra, Google Workspace, Okta) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1040 | CVE-2024-21182 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1041 | WhatsApp Artifact Exfiltration | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 1042 | Dependence on unencrypted GPS signals for navigation and communication | critical | 10.0 | 1 | GPS jamming |
| 1043 | Misconfigured Azure RBAC permissions | critical | 10.0 | 1 | Data Exfiltration |
| 1044 | Lack of access controls (broad permissions) | critical | 10.0 | 1 | Ransomware |
| 1045 | Compromised Subcontractor Credentials | critical | 10.0 | 1 | Data Breach |
| 1046 | CISA Known Exploited Vulnerabilities (unspecified) | critical | 10.0 | 1 | Cyber Espionage, Critical Infrastructure Attack |
| 1047 | Stolen Credentials (Infostealer Malware) | critical | 10.0 | 1 | Supply Chain Attack |
| 1048 | CVE-2024-37085 (Cisco) | critical | 10.0 | 1 | ransomware |
| 1049 | CVE-2026-3854 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1050 | CVE-2025-12556 (Improper input validation in ICM Viewer’s WebSocket communication) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1051 | CVE-2025-5086 (Deserialization of Untrusted Data) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1052 | outdated property assessment funding | critical | 10.0 | 1 | physical security breach |
| 1053 | Incorrect mailing of care management letters | critical | 10.0 | 1 | Data Breach |
| 1054 | Unsafe dynamic code generation in `Type.generateConstructor` (CVE not assigned, GHSA-xq3m-2v4x-88gg) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1055 | Over-Reliance on Email-Based Security Controls | critical | 10.0 | 1 | Social Engineering |
| 1056 | CVE-2024-12356 | critical | 10.0 | 1 | Breach |
| 1057 | Microsoft Phone Link (formerly 'Your Phone') SQLite database access | critical | 10.0 | 1 | Cyberattack |
| 1058 | CVE-2025-10035 (Critical deserialization flaw in GoAnywhere MFT) | critical | 10.0 | 1 | Zero-day exploitation |
| 1059 | Identity and Access Control Weaknesses | critical | 10.0 | 1 | Data Breach |
| 1060 | BDU:2025-10115 (CVSS 7.5) - Arbitrary file read | critical | 10.0 | 1 | Cyber Espionage |
| 1061 | Exposed Credentials in Repositories | critical | 10.0 | 1 | Data Breach |
| 1062 | CVE-2024-40766 (SonicWall) | critical | 10.0 | 1 | ransomware |
| 1063 | ADRecon for Active Directory mapping | critical | 10.0 | 1 | ransomware |
| 1064 | Cellebrite Software Exploitation | critical | 10.0 | 1 | State-Backed Surveillance & Hacking |
| 1065 | publicly exposed personal data (e.g., YouTube videos) | critical | 10.0 | 1 | cyber espionage |
| 1066 | Critical CVSS-rated vulnerabilities in legacy and new ICS devices | critical | 10.0 | 1 | Exposure of Critical Infrastructure |
| 1067 | Lack of IP restrictions | critical | 10.0 | 1 | Data Breach |
| 1068 | Poor Email Security Practices | critical | 10.0 | 1 | Data Breach |
| 1069 | CVE-2024-12856 | critical | 10.0 | 1 | DDoS |
| 1070 | 200+ vulnerabilities in CISA’s KEV catalog (2024–2025) | critical | 10.0 | 1 | ransomware |
| 1071 | Jira | critical | 10.0 | 1 | Data Leak |
| 1072 | Weak Authentication for Third-Party Access | critical | 10.0 | 1 | Cyberattack |
| 1073 | disabled antivirus processes | critical | 10.0 | 1 | ransomware |
| 1074 | HTML/CSS injection in draft restore dialog’s subject field | critical | 10.0 | 1 | SQL Injection |
| 1075 | Understaffed security operations | critical | 10.0 | 1 | Data Breach |
| 1076 | CVE-2025-5309 | critical | 10.0 | 1 | Remote Code Execution |
| 1077 | CVE-2022-26134 (Atlassian OGNL Injection) | critical | 10.0 | 1 | cyberespionage |
| 1078 | CVE-2025-61882 (Oracle E-Business Suite - Unauthenticated RCE) | critical | 10.0 | 1 | Data Breach |
| 1079 | CVE-2025-22226 | critical | 10.0 | 1 | Ransomware |
| 1080 | Shadow AI (unauthorized generative AI tools) | critical | 10.0 | 1 | Ransomware |
| 1081 | Data Scraping Vulnerability | critical | 10.0 | 1 | Data Breach |
| 1082 | MiniPlasma (Windows zero-day) | critical | 10.0 | 1 | Zero-day Exploit |
| 1083 | CVE-2018-5999 | critical | 10.0 | 1 | Botnet Exploitation |
| 1084 | CVE-2025-32433 | critical | 10.0 | 1 | Ransomware |
| 1085 | CVE-2026-33825 (CVSS 7.8, High) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1086 | Poor password hygiene, lack of multi-factor authentication, unsecured third-party services | critical | 10.0 | 1 | Credential Compromise |
| 1087 | Disabled Logging | critical | 10.0 | 1 | Data Exposure |
| 1088 | Overcollection of Personal Data | critical | 10.0 | 1 | Data Privacy Violation |
| 1089 | Vect Ransomware Bug | critical | 10.0 | 1 | Data Breach |
| 1090 | Budget Constraints | critical | 10.0 | 1 | Operational Risk |
| 1091 | Unknown (potentially misconfigurations or zero-day flaws) | critical | 10.0 | 1 | Data Breach |
| 1092 | Exposed management ports, weak authentication | critical | 10.0 | 1 | Cyber Attack |
| 1093 | Pool initialization bypass | critical | 10.0 | 1 | Exploit |
| 1094 | CVE-2024-40766 (SonicWall improper access control, CVSS 9.8) | critical | 10.0 | 1 | ransomware |
| 1095 | Lack of Real-Time Identity Data Sync | critical | 10.0 | 1 | Identity Security Crisis |
| 1096 | CVE-2024-57968 | critical | 10.0 | 1 | Security Breach |
| 1097 | Trust in fraudulent bank certificates | critical | 10.0 | 1 | Identity Fraud |
| 1098 | Trust in Employee | critical | 10.0 | 1 | Insider Threat |
| 1099 | Data encryption software vulnerability | critical | 10.0 | 1 | Data Breach |
| 1100 | LOLDrivers (Living Off The Land Drivers) - 'truesight.sys' from RogueKiller AntiRootkit | critical | 10.0 | 1 | ransomware |
| 1101 | Security flaw in MOVEit software | critical | 10.0 | 1 | Data Breach |
| 1102 | Lack of security monitoring | critical | 10.0 | 1 | Cyberattack |
| 1103 | OS auto-enumeration of mice on Windows 11 and macOS Sonoma, lack of HID trust models | critical | 10.0 | 1 | Hardware-based Attack |
| 1104 | CVE-2026-21962 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1105 | CVE-2026-8181 | critical | 10.0 | 1 | Authentication Bypass |
| 1106 | CWE-426 (Untrusted APT Source Path) | critical | 10.0 | 1 | Privilege Escalation |
| 1107 | Weak perimeter defenses, inadequate network segmentation | critical | 10.0 | 1 | Ransomware |
| 1108 | CVE-2025-34067 (Hikvision - remote code execution) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 1109 | metadata retention in files | critical | 10.0 | 1 | data breach |
| 1110 | Unrestricted Access Controls | critical | 10.0 | 1 | Ransomware |
| 1111 | GPS-based navigation and landing systems | critical | 10.0 | 1 | cyber attack |
| 1112 | Insufficient Privileged Access Controls (e.g., standing admin roles) | critical | 10.0 | 1 | Social Engineering |
| 1113 | CVE-2026-20190 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1114 | CVE-2021-36260 (Hikvision - command injection) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 1115 | CVE-2026-25084 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1116 | CVE-2025-0289 in BioNTdrv.sys driver | critical | 10.0 | 1 | Ransomware |
| 1117 | Protection insuffisante des terminaux | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1118 | CVE-2026-0229 | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 1119 | inadequate security of payment systems | critical | 10.0 | 1 | data breach |
| 1120 | human error (accidental download of malware-laced system administration tool) | critical | 10.0 | 1 | ransomware |
| 1121 | Legitimate drivers | critical | 10.0 | 1 | Ransomware |
| 1122 | Hidden preinstall scripts | critical | 10.0 | 1 | Supply Chain Attack |
| 1123 | Lack of a business associate agreement | critical | 10.0 | 1 | Ransomware Attack |
| 1124 | Weak Password Security (hypothetical, based on context) | critical | 10.0 | 1 | Ransomware Attack |
| 1125 | lack of managed GenAI tools | critical | 10.0 | 1 | ransomware |
| 1126 | Java Vulnerability | critical | 10.0 | 1 | Data Breach |
| 1127 | Unique validation node | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1128 | Non-password-protected database | critical | 10.0 | 1 | Data Breach |
| 1129 | Unsecured GitHub Personal Access Tokens (PATs) | critical | 10.0 | 1 | Supply-Chain Attack |
| 1130 | Lack of Multi-Factor Authentication (2FA) for OAuth Apps | critical | 10.0 | 1 | Data Breach |
| 1131 | Open Academic Networks in Universities | critical | 10.0 | 1 | Data Breach |
| 1132 | Zero-day vulnerabilities (42% weaponized before public disclosure) | critical | 10.0 | 1 | AI-driven cyber threats |
| 1133 | Poor Credential Hygiene (GitHub Repository) | critical | 10.0 | 1 | Data Breach |
| 1134 | CVE-2025-7028 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1135 | Supply chain compromise | critical | 10.0 | 1 | Supply Chain Attack |
| 1136 | Weak/reused passwords, coding flaw in 'DNA Relatives' feature | critical | 10.0 | 1 | Data Breach |
| 1137 | CVE-2026-34197 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1138 | Kernel-level hooks in EDR products (28+ vendors targeted) | critical | 10.0 | 1 | Ransomware |
| 1139 | IMSI-capturing | critical | 10.0 | 1 | Surveillance |
| 1140 | potential prior SharePoint vulnerabilities (historical context for Storm-2603) | critical | 10.0 | 1 | ransomware |
| 1141 | Weak Password Hashing (Early Breaches like LinkedIn 2012) | critical | 10.0 | 1 | Data Breach |
| 1142 | CVE-2023-48788 (Fortinet EMS SQL injection) | critical | 10.0 | 1 | Ransomware |
| 1143 | weak credential management (golden ticket risk) | critical | 10.0 | 1 | ransomware |
| 1144 | CVE-2022-42475 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 1145 | Previously unknown vulnerability in firewall software | critical | 10.0 | 1 | Ransomware Attack |
| 1146 | Trustwave’s miscategorization of breach alert as 'moderate' (delayed response) | critical | 10.0 | 1 | Ransomware |
| 1147 | Lack of Employee Cybersecurity Training | critical | 10.0 | 1 | Ransomware |
| 1148 | Unsecured MSSQL Database | critical | 10.0 | 1 | Data Breach |
| 1149 | CVE-2026-28318 (Uncontrolled Resource Consumption, CWE-400) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 1150 | Outdated software in critical sectors (hospitals, governments) | critical | 10.0 | 1 | Extortion |
| 1151 | Inadequate access controls for sensitive spreadsheets | critical | 10.0 | 1 | Data Breach |
| 1152 | Insufficient Workforce Training (phishing/social engineering) | critical | 10.0 | 1 | Ransomware |
| 1153 | Unmonitored API Traffic | critical | 10.0 | 1 | Data Breach |
| 1154 | Unsalted Password Hashes (pre-remediation) | critical | 10.0 | 1 | Data Breach |
| 1155 | upstream services | critical | 10.0 | 1 | ransomware |
| 1156 | Zero-day flaw in Oracle E-Business Suite | critical | 10.0 | 1 | Data Breach |
| 1157 | Follina | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1158 | Improper input validation in Gogs codebase | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1159 | Third-party library bug in Google Chrome | critical | 10.0 | 1 | Zero-Day Exploit |
| 1160 | Vulnerable signed drivers (exploited via BYOVD) | critical | 10.0 | 1 | Ransomware |
| 1161 | Lack of Code Integrity Checks | critical | 10.0 | 1 | Supply Chain Attack |
| 1162 | Geopolitical Tensions (NATO Expansion, Ukraine War) | critical | 10.0 | 1 | Physical Sabotage |
| 1163 | SAP Solution Manager | critical | 10.0 | 1 | Cyber Espionage |
| 1164 | Weaknesses in satellite-ground station security | critical | 10.0 | 1 | Cyber-Physical Threat |
| 1165 | Citrix VPN vulnerabilities | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 1166 | CVE-2025-10035 (Critical, CVSS 10.0) - Deserialization in License Servlet of GoAnywhere MFT | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1167 | Fortinet FortiGate appliances | critical | 10.0 | 1 | AI-driven cyberattack tool |
| 1168 | RedSun | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1169 | CVE-2025-20393 | critical | 10.0 | 1 | Cyberattack |
| 1170 | CVE-2026-21643 | critical | 10.0 | 1 | SQL Injection |
| 1171 | CVE-2025-70994 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1172 | CVE-2026-6875 | critical | 10.0 | 1 | Sandbox Escape |
| 1173 | Poor detection of abnormal system activity | critical | 10.0 | 1 | Data Breach |
| 1174 | unpatched/end-of-life devices | critical | 10.0 | 1 | unauthorized access |
| 1175 | Employee downloaded malware from untrusted source | critical | 10.0 | 1 | Ransomware Attack |
| 1176 | Known vulnerabilities dating back to 2018 | critical | 10.0 | 1 | Espionage |
| 1177 | Digitized supply chains | critical | 10.0 | 1 | Cyberattack |
| 1178 | Unpatched linked servers | critical | 10.0 | 1 | Ransomware |
| 1179 | Atlassian Confluence | critical | 10.0 | 1 | Cyberattack (Reconnaissance Campaign) |
| 1180 | Over-reliance on remote desktop tools without geofencing | critical | 10.0 | 1 | Espionage |
| 1181 | CVE-2026-40369 | critical | 10.0 | 1 | Privilege Escalation |
| 1182 | CVE-2023-3596 | critical | 10.0 | 1 | Cyber Espionage |
| 1183 | Unpatched VPN services | critical | 10.0 | 1 | Ransomware |
| 1184 | Tool disparities | critical | 10.0 | 1 | Ransomware Prediction |
| 1185 | Lack of Fragment Inspection in Security Tools | critical | 10.0 | 1 | Prompt Injection |
| 1186 | Zero-Day in Network Appliances (e.g., VMware vCenter, ESXi) | critical | 10.0 | 1 | Espionage |
| 1187 | SmarterMail | critical | 10.0 | 1 | Ransomware |
| 1188 | Compromised private key controlling minting approvals | critical | 10.0 | 1 | Stablecoin Exploit |
| 1189 | Improper authorization/callback handling in V2 vaults | critical | 10.0 | 1 | Exploit |
| 1190 | CVE-2026-55116 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1191 | Zero-Day Vulnerabilities (1 new CVE every 17 minutes) | critical | 10.0 | 1 | Ransomware |
| 1192 | Outdated legacy systems | critical | 10.0 | 1 | Cyberattack |
| 1193 | Public-Key Cryptography (e.g., RSA, ECC) | critical | 10.0 | 1 | Emerging Threat |
| 1194 | Vulnerabilities in Change Healthcare’s IT infrastructure | critical | 10.0 | 1 | Ransomware |
| 1195 | Ghost Logins (Unmonitored Active Sessions) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1196 | Prompt Injection (indirect) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1197 | CVE-2024-21887 (Ivanti Connect Secure/Policy Secure) | critical | 10.0 | 1 | Ransomware |
| 1198 | lack of AIS authentication mechanisms | critical | 10.0 | 1 | sabotage |
| 1199 | Unknown vulnerability in Microsoft SharePoint servers | critical | 10.0 | 1 | Cyber Espionage |
| 1200 | Weak Data Integrity Checks | critical | 10.0 | 1 | Supply Chain Attack |
| 1201 | CVE-2025-59468 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1202 | CVE-2025-53770 (Deserialization of untrusted data in SharePoint Server) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1203 | Misconfigured or stolen OAuth tokens, insufficient monitoring of API access logs | critical | 10.0 | 1 | Supply Chain Attack |
| 1204 | Weak Supplier Security Controls | critical | 10.0 | 1 | Ransomware |
| 1205 | Overprivileged identities | critical | 10.0 | 1 | Cloud Infrastructure Compromise |
| 1206 | MongoBleed | critical | 10.0 | 1 | Data Breach |
| 1207 | REST API endpoints | critical | 10.0 | 1 | Data Breach |
| 1208 | Inadequate penetration testing | critical | 10.0 | 1 | Data Breach |
| 1209 | Shared login credentials | critical | 10.0 | 1 | Data Breach |
| 1210 | Permanent URL Accessibility | critical | 10.0 | 1 | Data Leak |
| 1211 | Misconfigured document delivery platform | critical | 10.0 | 1 | Data Breach |
| 1212 | CVE-2026-34976 (Missing authorization check in restoreTenant command) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1213 | Vulnerability in the online payment system | critical | 10.0 | 1 | Data Breach |
| 1214 | Generative AI applications | critical | 10.0 | 1 | ransomware |
| 1215 | Influence of Radical Literature | critical | 10.0 | 1 | Domestic Terrorism |
| 1216 | GPS signal weakness | critical | 10.0 | 1 | spoofing |
| 1217 | CVE-2025-27821 (Out-of-bounds write in HDFS native client) | critical | 10.0 | 1 | Vulnerability |
| 1218 | VPN vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1219 | Password reminder bug | critical | 10.0 | 1 | Account Takeover |
| 1220 | Database Injection | critical | 10.0 | 1 | Website Defacement |
| 1221 | Dual-use technology misuse | critical | 10.0 | 1 | Policy Violation and Dual-Use Technology Misuse |
| 1222 | Security Incident During Server Setup | critical | 10.0 | 1 | Ransomware |
| 1223 | Palo Alto vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1224 | Cryptographic flaw in ChaCha20-IETF cipher implementation (nonce overwriting) | critical | 10.0 | 1 | Ransomware (Data Wiper) |
| 1225 | Unauthorized remote access, ATM jackpotting, Point-of-sale data compromise | critical | 10.0 | 1 | Cyber Attack |
| 1226 | Social Engineering, Impersonation | critical | 10.0 | 1 | Phishing, Cyber Espionage |
| 1227 | CVE-2017-11882 (Microsoft Office) | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 1228 | remote management tool abuse | critical | 10.0 | 1 | ransomware |
| 1229 | SQL injection vulnerability in Navy-SWM database | critical | 10.0 | 1 | data breach |
| 1230 | insufficient AI governance | critical | 10.0 | 1 | ransomware |
| 1231 | Tool sprawl and visibility gaps | critical | 10.0 | 1 | Data Breach |
| 1232 | CVE-2021-39935 (CWE-918) | critical | 10.0 | 1 | Server-Side Request Forgery (SSRF) |
| 1233 | Weak multi-factor authentication (MFA) | critical | 10.0 | 1 | AI-driven vulnerability exploitation |
| 1234 | Architectural flaw in Model Context Protocol (MCP) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1235 | CVE-2024-* (Buffer manipulation in NTFS disk image handling) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1236 | Inadequate cybersecurity training for non-IT staff | critical | 10.0 | 1 | Ransomware |
| 1237 | Disconnected IAM Systems | critical | 10.0 | 1 | Predictive Analysis |
| 1238 | CNAME DNS record | critical | 10.0 | 1 | Data Breach |
| 1239 | Insufficient Vetting of Remote IT Workers | critical | 10.0 | 1 | Cyber Theft |
| 1240 | Off-by-one error in encryption process | critical | 10.0 | 1 | Ransomware |
| 1241 | Abuse of legitimate browser permissions (File System Access API) | critical | 10.0 | 1 | Ransomware |
| 1242 | user trust in search engine ads | critical | 10.0 | 1 | ransomware |
| 1243 | CVE-2025-64111 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1244 | Critical API security vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 1245 | Insufficient Access Management | critical | 10.0 | 1 | Data Breach |
| 1246 | Unmanaged machine identities | critical | 10.0 | 1 | Ransomware |
| 1247 | Vulnerable drivers (BYOVD), misused legitimate software, obfuscation techniques (VX Crypt, VMProtect, control-flow flattening) | critical | 10.0 | 1 | Ransomware |
| 1248 | CVE-2025-27507 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1249 | CVE-2025-49155 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1250 | Opportunistic TLS | critical | 10.0 | 1 | Cross-protocol Application Layer Desynchronization |
| 1251 | Weak Insider Controls | critical | 10.0 | 1 | Data Breach |
| 1252 | Unsecured Network Servers | critical | 10.0 | 1 | Cybersecurity Incident |
| 1253 | virtualized environment exploits | critical | 10.0 | 1 | ransomware |
| 1254 | Trust in Professional Networking Platforms | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1255 | outdated IT infrastructure | critical | 10.0 | 1 | data breach |
| 1256 | Cached Administrative Credentials in Workstation Memory | critical | 10.0 | 1 | Data Breach |
| 1257 | Fragmented Security Posture (On-Premises vs. Cloud Visibility Gaps) | critical | 10.0 | 1 | Data Breach |
| 1258 | Weak Authentication for Publish Access (npm, PyPI) | critical | 10.0 | 1 | Supply Chain Attack |
| 1259 | Unknown vulnerability in the *Safe Smart Port (PIS)* platform | critical | 10.0 | 1 | Data Breach |
| 1260 | ATM Skimming Devices | critical | 10.0 | 1 | ATM Skimming |
| 1261 | CVE-2026-41050 | critical | 10.0 | 1 | Privilege Escalation |
| 1262 | Account-specific vulnerability | critical | 10.0 | 1 | Data Breach |
| 1263 | shadow IT (unapproved third-party tool integrations) | critical | 10.0 | 1 | third-party breach |
| 1264 | Improper escaping of LangChain’s internal marker key during serialization | critical | 10.0 | 1 | Serialization/Deserialization Injection |
| 1265 | Microsoft Exchange Server flaw | critical | 10.0 | 1 | Zero-day Exploit |
| 1266 | Remote code execution vulnerability in SharePoint’s authentication mechanism | critical | 10.0 | 1 | Cyberattack |
| 1267 | Invalid cast vulnerability in .NET Framework serialization processes | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1268 | Unlimited token allowances | critical | 10.0 | 1 | Security Breach |
| 1269 | Outdated accounting infrastructure | critical | 10.0 | 1 | Ransomware |
| 1270 | CVE-2026-42210 / CVE-2026-56022 | critical | 10.0 | 1 | XSS |
| 1271 | Lack of 'Two Pairs of Eyes' Review (Pre-November 2021) | critical | 10.0 | 1 | Data Breach |
| 1272 | Internal system vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 1273 | Outdated Juniper Networks Junos OS MX routers | critical | 10.0 | 1 | Cyber Espionage |
| 1274 | inadequate data loss prevention controls | critical | 10.0 | 1 | ransomware |
| 1275 | Abuse of legitimate software (BitDefender, VLC Media Player, Sangfor) | critical | 10.0 | 1 | Cyber Espionage |
| 1276 | Path traversal (CVE-2025-64712) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1277 | Cybersecurity vulnerabilities in Hikvision products | critical | 10.0 | 1 | Ransomware |
| 1278 | Unpatched legacy systems | critical | 10.0 | 1 | Ransomware |
| 1279 | lack of real-time cross-verification of vessel identities | critical | 10.0 | 1 | AIS spoofing |
| 1280 | Known flaw in a widely used healthcare management platform | critical | 10.0 | 1 | Ransomware |
| 1281 | CVE-2026-8711 (Heap Buffer Overflow in NGINX JavaScript) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1282 | NDJSON injection in `inventory_sync` subsystem (CWE-74, CWE-93, CWE-863) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1283 | SQL Injection vulnerabilities in WordPress-powered website | critical | 10.0 | 1 | Data Breach |
| 1284 | CVE-2025-68613 | critical | 10.0 | 1 | Botnet Campaign |
| 1285 | Opportunistic targeting | critical | 10.0 | 1 | Data Breach |
| 1286 | Unpatched vulnerability in TP-Link Archer routers | critical | 10.0 | 1 | Botnet |
| 1287 | CVE-2024-3721 (TBK DVRs) | critical | 10.0 | 1 | Botnet / DDoS Campaign |
| 1288 | Cisco Catalyst SD-WAN vulnerability | critical | 10.0 | 1 | Zero-day Exploit |
| 1289 | Symlink (junction) attack in Nessus Agent for Windows | critical | 10.0 | 1 | Privilege Escalation |
| 1290 | Publicly accessible Elasticsearch database | critical | 10.0 | 1 | Data Exposure |
| 1291 | Exposed Secrets in GitHub Repository | critical | 10.0 | 1 | Data Breach |
| 1292 | Lack of two-factor authentication (2FA) | critical | 10.0 | 1 | Supply Chain Attack |
| 1293 | Zero-Day Vulnerability in Fortra's GoAnywhere MFT | critical | 10.0 | 1 | Data Breach |
| 1294 | Content management system vulnerability | critical | 10.0 | 1 | Data Breach |
| 1295 | Improper input validation in USER environment variable handling | critical | 10.0 | 1 | Authentication Bypass |
| 1296 | Lack of Automated PII Detection | critical | 10.0 | 1 | Data Leak |
| 1297 | Human Vulnerability (Social Engineering via Impersonation) | critical | 10.0 | 1 | Cyber Attack |
| 1298 | Unpatched Microsoft SharePoint Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1299 | Lack of AIS/GPS signal authentication | critical | 10.0 | 1 | GPS spoofing |
| 1300 | CVE-2024-42057 | critical | 10.0 | 1 | Ransomware Attack |
| 1301 | Trust model in open-source ecosystems, self-replicating worm propagation | critical | 10.0 | 1 | Supply Chain Attack |
| 1302 | Unauthorized Access by Employee | critical | 10.0 | 1 | Data Breach |
| 1303 | QR Code Vulnerability | critical | 10.0 | 1 | Espionage |
| 1304 | inadequate third-party access controls | critical | 10.0 | 1 | data breach |
| 1305 | CVE-2026-28289 (bypass of CVE-2026-27636) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1306 | Undetected network vulnerability | critical | 10.0 | 1 | Data Breach |
| 1307 | CVE-2025-15576 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1308 | CVE-2025-54068 (Laravel Livewire v3 improper validation during hydration process) | critical | 10.0 | 1 | Credential Theft |
| 1309 | Insufficient permission checks | critical | 10.0 | 1 | DeFi Exploit |
| 1310 | CVE-2025-23319 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1311 | CVE-2026-22844 (Command Injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1312 | Lack of validation check in ReceiverAxelar contract | critical | 10.0 | 1 | Smart Contract Exploit |
| 1313 | User Registration & Membership WordPress plugin vulnerability | critical | 10.0 | 1 | Authentication Bypass |
| 1314 | Zero-day | critical | 10.0 | 1 | Ransomware |
| 1315 | CVE-2026-21509 (Microsoft Office OLE flaw) | critical | 10.0 | 1 | Cyberespionage |
| 1316 | third-party services and integrations | critical | 10.0 | 1 | ransomware |
| 1317 | CVE-2024-4885 | critical | 10.0 | 1 | Ransomware |
| 1318 | Technical error (premature website publication) | critical | 10.0 | 1 | Data Leak / Unauthorized Disclosure |
| 1319 | Publicly shared GPS data from fitness app | critical | 10.0 | 1 | Data Exposure |
| 1320 | CVE-2026-24512 (Improper handling of `rules.http.paths.path` field in Ingress resources) | critical | 10.0 | 1 | Code Execution Vulnerability |
| 1321 | SonicWall VPN flaws | critical | 10.0 | 1 | ransomware |
| 1322 | Payment system weaknesses | critical | 10.0 | 1 | Data Breach |
| 1323 | high_risk_assessment_ignored | critical | 10.0 | 1 | data_at_risk |
| 1324 | CVE-2024-53676 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1325 | Legitimate features of Signal | critical | 10.0 | 1 | Phishing |
| 1326 | Unmanaged OAuth App Permissions (Salesforce, Other SaaS) | critical | 10.0 | 1 | Browser-Based Attack |
| 1327 | Software flaw in Tesla's systems | critical | 10.0 | 1 | Hacking |
| 1328 | Outdated IT Systems | critical | 10.0 | 1 | Cybercrime |
| 1329 | Misconfigured Cloud Storage (S3, MongoDB) | critical | 10.0 | 1 | Data Breach |
| 1330 | Security holes in Verizon's systems | critical | 10.0 | 1 | Data Breach |
| 1331 | CVE-2025-55182 (CVSS 9.8) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1332 | Vulnerabilities in Synology Network-Attached Storage (NAS) devices | critical | 10.0 | 1 | Ransomware |
| 1333 | Unpatched Systems (Software/Hardware) | critical | 10.0 | 1 | Data Breach |
| 1334 | Over-Privileged Accounts | critical | 10.0 | 1 | Data Breach |
| 1335 | misconfigured AWS S3 bucket permissions | critical | 10.0 | 1 | ransomware |
| 1336 | Compromised Apple ID logins and LinkedIn data | critical | 10.0 | 1 | Data Breach |
| 1337 | CVE-2025-68947 (NsecSoft NSecKrnl driver) | critical | 10.0 | 1 | Ransomware |
| 1338 | Lack of Security Layers | critical | 10.0 | 1 | Ransomware |
| 1339 | Open Amazon S3 bucket | critical | 10.0 | 1 | Data Breach |
| 1340 | Insecure helpdesk protocols | critical | 10.0 | 1 | AI-driven vulnerability exploitation |
| 1341 | CVE-2025-22225 | critical | 10.0 | 1 | Ransomware |
| 1342 | CVE-2026-33660 (Improper input validation, CWE-94: Code Injection) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1343 | Optional MFA (to be phased out) | critical | 10.0 | 1 | Predictive Analysis |
| 1344 | Roundcube and SquirrelMail webmail vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1345 | Inadequate Data Redaction Procedures | critical | 10.0 | 1 | Data Breach |
| 1346 | CVE-2025-2172 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1347 | Fortinet systems | critical | 10.0 | 1 | Ransomware |
| 1348 | CVE-2024-38178 | critical | 10.0 | 1 | Cyber Espionage |
| 1349 | CVE-2025-68615 (Buffer Overflow in snmptrapd) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1350 | NVIDIA NeMo Framework Vulnerabilities | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1351 | Lack of Content Security Policy (CSP) enforcement | critical | 10.0 | 1 | Data Breach |
| 1352 | React2Shell (CVE-2025-55182) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1353 | Microsoft Exchange (unspecified CVEs) | critical | 10.0 | 1 | ransomware |
| 1354 | Lack of OIDC verification, unmatched GitHub commits | critical | 10.0 | 1 | Supply Chain Attack |
| 1355 | LNK file execution | critical | 10.0 | 1 | spear-phishing |
| 1356 | Publicly accessible management interfaces | critical | 10.0 | 1 | Cloud Exploitation Campaign |
| 1357 | underwater sensor network vulnerabilities | critical | 10.0 | 1 | espionage |
| 1358 | Confluence Server Webwork OGNL injection | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1359 | Cloud Misconfigurations (23% of cloud incidents) | critical | 10.0 | 1 | Ransomware |
| 1360 | CVE-2025-25012 | critical | 10.0 | 1 | Vulnerability Exploit |
| 1361 | Software Development and Distribution Processes | critical | 10.0 | 1 | Supply Chain Attack |
| 1362 | unencrypted storage of sensitive data in an internet-accessible environment | critical | 10.0 | 1 | ransomware |
| 1363 | Legacy System Exploits | critical | 10.0 | 1 | Ransomware |
| 1364 | MOVEit Software Vulnerabilities | critical | 10.0 | 1 | Cyber Attack |
| 1365 | lack of up-to-date incident response plans | critical | 10.0 | 1 | cyber attack |
| 1366 | Undisclosed Vulnerabilities in BIG-IP (details not public) | critical | 10.0 | 1 | Data Breach |
| 1367 | YellowKey (Windows zero-day) | critical | 10.0 | 1 | Zero-day Exploit |
| 1368 | CVE-2026-31694 (FUSE directory entry caching flaw) | critical | 10.0 | 1 | Privilege Escalation |
| 1369 | Legacy Operational Technology (OT) systems with known vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1370 | CVE-2026-33112 (SharePoint XmlValidator bypass via external XSD schemas) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1371 | Palo Alto PAN-OS | critical | 10.0 | 1 | Ransomware |
| 1372 | external-facing systems vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1373 | Command execution flaws | critical | 10.0 | 1 | Cyber Attack |
| 1374 | lack of system isolation capabilities | critical | 10.0 | 1 | cyberattack |
| 1375 | CVE-2025-29927 | critical | 10.0 | 1 | worm-driven campaign |
| 1376 | weak RDP credentials | critical | 10.0 | 1 | ransomware |
| 1377 | Manual SOC inefficiencies | critical | 10.0 | 1 | Data Breach |
| 1378 | MOVEit Transfer zero-day (Clop gang, 2023) | critical | 10.0 | 1 | ransomware |
| 1379 | Unauthenticated File Read | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1380 | hijacked_maintainer_account | critical | 10.0 | 1 | ransomware |
| 1381 | Insufficient Asset Discovery (IIoT Device Proliferation) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 1382 | Weak Third-Party Security Controls | critical | 10.0 | 1 | Data Breach |
| 1383 | Unsecured Infrastructure Controls | critical | 10.0 | 1 | Cyber Attack |
| 1384 | Lack of cybersecurity investment | critical | 10.0 | 1 | Cyberattack |
| 1385 | Alta Payment Portal | critical | 10.0 | 1 | Data Breach |
| 1386 | Cisco VPN vulnerabilities | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 1387 | Publicly exposed servers and computers | critical | 10.0 | 1 | Cyberattack |
| 1388 | User Trust in Fake App | critical | 10.0 | 1 | Malware Attack |
| 1389 | CVE-2025-14847 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1390 | dependency trust model | critical | 10.0 | 1 | supply chain attack |
| 1391 | Poorly secured networks, MFA vulnerabilities | critical | 10.0 | 1 | Cyberattack, Initial Access Brokerage, Ransomware |
| 1392 | Poor access controls and credential management for third-party code repositories | critical | 10.0 | 1 | Data Breach |
| 1393 | legitimate platform abuse (e.g., Google Calendar, Azure domains) | critical | 10.0 | 1 | ransomware |
| 1394 | Incomplete Patch (CVE-2026-21510) | critical | 10.0 | 1 | Data Breach |
| 1395 | Limited incident response capabilities in SMEs | critical | 10.0 | 1 | Extortion |
| 1396 | CVE-2023-23397 (Microsoft Outlook Elevation of Privilege Vulnerability) | critical | 10.0 | 1 | Cyber Espionage |
| 1397 | Lack of Robust Backup Systems | critical | 10.0 | 1 | Supply Chain Attack |
| 1398 | lack of multi-factor authentication for downloads | critical | 10.0 | 1 | ransomware |
| 1399 | CVE-2026-1358 (Unrestricted File Upload) | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1400 | Cleo file sharing tool | critical | 10.0 | 1 | Data Breach |
| 1401 | CVE-2026-44963 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1402 | Browser Fetch API abuse via Service Workers (CVE not specified) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1403 | Previously unknown vulnerability in email system | critical | 10.0 | 1 | Ransomware |
| 1404 | unrestricted RDP/remote tool access | critical | 10.0 | 1 | ransomware |
| 1405 | insecure use of pull_request_target in GitHub Actions | critical | 10.0 | 1 | supply chain attack |
| 1406 | CVE-2026-33017 (Langflow AI) | critical | 10.0 | 1 | ransomware |
| 1407 | Lack of Out-of-Band Authentication | critical | 10.0 | 1 | Social Engineering |
| 1408 | Juniper Networks routers | critical | 10.0 | 1 | Cyberespionage |
| 1409 | CVE-2026-24061 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1410 | Unsegmented Networks | critical | 10.0 | 1 | Data Breach |
| 1411 | Cloud storage platform | critical | 10.0 | 1 | Data Breach |
| 1412 | SonicWall SSL VPN endpoints | critical | 10.0 | 1 | Ransomware |
| 1413 | Previously unknown RCE vulnerability in Max Messenger’s media processing engine, existing since the beta phase in early 2025 | critical | 10.0 | 1 | Data Breach |
| 1414 | Reduced CISA staffing (from ~2,500 to <900) | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 1415 | Unencrypted Satellite Backhaul | critical | 10.0 | 1 | Data Interception |
| 1416 | Weak supply-chain security | critical | 10.0 | 1 | Data Breach |
| 1417 | CWE-93 (CRLF Injection) | critical | 10.0 | 1 | Privilege Escalation |
| 1418 | Previously unknown vulnerability in file-sharing system | critical | 10.0 | 1 | Ransomware Attack |
| 1419 | Compromised administrative accounts (26 user accounts, including admin-level) | critical | 10.0 | 1 | Ransomware Attack |
| 1420 | flat networks | critical | 10.0 | 1 | Ransomware |
| 1421 | Operational Trust | critical | 10.0 | 1 | Data Breach |
| 1422 | Abandoned Vercel-hosted URL takeover | critical | 10.0 | 1 | Phishing |
| 1423 | Unsafe code evaluation in LDAP autovalues option | critical | 10.0 | 1 | SQL Injection |
| 1424 | Critical RCE flaw in Apache Tomcat | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1425 | CVE-2025-20333 (Authentication bypass in Cisco ASA Software) | critical | 10.0 | 1 | Zero-day exploitation |
| 1426 | CVE-2026-25108 (OS command injection) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1427 | Inconsistent AI Safety Controls Across Languages | critical | 10.0 | 1 | Influence Operation |
| 1428 | CVE-2026-42945 (Heap Buffer Overflow in ngx_http_rewrite_module) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1429 | Kickidler employee monitoring tool | critical | 10.0 | 1 | Ransomware |
| 1430 | weak/recycled passwords | critical | 10.0 | 1 | general cybersecurity awareness |
| 1431 | Human trust in perceived secure platforms | critical | 10.0 | 1 | Social Engineering |
| 1432 | Absence of Standardized Risk Assessments | critical | 10.0 | 1 | Ransomware |
| 1433 | Lack of Email Filtering | critical | 10.0 | 1 | Targeted Cyberattack |
| 1434 | Systemic vulnerabilities in critical infrastructure | critical | 10.0 | 1 | Data Breach |
| 1435 | Package Impersonation | critical | 10.0 | 1 | Supply Chain Attack |
| 1436 | Inadequate Reporting Processes | critical | 10.0 | 1 | Data Breach |
| 1437 | Over-Reliance on Reactive Detection (EDR/XDR) | critical | 10.0 | 1 | EDR/XDR Evasion |
| 1438 | Poor Data Management | critical | 10.0 | 1 | Data Breach |
| 1439 | Fortinet CVEs | critical | 10.0 | 1 | Ransomware |
| 1440 | Microsoft Exchange Server vulnerabilities (e.g., ProxyLogon) | critical | 10.0 | 1 | Cyber Espionage |
| 1441 | CVE-2026-25177 | critical | 10.0 | 1 | Privilege Escalation |
| 1442 | Missing Function-Level Access Control (CWE-639) | critical | 10.0 | 1 | Unauthorized Access |
| 1443 | Trust in AI Model Updates | critical | 10.0 | 1 | Malware |
| 1444 | Flaw in SentinelOne's agent upgrade process | critical | 10.0 | 1 | Ransomware |
| 1445 | CVE-2024-40766 (SonicWall SSLVPN improper access control) | critical | 10.0 | 1 | ransomware |
| 1446 | Default Teams App Permissions | critical | 10.0 | 1 | Social Engineering |
| 1447 | weak backup protection (backups were deleted by attacker) | critical | 10.0 | 1 | ransomware |
| 1448 | CVE-2023-38831 | critical | 10.0 | 1 | Cyberespionage |
| 1449 | CVE-2026-43500 | critical | 10.0 | 1 | Privilege Escalation |
| 1450 | Salesforce Instance Misconfiguration | critical | 10.0 | 1 | Data Breach |
| 1451 | Student cybersecurity illiteracy | critical | 10.0 | 1 | Data Breach |
| 1452 | CVE-2026-33032 | critical | 10.0 | 1 | Authentication Bypass |
| 1453 | Unpatched Firmware/Software in Network Perimeter Devices | critical | 10.0 | 1 | Cyber Espionage |
| 1454 | F5 BIG-IP load balancers | critical | 10.0 | 1 | Reconnaissance |
| 1455 | Weak Authentication (68% of breaches involve credentials) | critical | 10.0 | 1 | Ransomware |
| 1456 | inadequate endpoint protection (Symantec Endpoint Protection failed to fully remediate backdoor) | critical | 10.0 | 1 | ransomware |
| 1457 | Insufficient Access Controls (Assumed) | critical | 10.0 | 1 | Ransomware |
| 1458 | Steganography | critical | 10.0 | 1 | Malware Infection |
| 1459 | Inadequate validation of `gatewayUrl` parameter in ClawDBot Control UI (GHSA-g8p2-7wf7-98mq) | critical | 10.0 | 1 | Authentication Bypass, Remote Code Execution (RCE) |
| 1460 | Stolen username and password of a UN employee purchased off the dark web | critical | 10.0 | 1 | Data Breach |
| 1461 | Third-party Salesforce CRM integration | critical | 10.0 | 1 | Data Breach |
| 1462 | CVE-2026-1492 (Privilege Management Flaw in User Registration & Membership Plugin) | critical | 10.0 | 1 | Privilege Escalation |
| 1463 | unsecured copper infrastructure | critical | 10.0 | 1 | infrastructure vulnerability |
| 1464 | Precision rounding error in swap calculations | critical | 10.0 | 1 | Exploit |
| 1465 | Vulnerabilities in SonicWall, Veeam, and Cisco products | critical | 10.0 | 1 | Ransomware |
| 1466 | SonicWall SSL VPN Vulnerability (Credentials in Backup Files) | critical | 10.0 | 1 | Unauthorized Access |
| 1467 | Programming Issue | critical | 10.0 | 1 | Data Exposure |
| 1468 | Absence of Visibility/Monitoring for Non-Email Channels | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1469 | CVE-2025-33064 (Windows SMB Improper Access Control) | critical | 10.0 | 1 | Patch Release |
| 1470 | Lack of MFA Enforcement | critical | 10.0 | 1 | Social Engineering |
| 1471 | Unpatched Teams Clients | critical | 10.0 | 1 | Social Engineering |
| 1472 | CVE-2025-64446 | critical | 10.0 | 1 | Ransomware |
| 1473 | CVE-2025-59287 (Windows Server Update Services - WSUS) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1474 | CVE-2026-8711 (Heap-based buffer overflow in ngx_http_js_module) | critical | 10.0 | 1 | Vulnerability |
| 1475 | Inadequate cybersecurity frameworks for space-based infrastructure | critical | 10.0 | 1 | Cyber-Physical Threat |
| 1476 | CVE-2025-32432 (CWE-94: Improper Control of Code Generation) | critical | 10.0 | 1 | Code Injection |
| 1477 | Weak Passwords (WordPress Admin Accounts) | critical | 10.0 | 1 | Influence Operation |
| 1478 | CVE-2026-8037 | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1479 | abuse of elevated privileges post-compromise (e.g., Trend Vision One uninstaller) | critical | 10.0 | 1 | ransomware |
| 1480 | Lack of Multi-Factor Authentication (2FA) Enforcement | critical | 10.0 | 1 | Data Breach |
| 1481 | Adobe Magento e-commerce platform | critical | 10.0 | 1 | Magecart Attack |
| 1482 | ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) | critical | 10.0 | 1 | ransomware |
| 1483 | poor_network_segmentation | critical | 10.0 | 1 | ransomware |
| 1484 | Outdated Ethernet systems | critical | 10.0 | 1 | Ransomware |
| 1485 | AI Browser Design Flaw (Fragment Inclusion in Context) | critical | 10.0 | 1 | Prompt Injection |
| 1486 | Infostealer logs | critical | 10.0 | 1 | Extortion / Data Leak Threat |
| 1487 | CVE-2024-1182 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 1488 | Improper security configurations in Windows Named Pipe implementation within the Acer Control Center Service (ACCSvc.exe) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1489 | Transition-Minimized Differential Signaling (TMDS) in HDMI/DVI interfaces | critical | 10.0 | 1 | Data Exfiltration |
| 1490 | CVE-2026-1354 | critical | 10.0 | 1 | Firmware Vulnerability |
| 1491 | Unmaintained Software (e.g., FreeImage in Audi Vehicles) | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 1492 | Oracle E-Business Suite vulnerability (patched post-incident) | critical | 10.0 | 1 | Ransomware |
| 1493 | CVE-2026-29000 | critical | 10.0 | 1 | Authentication Bypass |
| 1494 | BeyondTrust | critical | 10.0 | 1 | Ransomware |
| 1495 | Social engineering (malicious link disguised as system error) | critical | 10.0 | 1 | Data Breach |
| 1496 | MOVEit file-transfer software zero-day vulnerability | critical | 10.0 | 1 | Data Breach |
| 1497 | Use-After-Free (UAF) in Samsung KNOX PROCA/FIVE subsystem | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1498 | Impersonation of trusted contact (reporter) | critical | 10.0 | 1 | Cyber Espionage |
| 1499 | GraphQL interfaces | critical | 10.0 | 1 | Data Breach |
| 1500 | Dormant Backdoors | critical | 10.0 | 1 | Supply Chain Attack |
| 1501 | Liquidity Token Contracts | critical | 10.0 | 1 | Cyberattack |
| 1502 | CVE-2026-50160 (GHSA-j542-4rch-8hwf) | critical | 10.0 | 1 | Mass Assignment Vulnerability |
| 1503 | lack of formal AI-use/data privacy policies | critical | 10.0 | 1 | ransomware |
| 1504 | Security Oversight | critical | 10.0 | 1 | Data Breach |
| 1505 | Previously Patched Vulnerabilities (Exploited Post-Patch) | critical | 10.0 | 1 | Data Breach |
| 1506 | Unprotected 'Recent Links' feature with predictable URL format, enabling unauthorized data scraping via crawlers | critical | 10.0 | 1 | Data Exposure |
| 1507 | Critical SharePoint Vulnerabilities (July 2025) | critical | 10.0 | 1 | Ransomware Attack |
| 1508 | Minimal/No Authentication | critical | 10.0 | 1 | Exposure of Vulnerable Systems |
| 1509 | lack of centralized patching for consulting deliverables | critical | 10.0 | 1 | supply chain attack |
| 1510 | CVE-2026-20127 | critical | 10.0 | 1 | Authentication Bypass |
| 1511 | Default-enabled remote user account, unprotected superuser accounts, user enumeration, and lack of password protection | critical | 10.0 | 1 | Misconfiguration |
| 1512 | Unsecured IoT/Peripheral Devices | critical | 10.0 | 1 | Ransomware |
| 1513 | Publicly Exposed MCP Servers | critical | 10.0 | 1 | Data Exposure |
| 1514 | CWE-285 (Polkit Authorization Bypass) | critical | 10.0 | 1 | Privilege Escalation |
| 1515 | compromised WordPress sites | critical | 10.0 | 1 | malware |
| 1516 | Lack of Anomaly Detection | critical | 10.0 | 1 | Data Breach Risk |
| 1517 | Human Error (lack of skepticism toward unsolicited interactions) | critical | 10.0 | 1 | Cyber Theft |
| 1518 | Long-standing vulnerabilities in SonicWall firewall systems, unmanaged exceptions, temporary rules, unprotected backups, administrative credentials | critical | 10.0 | 1 | Ransomware, Data Breach |
| 1519 | poor staff training | critical | 10.0 | 1 | data breach |
| 1520 | Remote Code Execution in Imunify360 AV deobfuscation logic (versions before v32.7.4.0) | critical | 10.0 | 1 | Vulnerability |
| 1521 | Unauthorized access via compromised civil servant credentials | critical | 10.0 | 1 | Data Breach |
| 1522 | Compromised software update mechanism | critical | 10.0 | 1 | Supply Chain Attack |
| 1523 | Known flaw in a widely used healthcare IT management platform | critical | 10.0 | 1 | Ransomware |
| 1524 | Weak Subcontractor Security Postures | critical | 10.0 | 1 | Supply Chain Attack |
| 1525 | CVE-2025-23334 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1526 | cloud security misconfigurations | critical | 10.0 | 1 | cyber espionage |
| 1527 | Overly permissive IAM policies | critical | 10.0 | 1 | Supply-Chain Attack |
| 1528 | Trust Exploitation | critical | 10.0 | 1 | Cryptocurrency Scam |
| 1529 | CVE-2026-42880 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1530 | arbitrary code execution in CI/CD pipeline | critical | 10.0 | 1 | supply chain attack |
| 1531 | Stale IAM Accounts in AI Environments | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 1532 | CVE-2025-53690 (ViewState Deserialization in Sitecore XM/XP/XC/Managed Cloud) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1533 | Ivanti Connect Secure | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1534 | Weak or Compromised RDP Credentials | critical | 10.0 | 1 | Malware |
| 1535 | Weak Authentication in Third-Party Platforms | critical | 10.0 | 1 | Data Breach |
| 1536 | jailbreaking techniques | critical | 10.0 | 1 | ransomware |
| 1537 | Self-propagating payload in NPM packages | critical | 10.0 | 1 | Supply Chain Attack |
| 1538 | CVE-2025-34300 | critical | 10.0 | 1 | Remote Code Execution |
| 1539 | emotional manipulation | critical | 10.0 | 1 | phishing |
| 1540 | Router vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1541 | Manipulation of AmountWithBonus variable | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1542 | Trivy | critical | 10.0 | 1 | Ransomware |
| 1543 | SharePoint server vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1544 | Custom IoT malware, IOCONTROL | critical | 10.0 | 1 | Cyberattack |
| 1545 | CVE-2021-Log4j (Remote Code Execution) | critical | 10.0 | 1 | Ransomware |
| 1546 | Known vulnerability in IT infrastructure | critical | 10.0 | 1 | Data Breach |
| 1547 | Insecure SOHO routers with default or weak configurations | critical | 10.0 | 1 | Espionage |
| 1548 | CVE-2024-45347 | critical | 10.0 | 1 | Authentication Bypass Vulnerability |
| 1549 | CVE-2024-11120 | critical | 10.0 | 1 | Cyberattack |
| 1550 | Delegated Administrative Privileges (DAP) in Microsoft cloud solutions | critical | 10.0 | 1 | cyberespionage |
| 1551 | Insecure webcam | critical | 10.0 | 1 | Ransomware |
| 1552 | Legitimate SaaS platforms for command-and-control | critical | 10.0 | 1 | Data Theft |
| 1553 | CVE-2023-22527 | critical | 10.0 | 1 | Cryptomining Campaign |
| 1554 | unsecured internet-facing devices | critical | 10.0 | 1 | espionage |
| 1555 | Automatic execution of malicious code during package installation or project builds | critical | 10.0 | 1 | Supply Chain Attack |
| 1556 | Exposed FortiGate Management Interface | critical | 10.0 | 1 | Data Breach |
| 1557 | Rewards system manipulation | critical | 10.0 | 1 | Cryptocurrency Heist |
| 1558 | CVE-2026-20160 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1559 | Undocumented Warbird framework | critical | 10.0 | 1 | Supply Chain Attack |
| 1560 | OAuth Token Theft | critical | 10.0 | 1 | Data Breach |
| 1561 | GDPR compliance leverage (ransom coercion) | critical | 10.0 | 1 | ransomware |
| 1562 | VMware virtual machines | critical | 10.0 | 1 | Cyberespionage |
| 1563 | OAuth Token Misconfiguration | critical | 10.0 | 1 | Data Breach |
| 1564 | Incorrect configuration | critical | 10.0 | 1 | Data Breach |
| 1565 | AI-Generated Deepfakes | critical | 10.0 | 1 | Data Breach |
| 1566 | Browser-Based Credential Storage (Syncing Across Devices) | critical | 10.0 | 1 | Phishing (Non-Email) |
| 1567 | CVE-2026-49103 | critical | 10.0 | 1 | XSS |
| 1568 | Missing Alerts | critical | 10.0 | 1 | Data Exposure |
| 1569 | CVE-2025-4428 | critical | 10.0 | 1 | Cyber Espionage |
| 1570 | Insufficient Contractual Safeguards | critical | 10.0 | 1 | Third-Party Breach |
| 1571 | Insufficient Threat Hunting Capabilities | critical | 10.0 | 1 | EDR/XDR Evasion |
| 1572 | Weak/Reused Passwords (88% of breaches per Verizon DBIR) | critical | 10.0 | 1 | Data Breach |
| 1573 | Compromised Okta SSO account | critical | 10.0 | 1 | Data Breach |
| 1574 | Trojanized Software Supply Chain | critical | 10.0 | 1 | Targeted Attack |
| 1575 | Fortinet security devices | critical | 10.0 | 1 | Cyberespionage |
| 1576 | Lateral Movement from Contractor to MoD Systems | critical | 10.0 | 1 | Data Breach |
| 1577 | CVE-2022-41040 | critical | 10.0 | 1 | Ransomware |
| 1578 | Lack of Behavioral Analytics for Insider Threat Detection | critical | 10.0 | 1 | Insider Threat (Attempted) |
| 1579 | Compromised Passwords | critical | 10.0 | 1 | Data Breach |
| 1580 | Web application stack | critical | 10.0 | 1 | Data Breach |
| 1581 | CVE-2026-24423 (Missing Authentication for Critical Function - CWE-306) | critical | 10.0 | 1 | Ransomware |
| 1582 | Human Vulnerability (Bribery/Extortion) | critical | 10.0 | 1 | Insider Threat |
| 1583 | Inadequate Sandboxing for AI/ML Environments | critical | 10.0 | 1 | Supply Chain Attack |
| 1584 | Unpatched Software in Data Centers | critical | 10.0 | 1 | Cyber Espionage |
| 1585 | Weak/Reused Passwords | critical | 10.0 | 1 | Account Compromise |
| 1586 | Unintentional Misconfiguration | critical | 10.0 | 1 | Data Exposure |
| 1587 | Payment processing system vulnerability | critical | 10.0 | 1 | Data Breach |
| 1588 | Alleged zero-day vulnerability in MyBB or misconfiguration | critical | 10.0 | 1 | Data Breach |
| 1589 | Systemic design weaknesses in agentic red-team tools, including weak isolation, shared volumes, unauthenticated APIs, and excessive container privileges | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1590 | Overlooked Access Rights | critical | 10.0 | 1 | Data Breach |
| 1591 | Classified information mishandling | critical | 10.0 | 1 | Cyber Attack, Data Leak |
| 1592 | Lack of adequate detection and response capabilities for drone threats | critical | 10.0 | 1 | Physical Security Threat |
| 1593 | Unauthorized Disclosure of Sensitive Information | critical | 10.0 | 1 | Security Vulnerabilities |
| 1594 | lack of email security by design | critical | 10.0 | 1 | phishing |
| 1595 | external-facing RDP/VPN misconfigurations | critical | 10.0 | 1 | ransomware |
| 1596 | CVE-2017-17562 (GoAhead RCE) | critical | 10.0 | 1 | cyberespionage |
| 1597 | CVE-2025-30247 (OS Command Injection in Firmware UI) | critical | 10.0 | 1 | Vulnerability |
| 1598 | Phishing, Malicious Software Deployment | critical | 10.0 | 1 | Data Breach, Ransomware |
| 1599 | Default public location sharing settings in fitness app | critical | 10.0 | 1 | Data Exposure |
| 1600 | Fake Job Offers | critical | 10.0 | 1 | Cryptocurrency Scam |
| 1601 | vulnerable computer systems | critical | 10.0 | 1 | data breach |
| 1602 | Poor Spam Filtering | critical | 10.0 | 1 | Ransomware |
| 1603 | Excessive Privileges (God-level access) | critical | 10.0 | 1 | Data Breach |
| 1604 | Expiration of State and Local Cybersecurity Grant Program | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 1605 | CVE-2026-50746 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1606 | Vulnerabilities in Accellion file transfer platform | critical | 10.0 | 1 | Data Breach |
| 1607 | Zero-day vulnerability in ktapi.sys (Kontron driver) | critical | 10.0 | 1 | Ransomware |
| 1608 | Shared Responsibility Model Gaps in Cloud Security | critical | 10.0 | 1 | Predictive Analysis |
| 1609 | Outdated RTU firmware | critical | 10.0 | 1 | Cyberattack (Wiper Malware, Firmware Tampering) |
| 1610 | Unauthorized access to video lessons | critical | 10.0 | 1 | Data Breach |
| 1611 | Integer underflow in IPv6 extension header parser (Inspect.sys) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 1612 | Critical vulnerability in SAP NetWeaver Visual Composer development server | critical | 10.0 | 1 | Zero-day attack |
| 1613 | understaffed municipal services | critical | 10.0 | 1 | physical security breach |
| 1614 | 20 security vulnerabilities identified by Claude LLM | critical | 10.0 | 1 | Data Breach, Cyber Espionage |
| 1615 | Untrusted data deserialization in LeRobot's PolicyServer | critical | 10.0 | 1 | Phishing |
| 1616 | Oracle zero-day vulnerability | critical | 10.0 | 1 | Ransomware |
| 1617 | AppArmor vulnerabilities (no CVE assigned yet) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1618 | outdated cybersecurity protocols | critical | 10.0 | 1 | cyber attack |
| 1619 | Cross-Site Scripting (XSS) in Free-for-Teacher environment | critical | 10.0 | 1 | Data Breach, Extortion |
| 1620 | firewall vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1621 | Unpatched Solaris servers | critical | 10.0 | 1 | APT Attack |
| 1622 | Insufficient Log Retention/Preservation | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 1623 | Compromised IoT devices and routers, primarily Android TVs | critical | 10.0 | 1 | DDoS |
| 1624 | Unauthorized Cloud Storage | critical | 10.0 | 1 | Data Breach (Alleged) |
| 1625 | Command Execution as Root | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1626 | Hidden dependency with postinstall script execution | critical | 10.0 | 1 | Supply Chain Attack |
| 1627 | 27-year-old OpenBSD flaw | critical | 10.0 | 1 | AI-driven cyber attack |
| 1628 | Poor Oversight of Third-Party Vendor (PowerSchool) | critical | 10.0 | 1 | Data Breach |
| 1629 | Reduced Workforce Capacity | critical | 10.0 | 1 | Operational Risk |
| 1630 | Unpatched Third-Party Integrations (Salesloft Drift) | critical | 10.0 | 1 | Data Breach |
| 1631 | CVE-2024-27199 (JetBrains TeamCity) | critical | 10.0 | 1 | ransomware |
| 1632 | CVE-2026-0740 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1633 | Unauthorized access to departmental server | critical | 10.0 | 1 | Espionage |
| 1634 | Stale Accounts (Former Employees with Retained Access) | critical | 10.0 | 1 | Data Breach |
| 1635 | Unmanaged BYOD Devices | critical | 10.0 | 1 | Social Engineering |
| 1636 | CVE-2017-9805 (Apache Struts) | critical | 10.0 | 1 | cyberespionage |
| 1637 | Reused passwords from previous breaches | critical | 10.0 | 1 | Data Breach |
| 1638 | Security gap in MOVEit Transfer | critical | 10.0 | 1 | Data Breach |
| 1639 | Legacy systems, architectural weaknesses in industrial security, IT-OT convergence | critical | 10.0 | 1 | Cyberattack on Operational Technology (OT) |
| 1640 | Mismanagement of sensitive data, lack of secure cloud storage | critical | 10.0 | 1 | Data Breach |
| 1641 | Poor Access Management | critical | 10.0 | 1 | Data Breach |
| 1642 | Misconfigured or unmonitored edge devices | critical | 10.0 | 1 | Ransomware |
| 1643 | Third-Party Repository Access | critical | 10.0 | 1 | AI Cybersecurity Risk |
| 1644 | automated package update mechanisms | critical | 10.0 | 1 | supply chain attack |
| 1645 | CVE-2025-9491 (Windows Shortcut (LNK) file user interface misinterpretation) | critical | 10.0 | 1 | Remote Code Execution |
| 1646 | Default passwords, Outdated software, Lack of manual updates | critical | 10.0 | 1 | Data Breach, Voyeurism, Illegal Content Distribution |
| 1647 | AI System Autonomy (unsupervised decision-making) | critical | 10.0 | 1 | Predictive Analysis |
| 1648 | Publicly exposed Ollama AI servers without authentication or monitoring | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1649 | Remote Terminal Units (RTUs) | critical | 10.0 | 1 | Cyber Sabotage |
| 1650 | Weak password storage (SHA-256 with salt) | critical | 10.0 | 1 | Data Breach |
| 1651 | critical and zero-day vulnerabilities in internet-facing network equipment | critical | 10.0 | 1 | ransomware |
| 1652 | CVE-2026-2005 (Heap-based buffer overflow in PGP session key parsing) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1653 | insufficient physical security for network devices | critical | 10.0 | 1 | cyber-espionage |
| 1654 | Server Crash | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1655 | Critical jailbreak vulnerability in *Fable 5* and *Mythos 5* AI models | critical | 10.0 | 1 | AI Model Vulnerability / Regulatory Intervention |
| 1656 | Shared Accounts | critical | 10.0 | 1 | Data Breach |
| 1657 | Insufficient Anomaly Detection | critical | 10.0 | 1 | Data Breach |
| 1658 | unique implementation flaws | critical | 10.0 | 1 | supply chain attack |
| 1659 | Error by a third-party contractor | critical | 10.0 | 1 | Data Breach |
| 1660 | Lack of Business Continuity Plans | critical | 10.0 | 1 | Ransomware |
| 1661 | weak intranet security | critical | 10.0 | 1 | data breach |
| 1662 | CVE-2025-53771 (Path Traversal) | critical | 10.0 | 1 | Cyber Espionage |
| 1663 | public cloud | critical | 10.0 | 1 | ransomware |
| 1664 | CVE-2025-21042 (CVSS 8.8) - Out-of-Bounds Write in libimagecodec.quram.so | critical | 10.0 | 1 | Espionage |
| 1665 | misuse of scientific research cover | critical | 10.0 | 1 | espionage |
| 1666 | Supply Chain Weakness | critical | 10.0 | 1 | Supply Chain Attack |
| 1667 | Poorly maintained systems | critical | 10.0 | 1 | Ransomware |
| 1668 | CVE-2019-17571 (Apache Log4j 1.2 deserialization issue) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1669 | Roundcube webmail XSS vulnerability, twofactorgauthenticator plugin misconfiguration | critical | 10.0 | 1 | Cyberespionage |
| 1670 | Kernel compromise | critical | 10.0 | 1 | Espionage |
| 1671 | CVE-2024-9852 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 1672 | Vulnerabilities in aviation’s digital infrastructure | critical | 10.0 | 1 | Cyberattack |
| 1673 | CVE-2025-26319 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1674 | unpatched or misconfigured endpoints | critical | 10.0 | 1 | ransomware |
| 1675 | Unicode Private Use Area characters (0xFE00–0xFE0F, 0xE0100–0xE01EF) | critical | 10.0 | 1 | Supply Chain Attack |
| 1676 | Insufficient cybersecurity training | critical | 10.0 | 1 | Data Breach |
| 1677 | Progress MOVEit transfer systems | critical | 10.0 | 1 | Data Breach |
| 1678 | CVE-2026-25611 | critical | 10.0 | 1 | Denial of Service (DoS) |
| 1679 | Heap Metadata Corruption | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 1680 | budget reductions | critical | 10.0 | 1 | data breach |
| 1681 | Compromised Polyfill.io service | critical | 10.0 | 1 | Supply Chain Attack |
| 1682 | Political Distractions | critical | 10.0 | 1 | Operational Risk |
| 1683 | Buffer underflow in Synopsys DWC2 USB controller (BootROM) | critical | 10.0 | 1 | Hardware Vulnerability |
| 1684 | VIB Acceptance Level Tampering | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 1685 | Compromised Deloitte employee credentials | critical | 10.0 | 1 | data breach |
| 1686 | Vulnerability in data exchange platform | critical | 10.0 | 1 | Data Breach |
| 1687 | CVE-2024-20399 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 1688 | Cross-jurisdictional regulatory gaps | critical | 10.0 | 1 | Cyber-Physical Threat |
| 1689 | Undocumented backdoors in the Go1 quadruped | critical | 10.0 | 1 | Privacy Breach |
| 1690 | CVE-2024-11859 | critical | 10.0 | 1 | Malware Delivery |
| 1691 | PoisonX kernel driver (BYOVD attack) | critical | 10.0 | 1 | Ransomware |
| 1692 | Inadequate Incident Response Plans | critical | 10.0 | 1 | Ransomware |
| 1693 | Human error (opening malicious email attachment) | critical | 10.0 | 1 | Phishing Attack |
| 1694 | Absence of Memoranda of Agreement (MOAs) with LGUs | critical | 10.0 | 1 | Data Privacy Violation |
| 1695 | Exploitation of Android’s Accessibility Service, Google Play Protect bypass techniques | critical | 10.0 | 1 | Malware (Remote Access Trojan - RAT) |
| 1696 | CVE-2025-49144 | critical | 10.0 | 1 | Privilege Escalation |
| 1697 | Third-Party Integration Vulnerabilities (Salesforce-connected apps) | critical | 10.0 | 1 | Data Breach |
| 1698 | Lack of modern defenses | critical | 10.0 | 1 | GPS spoofing |
| 1699 | Pulse Secure CVE-2019-11510 | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 1700 | CVE-2026-5757 (Out-of-bounds memory vulnerability in model quantization engine) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1701 | Internal mechanism for helping password-forgetting users reclaim their accounts | critical | 10.0 | 1 | Data Privacy Breach |
| 1702 | CVE-2025-40551 (CWE-502: Unsafe Deserialization) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1703 | CVE-2024-8299 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 1704 | Weak private key generation algorithm | critical | 10.0 | 1 | Cryptocurrency Theft |
| 1705 | Weak Entra ID Configurations (e.g., external access policies) | critical | 10.0 | 1 | Social Engineering |
| 1706 | Default credentials (e.g., Hitachi RTU admin account 'Default') | critical | 10.0 | 1 | Cyberattack (Wiper Malware, Firmware Tampering) |
| 1707 | Separate vulnerability in login pages | critical | 10.0 | 1 | Ransomware |
| 1708 | Hijacked maintainer accounts and automated dependency updates | critical | 10.0 | 1 | Supply Chain Attack |
| 1709 | Lack of rate limiting and CAPTCHA controls | critical | 10.0 | 1 | Data Breach |
| 1710 | CVE-2026-50748 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1711 | Unauthenticated SQL injection in Lilli’s API, publicly exposed endpoints | critical | 10.0 | 1 | AI-driven cyberattack |
| 1712 | Legacy network | critical | 10.0 | 1 | Data Breach |
| 1713 | Web frameworks (React, Next.js) | critical | 10.0 | 1 | Reconnaissance |
| 1714 | CVE-2024-50603 | critical | 10.0 | 1 | Cryptojacking and Backdoor Exploitation |
| 1715 | CVE-2024-43468 | critical | 10.0 | 1 | SQL Injection |
| 1716 | Vulnerability in the virtual private network | critical | 10.0 | 1 | Ransomware |
| 1717 | Systemic design flaw in Anthropic’s Model Context Protocol (MCP) | critical | 10.0 | 1 | Remote Command Execution (RCE) |
| 1718 | Data Sharing with Third-Party | critical | 10.0 | 1 | Data Breach |
| 1719 | Manual Recovery Reliance | critical | 10.0 | 1 | Supply Chain Attack |
| 1720 | Race Conditions in Object Destruction | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 1721 | Abuse of trusted domain (bubble.io) to bypass email security filters | critical | 10.0 | 1 | Phishing |
| 1722 | CVE-2025-52665 (Improper Input Validation in Backup API Endpoint) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1723 | Coding error in 'DNA Relatives' feature | critical | 10.0 | 1 | Data Breach |
| 1724 | Diversité des systèmes OT rendant difficile une protection standardisée | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1725 | Adobe Flash Vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1726 | CVE-2026-34197 (13-year-old flaw in Apache ActiveMQ Classic) and CVE-2024-32114 (authentication bypass) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1727 | Abstract Threat Perception | critical | 10.0 | 1 | Data Breach |
| 1728 | Lack of Centralized Logging/Monitoring | critical | 10.0 | 1 | Cyber Espionage |
| 1729 | Improper Access Controls (Shared Credentials) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 1730 | Unsupported Firmware/OS (EOL Systems) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 1731 | SCADA-IT Data Convergence | critical | 10.0 | 1 | Cyber Espionage |
| 1732 | CNVD-2020-26585 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1733 | FortiOS (unspecified CVEs) | critical | 10.0 | 1 | ransomware |
| 1734 | CVE-2025-14894 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1735 | CVE-2026-40701 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1736 | Remote Code Execution (RCE) | critical | 10.0 | 1 | Security Vulnerabilities |
| 1737 | accidental exposure of regional blacklist data | critical | 10.0 | 1 | data breach |
| 1738 | CVE-2025-34291 (Origin Validation Error - CWE-346) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1739 | Cyber-Illiterate Student Population | critical | 10.0 | 1 | Data Breach |
| 1740 | Abuse of Device Admin and Accessibility Services permissions | critical | 10.0 | 1 | Ransomware |
| 1741 | Maintenance errors | critical | 10.0 | 1 | Physical Incident |
| 1742 | Lack of Zero-Trust for Non-Human Identities (AI agents) | critical | 10.0 | 1 | Predictive Analysis |
| 1743 | Endpoint Detection Gaps (EDR Limitations) | critical | 10.0 | 1 | Social Engineering |
| 1744 | leaked credentials or hacked WordPress websites | critical | 10.0 | 1 | malware |
| 1745 | SimpleHelp | critical | 10.0 | 1 | Ransomware |
| 1746 | aging IT systems | critical | 10.0 | 1 | data breach |
| 1747 | CitrixBleed2 (CVE unknown, related to Citrix Netscaler) | critical | 10.0 | 1 | ransomware |
| 1748 | DeFi infrastructure weaknesses (historical) | critical | 10.0 | 1 | cyber theft |
| 1749 | Untrusted forked code in CI/CD pipelines | critical | 10.0 | 1 | Supply Chain Attack |
| 1750 | Overprivileged service accounts | critical | 10.0 | 1 | Ransomware |
| 1751 | Embedded Credentials in BIG-IP | critical | 10.0 | 1 | Supply Chain Attack |
| 1752 | No Backup Strategy | critical | 10.0 | 1 | Ransomware |
| 1753 | Authentication bypasses | critical | 10.0 | 1 | Cyber Attack |
| 1754 | CVE-2019-5786 (Google Chrome FileReader) | critical | 10.0 | 1 | Memory Corruption Vulnerability |
| 1755 | developer mistyped dependency installation | critical | 10.0 | 1 | supply chain attack |
| 1756 | Funding constraints | critical | 10.0 | 1 | Data Breach |
| 1757 | CVE-2025-47577 | critical | 10.0 | 1 | Software Vulnerability |
| 1758 | Unspecified SQL Server Vulnerabilities | critical | 10.0 | 1 | Cyber Espionage |
| 1759 | Poor visibility in cloud/hybrid environments | critical | 10.0 | 1 | Ransomware |
| 1760 | Compromised Microsoft 365 Account | critical | 10.0 | 1 | Data Breach |
| 1761 | CVE-2026-21858 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1762 | authentication_bypass_flaw | critical | 10.0 | 1 | ransomware |
| 1763 | Disabled HMAC Authentication | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1764 | Limited Supply Chain Visibility (beyond first-tier vendors) | critical | 10.0 | 1 | Ransomware |
| 1765 | Flaws in Tesla’s Mothership server | critical | 10.0 | 1 | Remote Code Execution |
| 1766 | End-to-End Encryption | critical | 10.0 | 1 | Government Order |
| 1767 | Manual Redaction Errors | critical | 10.0 | 1 | Data Leak |
| 1768 | unpatched Windows SMB flaw (WannaCry) | critical | 10.0 | 1 | ransomware |
| 1769 | CVE-2026-5140 | critical | 10.0 | 1 | Privilege Escalation |
| 1770 | inadequate administrative/physical/technical safeguards (HIPAA) | critical | 10.0 | 1 | data breach |
| 1771 | CVE-2026-27689 (DoS in SAP Supply Chain Management) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1772 | CVE-2025-46811 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1773 | Static Zero Trust Policies (Lack of Dynamic Guardrails) | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 1774 | GreenPlasma (Local privilege escalation) | critical | 10.0 | 1 | Zero-day vulnerability |
| 1775 | CVE-2026-42934 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1776 | Unauthorized system access via help desk | critical | 10.0 | 1 | Ransomware |
| 1777 | Lack of regular security reviews | critical | 10.0 | 1 | Data Breach |
| 1778 | SaaS supply chain blind spots | critical | 10.0 | 1 | Ransomware |
| 1779 | CVE-2025-5777 (CitrixBleed2) | critical | 10.0 | 1 | ransomware |
| 1780 | Undocumented n-day vulnerability | critical | 10.0 | 1 | APT Attack |
| 1781 | Failure to Implement Security Recommendations | critical | 10.0 | 1 | Data Breach |
| 1782 | Unsecured Health Declaration Portal | critical | 10.0 | 1 | Data Breach |
| 1783 | unmanaged devices | critical | 10.0 | 1 | ransomware |
| 1784 | Zimbra Server vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1785 | Compromised WordPress sites, social engineering (fake updates) | critical | 10.0 | 1 | Malware Distribution / Botnet Takedown |
| 1786 | Microsoft Word 2010 vulnerability | critical | 10.0 | 1 | Cyber Espionage |
| 1787 | Legacy Infrastructure Weaknesses | critical | 10.0 | 1 | Data Breach |
| 1788 | CVE-2026-50752 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 1789 | Undetected network access | critical | 10.0 | 1 | Ransomware |
| 1790 | abuse of Velociraptor tool | critical | 10.0 | 1 | ransomware |
| 1791 | Trust in technical support specialists | critical | 10.0 | 1 | Data Breach |
| 1792 | CVE-2026-3300 (CVSS 9.8) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1793 | CVE-2026-41096 (Heap-based buffer overflow in DNSAPI.dll) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1794 | legacy software vulnerabilities | critical | 10.0 | 1 | cyber espionage |
| 1795 | Third-party software (Famly) used by Kido nursery chain | critical | 10.0 | 1 | ransomware |
| 1796 | CVE-2026-XXXXX (PolyShell - unauthenticated arbitrary file upload via REST API) | critical | 10.0 | 1 | Payment Skimmer Attack |
| 1797 | npm package hijacking | critical | 10.0 | 1 | supply chain attack |
| 1798 | Newly discovered vulnerability | critical | 10.0 | 1 | Ransomware |
| 1799 | Unspecified Cisco ASA Vulnerabilities (ArcaneDoor Campaign) | critical | 10.0 | 1 | Espionage |
| 1800 | Vehicle Tracking Systems (VTS), Immobilizer systems, Security systems | critical | 10.0 | 1 | Cyber Attack, Satellite Interference, Vehicle Immobilization |
| 1801 | Vulnerable IoT hardware (digital video recorders, web cameras, home Wi-Fi routers) | critical | 10.0 | 1 | DDoS Attack |
| 1802 | third-party ecosystem vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1803 | CVE-2025-48057 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1804 | SaaS platforms | critical | 10.0 | 1 | Ransomware |
| 1805 | Wide Attack Surfaces (Retail: staff, suppliers, IT systems) | critical | 10.0 | 1 | Ransomware |
| 1806 | insufficient cloud-native security controls | critical | 10.0 | 1 | ransomware |
| 1807 | CVE-2026-8206 (CVSS 9.8) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1808 | Stolen Passwords | critical | 10.0 | 1 | Data Breach |
| 1809 | vulnerable driver | critical | 10.0 | 1 | ransomware |
| 1810 | Human Error (Phishing/Vishing) | critical | 10.0 | 1 | Data Breach |
| 1811 | Misconfiguration of the project’s main smart contract | critical | 10.0 | 1 | Cryptocurrency Heist |
| 1812 | Software Issue | critical | 10.0 | 1 | Data Breach |
| 1813 | DNS infrastructure | critical | 10.0 | 1 | Cyberattack |
| 1814 | Improper Handling of Sensitive Material | critical | 10.0 | 1 | Data Breach |
| 1815 | Insecure Withdrawal Locking Mechanism | critical | 10.0 | 1 | Data Breach |
| 1816 | insufficient encryption | critical | 10.0 | 1 | data breach |
| 1817 | MSP software flaws | critical | 10.0 | 1 | ransomware |
| 1818 | Weak Helpdesk Authentication | critical | 10.0 | 1 | Cyber Extortion |
| 1819 | Microsoft SharePoint zero-day | critical | 10.0 | 1 | ransomware |
| 1820 | Lack of Multi-Factor Authentication (MFA) for Vendor Logins | critical | 10.0 | 1 | Cyberattack |
| 1821 | Employee credentials via spoofed websites | critical | 10.0 | 1 | Cryptocurrency Theft, Phishing, Identity Theft |
| 1822 | Shor's Algorithm (theoretical) | critical | 10.0 | 1 | Emerging Threat |
| 1823 | Known vulnerability in legacy IT infrastructure (unpatched) | critical | 10.0 | 1 | Ransomware, Data Breach |
| 1824 | Obsolete Traditional Detection Systems | critical | 10.0 | 1 | Ransomware |
| 1825 | Compromised OAuth token for a Heroku machine account | critical | 10.0 | 1 | Security Breach |
| 1826 | BlueKeep | critical | 10.0 | 1 | Ransomware |
| 1827 | Technical Debt in Legacy OT Systems (15-20 year lifecycles) | critical | 10.0 | 1 | Cyber-Physical Attack |
| 1828 | Memory Leak | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1829 | GitLab Server Misconfiguration (Red Hat) | critical | 10.0 | 1 | Data Breach |
| 1830 | Telnyx SDK | critical | 10.0 | 1 | Ransomware |
| 1831 | CVE-2025-8088 (WinRAR vulnerability) | critical | 10.0 | 1 | Cyber Espionage, Data Theft |
| 1832 | CVE-2025-29927 (React2Shell) | critical | 10.0 | 1 | Cloud Misconfiguration Exploitation |
| 1833 | Insecure Remote Work Tools | critical | 10.0 | 1 | Data Breach (General Discussion) |
| 1834 | CVE-2025-52163 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 1835 | Social engineering, ClickFix-style prompts, PowerShell exploitation, Windows Defender exclusion manipulation | critical | 10.0 | 1 | Malware Deployment, Social Engineering, Data Exfiltration |
| 1836 | Full Disk Access Exploitation | critical | 10.0 | 1 | AI Cybersecurity Risk |
| 1837 | CVE-2026-0542 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1838 | CVE-2026-33017 | critical | 10.0 | 1 | Code Injection |
| 1839 | Microsoft Artifact Signing service abuse | critical | 10.0 | 1 | Cybercrime Operation Disruption |
| 1840 | Fortinet software | critical | 10.0 | 1 | Cyber Attack |
| 1841 | Identity Debt | critical | 10.0 | 1 | Data Breach |
| 1842 | Crafted local address URLs for SSRF bypass | critical | 10.0 | 1 | SQL Injection |
| 1843 | CVE-2026-3497 (OpenSSH GSSAPI Key Exchange) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1844 | CVE-2025-49844 (RediShell - Use-after-free in Lua sandbox) | critical | 10.0 | 1 | Vulnerability |
| 1845 | Unpatched or end-of-life networking equipment (TP-Link routers) | critical | 10.0 | 1 | Cyberespionage, DNS Hijacking, Adversary-in-the-Middle (AiTM) Attack |
| 1846 | Misconfigured MongoDB databases (lack of authentication, outdated versions) | critical | 10.0 | 1 | Ransomware |
| 1847 | Citrix vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1848 | CVE-2025-59470 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1849 | Trust in official source repository | critical | 10.0 | 1 | Supply Chain Attack |
| 1850 | unchanged default passwords in VSAT terminals | critical | 10.0 | 1 | cyberattack |
| 1851 | CVE-2025-44179 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1852 | Exploit Kit | critical | 10.0 | 1 | Malvertising |
| 1853 | Redis/Memcache session poisoning for arbitrary file deletion | critical | 10.0 | 1 | SQL Injection |
| 1854 | Unauthorized data transfer to private cloud storage | critical | 10.0 | 1 | Data Breach |
| 1855 | Virtual Office portal public access | critical | 10.0 | 1 | ransomware |
| 1856 | AI Chatbot Feature | critical | 10.0 | 1 | Copyright Infringement |
| 1857 | Oracle’s E-Business Suite flaw | critical | 10.0 | 1 | Ransomware Attack |
| 1858 | Weak Enforcement of ISO SAE 21434 (Pre-Release Security) | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 1859 | ManageSieve misconfigurations | critical | 10.0 | 1 | Cyber Espionage |
| 1860 | unpatched flaw in a popular file-transfer tool | critical | 10.0 | 1 | ransomware |
| 1861 | Microsoft Outlook vulnerability | critical | 10.0 | 1 | Data Breach |
| 1862 | unsecured AWS memory dump | critical | 10.0 | 1 | ransomware |
| 1863 | CVE-2025-34158 (Improper Input Validation) | critical | 10.0 | 1 | Vulnerability Exposure |
| 1864 | SonicWall vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 1865 | Outdated network infrastructure | critical | 10.0 | 1 | Data Breach |
| 1866 | weak credential governance | critical | 10.0 | 1 | phishing |
| 1867 | File transfer software vulnerability | critical | 10.0 | 1 | Data Breach |
| 1868 | Unrestricted Remote Access ('Always-On' Feature) | critical | 10.0 | 1 | Data Breach |
| 1869 | Lack of file type limitations | critical | 10.0 | 1 | Data Breach |
| 1870 | CVE-2025-20333 (Cisco ASA VPN) | critical | 10.0 | 1 | Ransomware |
| 1871 | Insider access to classified systems, Lack of real-time monitoring for data exfiltration | critical | 10.0 | 1 | Insider Threat, Espionage |
| 1872 | CVE-2025-55182 (CVSS 10.0) | critical | 10.0 | 1 | worm-driven campaign |
| 1873 | Internet-connected cameras | critical | 10.0 | 1 | Ransomware, Cyber Espionage, Industrial Sabotage |
| 1874 | Lack of Vendor Oversight | critical | 10.0 | 1 | Data Breach |
| 1875 | Lack of BCC usage in group emails | critical | 10.0 | 1 | Data Breach |
| 1876 | Third-Party Supply Chain Weaknesses | critical | 10.0 | 1 | Data Breach |
| 1877 | CVE-2026-25049 (insufficient input sanitization in expression evaluation mechanism) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1878 | CVE-2024-XXXX | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1879 | AI-generated phishing | critical | 10.0 | 1 | credential theft |
| 1880 | Container escape vulnerabilities (e.g., CVE-2025-23266) | critical | 10.0 | 1 | Malware Framework |
| 1881 | Lack of Rate-Limiting | critical | 10.0 | 1 | Data Breach |
| 1882 | Unpatched ICS/OT Systems | critical | 10.0 | 1 | Ransomware |
| 1883 | Insufficient Network Segmentation (implied) | critical | 10.0 | 1 | Ransomware Attack |
| 1884 | Poor Endpoint Security | critical | 10.0 | 1 | Data Breach (General Discussion) |
| 1885 | CVE-2025-10725 (CVSS 9.9) | critical | 10.0 | 1 | Privilege Escalation / Vulnerability Exploitation |
| 1886 | Unsalted MD5 | critical | 10.0 | 1 | Data Breach |
| 1887 | Over-the-Air Broadcast Without Protection | critical | 10.0 | 1 | Data Interception |
| 1888 | Confluence Server Zero-Day Vulnerability | critical | 10.0 | 1 | Zero-Day Exploit |
| 1889 | SQL Injection Vulnerability | critical | 10.0 | 1 | Data Breach |
| 1890 | kernel-level access via vulnerable driver | critical | 10.0 | 1 | ransomware |
| 1891 | CVE-2024-56336 | critical | 10.0 | 1 | Vulnerability |
| 1892 | MOVEit file transfer software zero-day vulnerability | critical | 10.0 | 1 | Ransomware |
| 1893 | Mobile carrier verification processes, SMS-based authentication | critical | 10.0 | 1 | SIM Swap Attack |
| 1894 | CVE-2026-25874 (Unsafe deserialization via Python's `pickle.loads()` in LeRobot's gRPC PolicyServer) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1895 | Fortinet SSL VPN vulnerabilities | critical | 10.0 | 1 | ransomware |
| 1896 | CVE-2023-34048 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 1897 | npm auto-update mechanisms, lifecycle hooks in package installation | critical | 10.0 | 1 | Supply Chain Attack |
| 1898 | CVE-2024-30103 (Remote Code Execution) | critical | 10.0 | 1 | Zero-Day Exploit |
| 1899 | Exposed VPN concentrators | critical | 10.0 | 1 | Destructive Cyberattack |
| 1900 | Lack of domestic rare earth processing capacity | critical | 10.0 | 1 | Geopolitical Risk |
| 1901 | Vulnerabilities in enterprise platforms like Oracle EBS | critical | 10.0 | 1 | Data Theft |
| 1902 | Absence of two-factor authentication | critical | 10.0 | 1 | Ransomware |
| 1903 | User Trust in App Store and Social Media Ads | critical | 10.0 | 1 | Data Breach |
| 1904 | Malfunction at AWS data center (likely a configuration error) | critical | 10.0 | 1 | Service Disruption |
| 1905 | Weak administrative oversight, lack of data-protection culture | critical | 10.0 | 1 | Data Leak |
| 1906 | poor network segmentation (IT/OT convergence) | critical | 10.0 | 1 | ransomware |
| 1907 | CVE-2025-61882 (Critical Authentication Bypass in Oracle E-Business Suite) | critical | 10.0 | 1 | Data Breach |
| 1908 | Implicit trust in supply chains | critical | 10.0 | 1 | Supply Chain Attack, Extortion Campaign |
| 1909 | Improper validation of profile image uploads (SVG files with embedded JavaScript) | critical | 10.0 | 1 | Stored Cross-Site Scripting (XSS) |
| 1910 | Social Engineering (Employee Interaction) | critical | 10.0 | 1 | Ransomware |
| 1911 | Weak or Missing End-to-End Encryption | critical | 10.0 | 1 | Data Breach |
| 1912 | Vulnerable server | critical | 10.0 | 1 | Ransomware |
| 1913 | Remote desktop gateway vulnerability | critical | 10.0 | 1 | Ransomware |
| 1914 | CVE-2025-6000 | critical | 10.0 | 1 | Vulnerability |
| 1915 | Manque de sauvegardes régulières | critical | 10.0 | 1 | Cyberattaque ciblée |
| 1916 | Web server vulnerability | critical | 10.0 | 1 | Data Breach |
| 1917 | Known vulnerability in remote-access software, lack of multi-factor authentication (MFA) | critical | 10.0 | 1 | Ransomware |
| 1918 | Vulnerabilities in decentralized energy infrastructure and OT/ICS systems | critical | 10.0 | 1 | Cyberattack on Critical Infrastructure |
| 1919 | Exposed Web-Accessible Operational Technology (OT) System | critical | 10.0 | 1 | Cyberattack |
| 1920 | Government mismanagement, lack of security protocols | critical | 10.0 | 1 | Data Breach |
| 1921 | Data integrity | critical | 10.0 | 1 | Security Concerns |
| 1922 | CVE-2025-31324 (unspecified CRM/DBMS/SaaS target) | critical | 10.0 | 1 | Cybercriminal Alliance Formation |
| 1923 | Default credentials, weak cybersecurity oversight, legacy systems | critical | 10.0 | 1 | Cyber Espionage, Supply Chain Attack |
| 1924 | CVE-2026-7482 (Memory Overread in GGUF Model File Processing) | critical | 10.0 | 1 | Data Breach |
| 1925 | Salesforce OAuth Misconfiguration (via Vishing) | critical | 10.0 | 1 | Data Breach |
| 1926 | Weak Detection/Response Capabilities (SMEs) | critical | 10.0 | 1 | Ransomware |
| 1927 | Misconfigured OAuth integrations (historical, via Salesloft's Drift) | critical | 10.0 | 1 | Extortion |
| 1928 | Stack overflow (CVE-2026-3608) | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 1929 | CVE-2026-5194 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1930 | Document Management Systems | critical | 10.0 | 1 | Data Theft Extortion |
| 1931 | Azure Data Factory service certificate vulnerability | critical | 10.0 | 1 | Security Flaw |
| 1932 | 181 Firefox exploits | critical | 10.0 | 1 | AI-driven cyber attack |
| 1933 | AI system weaknesses | critical | 10.0 | 1 | ransomware |
| 1934 | Exposed Database Credentials | critical | 10.0 | 1 | Data Exposure |
| 1935 | Misconfigured Cloud Identity and Access Management (IAM) | critical | 10.0 | 1 | Data Breach |
| 1936 | Undisclosed zero-day vulnerability | critical | 10.0 | 1 | Zero-day exploitation |
| 1937 | Third-party AI tool vulnerabilities | critical | 10.0 | 1 | DDoS |
| 1938 | CVE-2024-54085 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1939 | CVE-2026-35194 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 1940 | CVE-2026-33784 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1941 | Software Bug in MCP Server | critical | 10.0 | 1 | Data Exposure |
| 1942 | Six vulnerabilities | critical | 10.0 | 1 | Exploit Kit / Cyber Espionage |
| 1943 | Enterprise hardware vulnerabilities (Fortinet, SonicWall, Cisco) | critical | 10.0 | 1 | Ransomware |
| 1944 | IT-OT Boundary Erosion | critical | 10.0 | 1 | Cyber Espionage |
| 1945 | Legacy OT systems, lack of OT security prioritization, IT-OT convergence | critical | 10.0 | 1 | Ransomware |
| 1946 | CVE-2024-7014 | critical | 10.0 | 1 | Vulnerability Exploit |
| 1947 | Social Engineering (Impersonation of IT support) | critical | 10.0 | 1 | Ransomware |
| 1948 | Microsoft Entra ID Self-Service Password Reset Process | critical | 10.0 | 1 | Cloud Data Theft |
| 1949 | Improper access controls in Capital One's cloud-based firewall (AWS S3 bucket misconfiguration) | critical | 10.0 | 1 | Data Breach |
| 1950 | Trust in open-source packages | critical | 10.0 | 1 | Supply Chain Attack |
| 1951 | CVE-2025-61882 (Oracle E-Business Suite BI Publisher Integration Component) | critical | 10.0 | 1 | Data Theft |
| 1952 | weak token security | critical | 10.0 | 1 | third-party breach |
| 1953 | CVE-2025-2857 | critical | 10.0 | 1 | Zero-day Vulnerability |
| 1954 | Unpatched Adobe Reader zero-day vulnerability | critical | 10.0 | 1 | Zero-Day Exploit |
| 1955 | Poor IT/OT network segmentation | critical | 10.0 | 1 | Cyber Espionage |
| 1956 | legacy monitoring tools | critical | 10.0 | 1 | data_breach |
| 1957 | PowerShell script abuse | critical | 10.0 | 1 | spear-phishing |
| 1958 | File System Access API (user-granted permissions) | critical | 10.0 | 1 | Ransomware |
| 1959 | unrestricted PowerShell usage | critical | 10.0 | 1 | ransomware |
| 1960 | Hardcoded Credentials in Binaries | critical | 10.0 | 1 | Supply Chain Attack |
| 1961 | CVE-2025-47164 (Microsoft Office Use-After-Free) | critical | 10.0 | 1 | Patch Release |
| 1962 | Poor IT-OT segmentation | critical | 10.0 | 1 | Ransomware, Cyber Espionage, Industrial Sabotage |
| 1963 | PackageGate Vulnerabilities | critical | 10.0 | 1 | Supply Chain Attack |
| 1964 | Stolen Employee Tokens | critical | 10.0 | 1 | Data Breach |
| 1965 | Inadequate Data Encryption | critical | 10.0 | 1 | Ransomware |
| 1966 | CVE-2026-9739 (CWE-942 - Permissive Cross-domain Policy with Untrusted Domains) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1967 | Backup Restoration Failures | critical | 10.0 | 1 | Ransomware |
| 1968 | Malicious TestFlight app | critical | 10.0 | 1 | Financial Theft |
| 1969 | Supply chain compromise (Trivy), credential theft | critical | 10.0 | 1 | Supply Chain Attack, Data Breach |
| 1970 | Unpatched vulnerability disclosed in December 2024 | critical | 10.0 | 1 | Data Breach |
| 1971 | Weak IoT Device Security (e.g., default credentials, unpatched firmware) | critical | 10.0 | 1 | Distributed Denial of Service (DDoS) |
| 1972 | Hidden malicious proxy in AI agents | critical | 10.0 | 1 | Vulnerability Exploit |
| 1973 | Lack of Access Controls for Sensitive Data Aggregation | critical | 10.0 | 1 | Data Breach |
| 1974 | inconsistent security standards across geographies | critical | 10.0 | 1 | supply chain attack |
| 1975 | Insufficient regex anchoring in AWS CodeBuild webhook filters | critical | 10.0 | 1 | Supply Chain Attack |
| 1976 | improper cloud storage configuration | critical | 10.0 | 1 | ransomware |
| 1977 | Weak or Outdated Cryptographic Standards | critical | 10.0 | 1 | Emerging Threat |
| 1978 | Cloud Security Gaps | critical | 10.0 | 1 | Cyberattack Surge |
| 1979 | Legitimate utilities repurposed for malicious use (e.g., gpscript.exe) | critical | 10.0 | 1 | Ransomware |
| 1980 | weak MFA implementations (Evilginx tool) | critical | 10.0 | 1 | ransomware |
| 1981 | Unknown Third-Party Relationships | critical | 10.0 | 1 | Data Breach |
| 1982 | Unguarded Museum | critical | 10.0 | 1 | Theft |
| 1983 | Over-Permissive API/OAuth Token Access | critical | 10.0 | 1 | Data Breach |
| 1984 | Misconfigured MongoDB instances lacking authentication, typically listening on port 27017 | critical | 10.0 | 1 | Ransomware |
| 1985 | Lack of MFA on FortiGate VPN firewalls | critical | 10.0 | 1 | Cyberattack (Wiper Malware, Firmware Tampering) |
| 1986 | Unpatched IoMT devices | critical | 10.0 | 1 | Data Breach |
| 1987 | Vulnerabilities present during high-risk phases like satellite deployment, where telemetry, software loadouts, and encryption keys are most exposed. | critical | 10.0 | 1 | Cyber Espionage |
| 1988 | Absence of AI Governance Frameworks | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 1989 | CVE-2023-46805 (Ivanti Connect Secure) | critical | 10.0 | 1 | ransomware |
| 1990 | Outdated Factory Digital Systems | critical | 10.0 | 1 | Cyberattack Surge |
| 1991 | Impersonation of a colleague | critical | 10.0 | 1 | Cyberattack |
| 1992 | CVE-2025-64155 (CWE-78: Improper Neutralization of Special Elements used in an OS Command) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 1993 | compromised authentication credentials | critical | 10.0 | 1 | ransomware |
| 1994 | Insecure RDP configurations | critical | 10.0 | 1 | Ransomware |
| 1995 | Kerberoasting in Active Directory | critical | 10.0 | 1 | ransomware |
| 1996 | Zero-Day in Oracle E-Business Suite | critical | 10.0 | 1 | Data Breach |
| 1997 | Operational Security | critical | 10.0 | 1 | Operational Security Breach |
| 1998 | Weak Employee Credentials | critical | 10.0 | 1 | Cyberattack Surge |
| 1999 | Avast Anti-Rootkit driver | critical | 10.0 | 1 | Malware Campaign |
| 2000 | Outdated or unpatched consumer and small office devices | critical | 10.0 | 1 | Cyber Espionage |
| 2001 | Insufficient client-side runtime monitoring | critical | 10.0 | 1 | Data Breach |
| 2002 | Internet-facing OT devices, project files in PLCs | critical | 10.0 | 1 | Cyberattack |
| 2003 | Improper access control in WDS (CVE-2026-0386) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2004 | Over-Permissive API Access | critical | 10.0 | 1 | Supply Chain Attack |
| 2005 | Improper input validation in the plugin’s `prepare_post_data()` function, allowing PHP function injection via placeholders (e.g., `{entryCounter}`). | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2006 | CAN bus vulnerabilities in Tesla Model S | critical | 10.0 | 1 | Remote Code Execution |
| 2007 | Inadequate backup testing policy | critical | 10.0 | 1 | Policy Deficiency |
| 2008 | Human Error (Phishing Susceptibility) & Weak Remote Access Controls | critical | 10.0 | 1 | Data Breach (Phishing & Unauthorized Access) |
| 2009 | CVE-2026-21509 (RTF parsing flaw) | critical | 10.0 | 1 | Cyber Espionage |
| 2010 | Weaknesses in third-party integrations, lack of real-time monitoring | critical | 10.0 | 1 | Third-Party Breach |
| 2011 | Kernel driver update | critical | 10.0 | 1 | Software Malfunction |
| 2012 | Newly disclosed vulnerabilities | critical | 10.0 | 1 | Botnet, Cyber Espionage |
| 2013 | OAuth Token Misuse | critical | 10.0 | 1 | Supply Chain Attack |
| 2014 | Insecure GitHub Actions workflows misclassified as configuration rather than code, enabling untrusted data to carry into high-privilege workflows | critical | 10.0 | 1 | Supply Chain Attack |
| 2015 | CVE-2026-27684 (SQL injection in SAP NetWeaver Feedback Notification) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2016 | Social Media Account Compromise | critical | 10.0 | 1 | Phishing, Social Engineering |
| 2017 | CVE-2025-60021 (Inadequate input validation in Apache bRPC heap profiler endpoint) | critical | 10.0 | 1 | Remote Command Injection |
| 2018 | Faulty access control mechanisms in Balancer's DeFi protocol | critical | 10.0 | 1 | Cryptocurrency Theft |
| 2019 | React2Shell (CVE not specified) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2020 | CVE-2024-0132, Docker DoS flaw on Linux | critical | 10.0 | 1 | Vulnerability Exploitation, DoS Attack |
| 2021 | Outdated and vulnerable infrastructure | critical | 10.0 | 1 | State-sponsored cyberattack |
| 2022 | CVE-2025-61882 (Oracle E-Business Suite Zero-Day) | critical | 10.0 | 1 | Data Breach |
| 2023 | Unknown vulnerability in online platforms | critical | 10.0 | 1 | Data Breach |
| 2024 | CVE-2026-27771 | critical | 10.0 | 1 | Data Exposure |
| 2025 | Inadequate Access Controls for PowerSource Portal | critical | 10.0 | 1 | Data Breach |
| 2026 | Default Pre-Shared Keys | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2027 | Impersonation of legitimate SDK, hidden credential exfiltration logic | critical | 10.0 | 1 | Supply Chain Attack |
| 2028 | Unpatched vulnerability in the email system | critical | 10.0 | 1 | Ransomware |
| 2029 | AI Training Data Exposure | critical | 10.0 | 1 | Cyber Espionage |
| 2030 | GPS signal manipulation | critical | 10.0 | 1 | cyber deception |
| 2031 | delayed AV detection due to obfuscation | critical | 10.0 | 1 | ransomware |
| 2032 | Loose Sharing Permissions | critical | 10.0 | 1 | Data Breach Risk |
| 2033 | Oracle software vulnerability (identified in September 2023 by NCSC) | critical | 10.0 | 1 | Data Breach, Ransomware |
| 2034 | OpenSSL flaws | critical | 10.0 | 1 | Ransomware |
| 2035 | Trust in open-source maintainers, Fake meeting infrastructure | critical | 10.0 | 1 | Supply Chain Attack |
| 2036 | Single-point-of-failure in 1/1 validation setup, lack of redundant verifiers | critical | 10.0 | 1 | Exploit |
| 2037 | SynologyPhotos application on BeeStation and DiskStation systems | critical | 10.0 | 1 | Zero-Click Vulnerability |
| 2038 | Unpatched Domain Controllers (Privilege Escalation Flaw, April 2025) | critical | 10.0 | 1 | Data Breach |
| 2039 | VMware Fusion root access bug | critical | 10.0 | 1 | Zero-day Exploit |
| 2040 | Insecure Database Configuration | critical | 10.0 | 1 | Data Exposure |
| 2041 | Human psychology | critical | 10.0 | 1 | AI-driven cyberattack |
| 2042 | CVE-2026-4670 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2043 | Videoconference Invitation | critical | 10.0 | 1 | Data Breach |
| 2044 | Funding Pressures in State Schools | critical | 10.0 | 1 | Data Breach |
| 2045 | CVE-2026-50747 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2046 | CVE-2023-MoveIt (Critical File Transfer Vulnerability) | critical | 10.0 | 1 | Ransomware |
| 2047 | CVE-2024-37079 (CWE-787 - Out-of-bounds Write) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2048 | Human trust exploitation | critical | 10.0 | 1 | Data Breach |
| 2049 | CVE-2023-52271 | critical | 10.0 | 1 | Ransomware |
| 2050 | Exposed API endpoints returning call metadata/recordings without authentication | critical | 10.0 | 1 | Data Breach |
| 2051 | Third-party vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 2052 | Malicious PowerPoint Add-Ins | critical | 10.0 | 1 | Cyber Espionage |
| 2053 | Technical Security Configuration Issue | critical | 10.0 | 1 | Data Breach |
| 2054 | Insufficient Vendor Oversight | critical | 10.0 | 1 | Supply Chain Attack |
| 2055 | publicly available personal data (e.g., photos, job titles) | critical | 10.0 | 1 | social engineering |
| 2056 | delayed maintenance response | critical | 10.0 | 1 | physical security breach |
| 2057 | Legitimate Cybersecurity Testing Impersonation | critical | 10.0 | 1 | Espionage |
| 2058 | Microsoft products (17% of exploitations) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2059 | Enabled dangerous features (xp_cmdshell, CLR, OLE Automation) | critical | 10.0 | 1 | Ransomware |
| 2060 | weak supply chain security | critical | 10.0 | 1 | data breach |
| 2061 | unencrypted data transmission | critical | 10.0 | 1 | ransomware |
| 2062 | CVE-2025-32711 (EchoLeak) | critical | 10.0 | 1 | Data Exposure |
| 2063 | Misconfigured Security Controls | critical | 10.0 | 1 | Malware |
| 2064 | Backdoor in M.E.Doc software updates (Intellect Service) | critical | 10.0 | 1 | Cyber Attack |
| 2065 | User Data Misuse | critical | 10.0 | 1 | Data Breach |
| 2066 | custom network architectures in CERs | critical | 10.0 | 1 | supply chain attack |
| 2067 | CVE-2026-42946 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2068 | CVE-2026-49975 (HTTP/2 Bomb) | critical | 10.0 | 1 | Denial of Service (DoS) |
| 2069 | Unaddressed software vulnerabilities in CM/ECF system (identified in 2019 after a prior 2020 breach) | critical | 10.0 | 1 | Data Breach |
| 2070 | Accellion sharing software | critical | 10.0 | 1 | Ransomware |
| 2071 | Shadow AI, IdentityMesh, Infostealers | critical | 10.0 | 1 | Data Breach |
| 2072 | No rate-limiting or access restrictions on user data | critical | 10.0 | 1 | Data Breach |
| 2073 | Inadequate privileged access management | critical | 10.0 | 1 | Ransomware |
| 2074 | inadequate monitoring of employee activity | critical | 10.0 | 1 | data breach |
| 2075 | Unrotated Factory-Default Logins | critical | 10.0 | 1 | Cyber Espionage |
| 2076 | CVE-2026-8053 | critical | 10.0 | 1 | Vulnerability |
| 2077 | over_permissive_cloud_settings | critical | 10.0 | 1 | ransomware |
| 2078 | Unmonitored ESXCLI Command Usage | critical | 10.0 | 1 | Ransomware Prevention Guide |
| 2079 | Outdated Junos OS routers | critical | 10.0 | 1 | Espionage |
| 2080 | Exposed NAS devices | critical | 10.0 | 1 | Ransomware |
| 2081 | Local privilege escalation | critical | 10.0 | 1 | Exploit Kit / Cyber Espionage |
| 2082 | Weak data protections | critical | 10.0 | 1 | Data Breach |
| 2083 | reliance on IT generalists without specialized security training | critical | 10.0 | 1 | ransomware |
| 2084 | human error (e.g., clicking malicious links) | critical | 10.0 | 1 | phishing |
| 2085 | Human behavior | critical | 10.0 | 1 | Illegal intrusion |
| 2086 | CVE-2025-55182 (React2Shell, CVSS 10.0) | critical | 10.0 | 1 | Web Application Exploitation |
| 2087 | Insufficient Integration Lifecycle Management | critical | 10.0 | 1 | Supply Chain Attack |
| 2088 | prolonged lapses in security oversight | critical | 10.0 | 1 | data breach |
| 2089 | External call to 'transfer' function using a fake hash | critical | 10.0 | 1 | Cryptocurrency Theft |
| 2090 | Log4Shell vulnerability in an unpatched VMware Horizon server | critical | 10.0 | 1 | Hacking |
| 2091 | urgency/authority manipulation | critical | 10.0 | 1 | social engineering |
| 2092 | CVE-2021-26828 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2093 | CVE-2025-20337 | critical | 10.0 | 1 | Remote Code Execution |
| 2094 | Internal Login | critical | 10.0 | 1 | Data Breach |
| 2095 | CVE-2025-52562 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2096 | Improper Access Controls / Platform Misconfiguration | critical | 10.0 | 1 | Data Exposure |
| 2097 | human vulnerabilities (vishing, native-language social engineering) | critical | 10.0 | 1 | ransomware |
| 2098 | Insufficient security controls, governance gaps, vendor-related risks | critical | 10.0 | 1 | Ransomware Attack |
| 2099 | Authentication key theft | critical | 10.0 | 1 | Data Breach |
| 2100 | Poor Patch Management | critical | 10.0 | 1 | Compliance Failure |
| 2101 | unsecured_API | critical | 10.0 | 1 | ransomware |
| 2102 | open ports | critical | 10.0 | 1 | Ransomware |
| 2103 | User Information Exposure | critical | 10.0 | 1 | Data Breach |
| 2104 | Abuse of Legitimate Tools (BITSAdmin) | critical | 10.0 | 1 | Targeted Attack |
| 2105 | Poor Vendor/Third-Party Risk Management | critical | 10.0 | 1 | Ransomware |
| 2106 | Misuse of authorized access to medical records under false pretenses | critical | 10.0 | 1 | Data Breach |
| 2107 | Partial Logging of Data Access | critical | 10.0 | 1 | Insider Threat |
| 2108 | Log4Shell vulnerability | critical | 10.0 | 1 | Cyber Attack |
| 2109 | interconnected manufacturing systems | critical | 10.0 | 1 | cyberattack |
| 2110 | outsourcing risks | critical | 10.0 | 1 | data breach |
| 2111 | uneven cybersecurity maturity | critical | 10.0 | 1 | data breach |
| 2112 | Exposure management adoption | critical | 10.0 | 1 | Ransomware Prediction |
| 2113 | CVE-2025-59469 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2114 | CVE-2025-6218 | critical | 10.0 | 1 | Cyberespionage |
| 2115 | Lack of multi-factor authentication, Lack of encryption | critical | 10.0 | 1 | Data Breach, Ransomware |
| 2116 | Lack of Multi-Factor Authentication (MFA) for high-value targets | critical | 10.0 | 1 | Cyber Theft |
| 2117 | Misconfigured permissions, weak access controls, over-privileged identities | critical | 10.0 | 1 | Misconfiguration, Privilege Escalation, Data Exfiltration, AI Security |
| 2118 | CVE-2025-52691 (SmarterMail) | critical | 10.0 | 1 | ransomware |
| 2119 | Weak Authentication (compromised social media accounts) | critical | 10.0 | 1 | Cyber Theft |
| 2120 | Legacy System Risks | critical | 10.0 | 1 | Data Breach |
| 2121 | CVE-2026-31431 (Incorrect resource transfer between spheres, CWE-699) | critical | 10.0 | 1 | Privilege Escalation |
| 2122 | lack of physical safeguards | critical | 10.0 | 1 | infrastructure vulnerability |
| 2123 | overlooked vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2124 | Lack of MFA on FortiGate VPN devices | critical | 10.0 | 1 | Destructive Cyberattack |
| 2125 | lack of actionable alerting | critical | 10.0 | 1 | ransomware |
| 2126 | Stack Buffer Overflow | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2127 | Zero-day vulnerability in Oracle E-Business Suite (EBS) financial application | critical | 10.0 | 1 | Data Breach |
| 2128 | AI Model Vulnerabilities | critical | 10.0 | 1 | State-Backed Surveillance & Hacking |
| 2129 | Lack of Data Processing Agreements (DPAs/DSAs) | critical | 10.0 | 1 | Data Privacy Violation |
| 2130 | Lack of Password or Encryption | critical | 10.0 | 1 | Data Exposure |
| 2131 | lack of package verification in CI/CD pipelines | critical | 10.0 | 1 | supply chain attack |
| 2132 | JetBrains TeamCity | critical | 10.0 | 1 | Ransomware |
| 2133 | Lack of HIPAA-compliant risk analysis | critical | 10.0 | 1 | Ransomware |
| 2134 | Unpatched Systems (Historical) | critical | 10.0 | 1 | Data Breach |
| 2135 | Unprotected Fax Server | critical | 10.0 | 1 | Data Breach |
| 2136 | Human factor (credentials theft) | critical | 10.0 | 1 | Phishing |
| 2137 | API Key Exposure | critical | 10.0 | 1 | Supply Chain Attack |
| 2138 | Exposed network devices and vulnerabilities in OT systems | critical | 10.0 | 1 | Cyberattack on Critical Infrastructure |
| 2139 | Poisoned machine-learning models | critical | 10.0 | 1 | Malware Framework |
| 2140 | Chrome zero-day (fifth in 2026) | critical | 10.0 | 1 | ransomware |
| 2141 | Incorrect access permissions and configuration settings | critical | 10.0 | 1 | Data Breach |
| 2142 | Third-Party Supplier Weakness | critical | 10.0 | 1 | Ransomware |
| 2143 | CVE-2026-20045 (Improper input validation in HTTP requests) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2144 | Delayed Incident Notification | critical | 10.0 | 1 | Cybersecurity Incident |
| 2145 | CVE-2026-23918 (double free memory corruption) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2146 | WinRAR RCE | critical | 10.0 | 1 | Cybercrime Forum Seizure |
| 2147 | Known vulnerabilities in DNN platform | critical | 10.0 | 1 | Data Breach |
| 2148 | Insufficient IT resources | critical | 10.0 | 1 | Cyberattack |
| 2149 | CVE-2017-7921 (CWE-287: Improper Authentication) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2150 | cross-border supplier networks | critical | 10.0 | 1 | ransomware |
| 2151 | Infostealer malware infection, lack of multi-factor authentication, static security question, unchanged default credentials | critical | 10.0 | 1 | Unauthorized Access |
| 2152 | weak account/access controls (reactivation of default accounts, new privileged users) | critical | 10.0 | 1 | ransomware |
| 2153 | Claude Code tool's contextual safeguard limitations | critical | 10.0 | 1 | cyberespionage |
| 2154 | CV_2025_03_1 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2155 | Abuse of Native Windows Utilities (curl, certutil) | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 2156 | CVE-2025-27915 (Stored XSS in Zimbra Classic Web Client via ICS files) | critical | 10.0 | 1 | Cyber Espionage |
| 2157 | CVE-2026-25108 | critical | 10.0 | 1 | OS Command Injection |
| 2158 | YellowKey (BitLocker bypass) | critical | 10.0 | 1 | Zero-day vulnerability |
| 2159 | CVE-2025-33053 (WebDAV External Control of File Name or Path) | critical | 10.0 | 1 | Patch Release |
| 2160 | Unmonitored third-party script dependencies | critical | 10.0 | 1 | Data Breach |
| 2161 | supply chain trust abuse | critical | 10.0 | 1 | supply chain attack |
| 2162 | Insufficient Identity Security Policies for AI Agents | critical | 10.0 | 1 | Identity Security Crisis |
| 2163 | Lack of Timely Detection (6-month delay) | critical | 10.0 | 1 | Supply Chain Attack |
| 2164 | Improperly secured AJAX action (CVE not specified) | critical | 10.0 | 1 | Privilege Escalation |
| 2165 | Cisco AnyConnect software vulnerability | critical | 10.0 | 1 | Data Breach |
| 2166 | Outdated Android versions | critical | 10.0 | 1 | Malware |
| 2167 | Legacy Firewall Deployments (single point of failure for ecosystems) | critical | 10.0 | 1 | Predictive Analysis |
| 2168 | CVE-2026-4368 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2169 | Security gaps in industrial networks | critical | 10.0 | 1 | Cyber Espionage |
| 2170 | Persistent IT/OT silos | critical | 10.0 | 1 | Cyber Espionage |
| 2171 | OpenClaw WebSocket-based AI agent framework vulnerability | critical | 10.0 | 1 | Zero-Click Exploit |
| 2172 | weak insider threat detection | critical | 10.0 | 1 | data breach |
| 2173 | CVE-2025-4427 | critical | 10.0 | 1 | Cyber Espionage |
| 2174 | abuse of legitimate code-signing certificates | critical | 10.0 | 1 | ransomware |
| 2175 | Remote-file-transfer vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2176 | Microsoft 365 authorization flows | critical | 10.0 | 1 | Phishing |
| 2177 | lack of asset visibility | critical | 10.0 | 1 | unauthorized access |
| 2178 | Internet-exposed systems | critical | 10.0 | 1 | Cyber Threat Alert |
| 2179 | CVE-2023-6895 (Hikvision - OS command injection) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 2180 | usbliter8 (BootROM misconfiguration in Synopsys DesignWare USB2 controller) | critical | 10.0 | 1 | Hardware Vulnerability |
| 2181 | Ineffective DMARC Protection | critical | 10.0 | 1 | Data Breach |
| 2182 | OAuth Application Abuse | critical | 10.0 | 1 | Data Breach |
| 2183 | Weak default passwords, unpatched vulnerabilities | critical | 10.0 | 1 | Cyberattack |
| 2184 | Known vulnerability in data storage systems | critical | 10.0 | 1 | Ransomware Attack |
| 2185 | CVE-2020-12641 | critical | 10.0 | 1 | Cyberespionage |
| 2186 | Third-Party Customer Service Provider (Discord) | critical | 10.0 | 1 | Data Breach |
| 2187 | Free-for-Teacher Accounts | critical | 10.0 | 1 | Data Breach |
| 2188 | Insufficient endpoint detection and response (EDR) | critical | 10.0 | 1 | Ransomware |
| 2189 | CVE-2026-27685 (Insecure deserialization in SAP NetWeaver Enterprise Portal Administration) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2190 | CVE-2026-3564 (CWE-347: Improper Verification of Cryptographic Signature) | critical | 10.0 | 1 | Cryptographic Vulnerability |
| 2191 | Improper handling of BOOTP file field in DHCP server responses (CVE-2026-42511) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2192 | help-desk protocol vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2193 | Unknown vulnerabilities in routers and VPN appliances | critical | 10.0 | 1 | Botnet |
| 2194 | Human vulnerability (tricking employees into divulging credentials) | critical | 10.0 | 1 | Data Breach / Ransomware Attack |
| 2195 | identity governance gaps | critical | 10.0 | 1 | ransomware |
| 2196 | XAML deserialization | critical | 10.0 | 1 | Cyber Espionage |
| 2197 | Unvetted Browser Extensions (Cyberhaven Hack, 35+ Extensions in 2024) | critical | 10.0 | 1 | Browser-Based Attack |
| 2198 | CVE-2026-3502 (CVSS 7.8) | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2199 | PCI DSS 4.0.1 compliance gaps in client-side data protection | critical | 10.0 | 1 | Data Breach |
| 2200 | Predictable defense patterns | critical | 10.0 | 1 | AI-driven cyberattack |
| 2201 | Obfuscated .NET Reactor-protected infostealer, JIT compilation hooking (clrjit.dll!getJit) | critical | 10.0 | 1 | Supply Chain Attack |
| 2202 | CVE-2026-3502 (Download of Code Without Integrity Check - CWE-494) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2203 | TerraMaster NAS Vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2204 | Weaknesses in maritime navigation security protocols | critical | 10.0 | 1 | GPS spoofing |
| 2205 | Poorly Secured ICS | critical | 10.0 | 1 | Cyberattack |
| 2206 | Potential CVE-2023-29357 (SharePoint RCE, linked to summer 2023 exploits) | critical | 10.0 | 1 | Data Breach |
| 2207 | Azure Automation Service Vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2208 | GitHub Workflows Misconfiguration | critical | 10.0 | 1 | Supply Chain Attack |
| 2209 | Cryptographic Protocols | critical | 10.0 | 1 | Cryptographic Risk |
| 2210 | Irregular software patching | critical | 10.0 | 1 | Ransomware |
| 2211 | CVE-2026-31694 (Heap Overflow in FUSE Subsystem) | critical | 10.0 | 1 | Privilege Escalation |
| 2212 | Indirect prompt injection | critical | 10.0 | 1 | Data Privacy and Cybersecurity Advisory |
| 2213 | Stored Credentials in Veeam Backup Infrastructure | critical | 10.0 | 1 | Social Engineering |
| 2214 | Process Drift in Third-Party Service Desk | critical | 10.0 | 1 | Social Engineering |
| 2215 | overlooked software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2216 | Unknown flaw in Oracle E-Business Suite (EBS) | critical | 10.0 | 1 | Data Breach |
| 2217 | Legitimate cloud administrative tools | critical | 10.0 | 1 | Data Exfiltration |
| 2218 | Technical know-how gap in solvent extraction | critical | 10.0 | 1 | Geopolitical Risk |
| 2219 | No AI-Enabled Identity Threat Detection | critical | 10.0 | 1 | Identity Security Crisis |
| 2220 | Weak vendor credentials | critical | 10.0 | 1 | Data Breach |
| 2221 | Zero-day vulnerability (claimed by Qilin) | critical | 10.0 | 1 | Ransomware |
| 2222 | CVE-2024-57727 (SimpleHelp remote code execution) | critical | 10.0 | 1 | ransomware |
| 2223 | Insufficient Real-Time Threat Intelligence | critical | 10.0 | 1 | Domain Hijacking |
| 2224 | Ivanti Endpoint Manager Mobile | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2225 | Oracle E-Business Suite (EBS) exploit (unspecified) | critical | 10.0 | 1 | potential data breach |
| 2226 | Vulnerability allowing linkage of email addresses and phone numbers to Twitter accounts | critical | 10.0 | 1 | Data Breach |
| 2227 | Weak vendor compliance enforcement | critical | 10.0 | 1 | Ransomware |
| 2228 | Alert Fatigue and False Positives | critical | 10.0 | 1 | EDR/XDR Evasion |
| 2229 | Remote Work Security Blind Spots | critical | 10.0 | 1 | Cybercrime |
| 2230 | Unsecured devices and networks | critical | 10.0 | 1 | Ransomware |
| 2231 | maritime domain awareness gaps | critical | 10.0 | 1 | espionage |
| 2232 | Misconfigured Email Security Solutions (Mimecast, Proofpoint, Barracuda) | critical | 10.0 | 1 | Data Breach |
| 2233 | limited transparency in global supply chains | critical | 10.0 | 1 | supply chain attack |
| 2234 | Limited Budget/Resources | critical | 10.0 | 1 | Collaborative Initiative |
| 2235 | human error (social engineering via phishing) | critical | 10.0 | 1 | cyberespionage |
| 2236 | Known vulnerability in the email system | critical | 10.0 | 1 | Data Breach |
| 2237 | Outdated versions of Windows | critical | 10.0 | 1 | Data Breach, Ransomware |
| 2238 | CVE-2026-40175 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2239 | Caching Error | critical | 10.0 | 1 | Data Breach |
| 2240 | CVE-2025-1316 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2241 | Cross-Site Scripting (XSS) flaws | critical | 10.0 | 1 | Cyber Espionage |
| 2242 | Inadequate Email Security Protocols | critical | 10.0 | 1 | Data Breach |
| 2243 | CVE-2025-10035 (GoAnywhere MFT, CVSS 10.0) | critical | 10.0 | 1 | data breach |
| 2244 | Authenticated Reflected XSS | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2245 | CVE-2021-44228 (Log4j) | critical | 10.0 | 1 | cyberespionage |
| 2246 | Absence of Subresource Integrity (SRI) checks | critical | 10.0 | 1 | Data Breach |
| 2247 | CVE-2023-20867 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 2248 | Network infiltration | critical | 10.0 | 1 | Security Concerns |
| 2249 | Lack of MFA on Personal/Social Media Accounts | critical | 10.0 | 1 | Phishing (Non-Email) |
| 2250 | Physical accessibility of undersea infrastructure | critical | 10.0 | 1 | Physical sabotage (cyber-physical attack) |
| 2251 | Unknown vulnerabilities in operating systems and browsers | critical | 10.0 | 1 | Ransomware |
| 2252 | trusted communications impersonation | critical | 10.0 | 1 | phishing |
| 2253 | CVE-2025-2502 | critical | 10.0 | 1 | Outage and Vulnerability |
| 2254 | weaknesses in AIS (Automatic Identification System) authentication | critical | 10.0 | 1 | AIS spoofing |
| 2255 | Failure to randomize hostnames in VMmanager, KMS-enabled unlicensed operation | critical | 10.0 | 1 | ransomware |
| 2256 | CVE-2025-47171 (Windows Netlogon Use of Uninitialized Resources) | critical | 10.0 | 1 | Patch Release |
| 2257 | CVE-2025-2783 | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 2258 | Social Engineering, Excessive Permissions | critical | 10.0 | 1 | Data Breach, Extortion, Harassment |
| 2259 | SAP Netweaver (specific details undisclosed) | critical | 10.0 | 1 | Cyberattack |
| 2260 | Inadequate Redaction | critical | 10.0 | 1 | Data Breach |
| 2261 | Compromised Mailing List | critical | 10.0 | 1 | Phishing |
| 2262 | Privacy Regulation Non-Compliance | critical | 10.0 | 1 | Ransomware |
| 2263 | CVE-2025-3835 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2264 | System Migration Bug | critical | 10.0 | 1 | Data Breach |
| 2265 | RC4 encryption (obsolete since 1980s) | critical | 10.0 | 1 | ransomware |
| 2266 | lack_of_verified_security_controls | critical | 10.0 | 1 | data_at_risk |
| 2267 | Lack of Advanced DNS Monitoring | critical | 10.0 | 1 | Domain Hijacking |
| 2268 | visibility gaps | critical | 10.0 | 1 | ransomware |
| 2269 | CVE-2023-4966 (Citrix Bleed) | critical | 10.0 | 1 | Ransomware |
| 2270 | CVE-2025-47962 (Windows SDK EoP) | critical | 10.0 | 1 | Patch Release |
| 2271 | CVE-2026-24747 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2272 | Social Engineering (Disguised as Legitimate npm Package) | critical | 10.0 | 1 | Malware Campaign |
| 2273 | Publicly Accessible Executive Profiles (for AI Phishing) | critical | 10.0 | 1 | Supply Chain Attack |
| 2274 | Limited control over shipping and air cargo spaces | critical | 10.0 | 1 | Economic Vulnerability |
| 2275 | Weak vendor security controls | critical | 10.0 | 1 | Ransomware |
| 2276 | Third-party systems (Famly platform and one other unnamed system) | critical | 10.0 | 1 | data breach |
| 2277 | CVE-2026-1492 | critical | 10.0 | 1 | Privilege Escalation |
| 2278 | CVE-2026-22898 (Missing authentication check in QVR Pro) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2279 | Fragmented Cybersecurity Governance (no common procedures) | critical | 10.0 | 1 | Ransomware |
| 2280 | Supply-chain vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2281 | Informant Malfeasance | critical | 10.0 | 1 | Dissemination of Propaganda and Child Abuse Material |
| 2282 | CVE-2017-17215 (TP-Link Routers) | critical | 10.0 | 1 | Botnet / DDoS Campaign |
| 2283 | Input validation bypass in MWEB transactions | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 2284 | CVE-2025-22224 | critical | 10.0 | 1 | Ransomware |
| 2285 | cloud security weaknesses | critical | 10.0 | 1 | ransomware |
| 2286 | Unauthenticated file uploads | critical | 10.0 | 1 | Cyberattack |
| 2287 | Lack of Cybersecurity Preparedness | critical | 10.0 | 1 | Ransomware Attack |
| 2288 | Human vulnerabilities (compromised adviser accounts) | critical | 10.0 | 1 | Data Breach |
| 2289 | Compromised AWS API key via supply-chain attack on Trivy | critical | 10.0 | 1 | Data Breach |
| 2290 | Improper data classification procedures | critical | 10.0 | 1 | Data Breach |
| 2291 | Unsecured Self-Service Password Reset | critical | 10.0 | 1 | Cyber Espionage |
| 2292 | Lack of Segmentation | critical | 10.0 | 1 | Data Exposure |
| 2293 | CVE-2022-29499 | critical | 10.0 | 1 | Ransomware |
| 2294 | CWE-22: Path Traversal in Docker build context configuration (smithery.yaml) | critical | 10.0 | 1 | Supply Chain Attack |
| 2295 | no password protection on critical servers | critical | 10.0 | 1 | data breach |
| 2296 | CVE-2025-10035 (Critical vulnerability in Fortra's GoAnywhere MFT) | critical | 10.0 | 1 | Ransomware |
| 2297 | Lack of basic security features such as two-factor authentication | critical | 10.0 | 1 | Data Breach |
| 2298 | Insufficient insider threat controls | critical | 10.0 | 1 | Data Breach |
| 2299 | lack of tamper-proof audit trails | critical | 10.0 | 1 | ransomware |
| 2300 | Poor authentication controls | critical | 10.0 | 1 | Data Breach |
| 2301 | RxRPC Page-Cache Write | critical | 10.0 | 1 | Local Privilege Escalation (LPE) |
| 2302 | Entra ID application registration secrets | critical | 10.0 | 1 | cyberespionage |
| 2303 | Flaw in CI/CD pipeline | critical | 10.0 | 1 | Supply-Chain Attack |
| 2304 | Insecure Data Storage Practices | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2305 | Understaffed Security Operations Center (SOC) | critical | 10.0 | 1 | Data Breach |
| 2306 | Valid Login Information | critical | 10.0 | 1 | Data Breach |
| 2307 | Email reply-chain exploitation | critical | 10.0 | 1 | Phishing |
| 2308 | Drupal core security flaw (unspecified) | critical | 10.0 | 1 | Vulnerability |
| 2309 | vendor distribution pipelines | critical | 10.0 | 1 | ransomware |
| 2310 | Lack of Regular Penetration Testing | critical | 10.0 | 1 | Data Breach |
| 2311 | Lack of Data Review Process / Gross Negligence | critical | 10.0 | 1 | Data Breach |
| 2312 | Weak Security Controls at Third-Party Contractor | critical | 10.0 | 1 | Data Breach |
| 2313 | CVE-2025-59689 (Command injection in Libraesva ESG) | critical | 10.0 | 1 | Zero-day exploitation |
| 2314 | Coding vulnerability in the 'DNA Relatives' feature | critical | 10.0 | 1 | Data Breach |
| 2315 | CVE-2026-1207 | critical | 10.0 | 1 | SQL Injection |
| 2316 | Misconfigurations in operational technology (OT) systems | critical | 10.0 | 1 | Exposure of Critical Infrastructure |
| 2317 | CVE-2026-20093 | critical | 10.0 | 1 | Authentication Bypass |
| 2318 | CVE-2025-32713 (Windows Common Log File System Driver EoP) | critical | 10.0 | 1 | Patch Release |
| 2319 | network vulnerabilities (unspecified) | critical | 10.0 | 1 | ransomware |
| 2320 | Improper Whitelisting of Microsoft CDB | critical | 10.0 | 1 | APT (Advanced Persistent Threat) |
| 2321 | CVE-2025-30333 | critical | 10.0 | 1 | Data Breach, Persistent Malware, Unauthorized Access |
| 2322 | CVE-2025-55125 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2323 | Known vulnerability in cloud storage services | critical | 10.0 | 1 | Data Breach |
| 2324 | CVE-2025-61882 (Critical, CVSS 9.8) | critical | 10.0 | 1 | Ransomware |
| 2325 | CVE-2026-1579 (Missing Authentication for Critical Function) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2326 | CVE-2018-13379 | critical | 10.0 | 1 | Ransomware |
| 2327 | GenAI Prompt Leakage | critical | 10.0 | 1 | Cyber-Attack |
| 2328 | CVE-2025-0921, CVE-2024-7587 | critical | 10.0 | 1 | Denial-of-Service (DoS) |
| 2329 | Legitimate signed drivers | critical | 10.0 | 1 | Ransomware |
| 2330 | Vulnerabilities in MOVEit software | critical | 10.0 | 1 | Cyberattack |
| 2331 | CVE-2026-54420 | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2332 | Improper access controls and lack of technical safeguards | critical | 10.0 | 1 | Data Breach |
| 2333 | CVE not specified (algif_aead module in Linux kernel’s AF_ALG cryptographic subsystem) | critical | 10.0 | 1 | Privilege Escalation |
| 2334 | Outdated EnCase driver (EnPortv.sys) with revoked certificate, Windows signature validation loophole for pre-2015 certificates | critical | 10.0 | 1 | BYOVD (Bring Your Own Vulnerable Driver) |
| 2335 | Citrix NetScaler Gateway Appliance (unspecified CVE) | critical | 10.0 | 1 | Cyber Espionage |
| 2336 | Internet-facing edge devices (40% targeted by China-nexus actors) | critical | 10.0 | 1 | AI-driven cyber threats |
| 2337 | Remote Disabling Capability | critical | 10.0 | 1 | Repurposing of Commercial Technology for Military Use |
| 2338 | CVE-2023-50224 | critical | 10.0 | 1 | Credential Harvesting |
| 2339 | Absence of Multi-Factor Authentication (MFA) | critical | 10.0 | 1 | Ransomware |
| 2340 | Microsoft SharePoint ToolShell vulnerabilities (zero-day, patched post-exploitation) | critical | 10.0 | 1 | Ransomware |
| 2341 | Lack of strict removable media controls, insufficient monitoring of privileged users | critical | 10.0 | 1 | Insider Threat, Data Exfiltration |
| 2342 | Potential vulnerability in screen monitoring software | critical | 10.0 | 1 | Ransomware |
| 2343 | Outsourced IT support vendor | critical | 10.0 | 1 | Social Engineering |
| 2344 | Immutable Log Gaps in AI Pipelines | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 2345 | Insufficient Physical Security for Fiber-Optic Cables | critical | 10.0 | 1 | Cyber Espionage |
| 2346 | Schneider Electric safety equipment | critical | 10.0 | 1 | Cyberattack |
| 2347 | Lack of Real-Time Monitoring for Undersea Infrastructure | critical | 10.0 | 1 | Physical Sabotage |
| 2348 | Improper input sanitization in telnetd authentication mechanism (CWE-20) | critical | 10.0 | 1 | Authentication Bypass |
| 2349 | Insufficient Disaster Recovery Plans | critical | 10.0 | 1 | Supply Chain Attack |
| 2350 | Auto-update mechanisms | critical | 10.0 | 1 | Session Hijacking |
| 2351 | CVE-2025-32714 (Windows Installer EoP) | critical | 10.0 | 1 | Patch Release |
| 2352 | Previously exposed data breach (Gmail account) | critical | 10.0 | 1 | Cyber Espionage |
| 2353 | Shallow Depth of Baltic Sea (Ease of Anchor Damage) | critical | 10.0 | 1 | Physical Sabotage |
| 2354 | Poor Data Residency Enforcement | critical | 10.0 | 1 | Data Breach Risk |
| 2355 | CVE-2024-21893 | critical | 10.0 | 1 | Ransomware |
| 2356 | Architectural weakness in LLM input processing and trust boundaries | critical | 10.0 | 1 | Zero-Click Remote Code Execution (RCE) |
| 2357 | CVE-2026-29058 (CWE-78: Improper Neutralization of Special Elements) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2358 | CVE-2026-27944 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2359 | Misconfigured or unprotected cloud logging mechanisms (AWS CloudTrail, Google Cloud Logging) | critical | 10.0 | 1 | Cloud Security Incident |
| 2360 | Windows SMB vulnerability (MS17-010), Unpatched systems, Windows XP | critical | 10.0 | 1 | Ransomware |
| 2361 | Persistent jailbreak of Google Gemini AI, Weak non-English safety controls, Memory retention flaws, Stolen API keys, Trojanized software (StellarMonster) | critical | 10.0 | 1 | Fraud, Credential Theft, Cryptocurrency Theft, Social Engineering |
| 2362 | CVE-2026-2329 (Stack-based buffer overflow in /cgi-bin/api.values.Get endpoint) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 2363 | File System Access API in Chrome/Chromium-based browsers | critical | 10.0 | 1 | Ransomware |
| 2364 | CVE-2025-42999 | critical | 10.0 | 1 | vulnerability |
| 2365 | Data susceptible to interception or misuse during cloud processing | critical | 10.0 | 1 | Privacy Breach |
| 2366 | lack of package cooldown periods | critical | 10.0 | 1 | supply chain attack |
| 2367 | AI's inability to recognize malicious intent in fragmented tasks | critical | 10.0 | 1 | cyberespionage |
| 2368 | Legitimate Tools Abuse (Bitsadmin, PowerShell, curl) | critical | 10.0 | 1 | Targeted Cyberattack |
| 2369 | Kaseya VSA platform | critical | 10.0 | 1 | Ransomware Attack |
| 2370 | Inadequate Contractual Security Provisions | critical | 10.0 | 1 | Data Breach |
| 2371 | CVE-2020-3259 (Cisco) | critical | 10.0 | 1 | ransomware |
| 2372 | Lack of browser-layer visibility | critical | 10.0 | 1 | Session Hijacking |
| 2373 | Unsecured cloud environment, lack of proper oversight | critical | 10.0 | 1 | Data Breach |
| 2374 | CVE-2024-7694 | critical | 10.0 | 1 | Supply Chain Attack |
| 2375 | Unsecured RDP access, absence of MFA | critical | 10.0 | 1 | Ransomware |
| 2376 | Weak supply chain controls for hardware distribution | critical | 10.0 | 1 | Espionage |
| 2377 | Security protocol bypass, weak access controls, anti-virus circumvention, secret key exposure in source code | critical | 10.0 | 1 | Insider Threat / AI Exploitation |
| 2378 | Zero-day exploits, Supply-chain weaknesses | critical | 10.0 | 1 | Supply-chain attack, Data exfiltration, Reconnaissance |
| 2379 | EternalBlue (WannaCry, 2017) | critical | 10.0 | 1 | ransomware |
| 2380 | Memory Injection (persistent threat mechanism) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2381 | npm supply chain compromise (Nx platform) | critical | 10.0 | 1 | Supply Chain Attack |
| 2382 | lack of MFA on critical systems | critical | 10.0 | 1 | ransomware |
| 2383 | AI voice cloning limitations | critical | 10.0 | 1 | social engineering |
| 2384 | Lack of Cybersecurity Protocols | critical | 10.0 | 1 | Cybercrime |
| 2385 | Unspecified Salesforce vulnerability (likely API or authentication flaw) | critical | 10.0 | 1 | Data Breach |
| 2386 | third-party tokens | critical | 10.0 | 1 | ransomware |
| 2387 | Cisco IOS vulnerabilities | critical | 10.0 | 1 | Data Breach |
| 2388 | CVE-2021-36380 | critical | 10.0 | 1 | Cyber Attack |
| 2389 | CVE-2025-58434 (Unauthenticated Password Reset Token Disclosure in `/api/v1/account/forgot-password`) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2390 | Zero-day vulnerability in GoAnywhere MFT (Managed File Transfer) software | critical | 10.0 | 1 | Data Breach |
| 2391 | CVE-2022-41082 | critical | 10.0 | 1 | Ransomware |
| 2392 | CVE-2026-1490 (Authorization Bypass via Reverse DNS Spoofing) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2393 | CrushFTP | critical | 10.0 | 1 | Ransomware |
| 2394 | Cisco-related exploits | critical | 10.0 | 1 | Ransomware |
| 2395 | Unknown authentication bug, Insider knowledge of security procedures | critical | 10.0 | 1 | Corporate Espionage, Trade Secret Theft |
| 2396 | Technical vulnerabilities | critical | 10.0 | 1 | Illegal intrusion |
| 2397 | Lack of real-time threat-sharing incentives | critical | 10.0 | 1 | Policy/Regulatory Failure |
| 2398 | Weak DNS Security Extensions (DNSSEC) Implementation | critical | 10.0 | 1 | Domain Hijacking |
| 2399 | Unpatched Software (e.g., Equifax) | critical | 10.0 | 1 | Data Breach |
| 2400 | Vimar smart home devices | critical | 10.0 | 1 | DDoS Attack |
| 2401 | Vulnerability in Huawei routers' VRP network operating system | critical | 10.0 | 1 | Cyberattack |
| 2402 | preventable software vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2403 | operational lapses in rule propagation | critical | 10.0 | 1 | data breach |
| 2404 | Information Disclosure Vulnerability | critical | 10.0 | 1 | Information Disclosure |
| 2405 | Compromised Software Development Tools | critical | 10.0 | 1 | Malware |
| 2406 | CVE in Tridium’s Niagara Framework (13 vulnerabilities, Nozomi Networks) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 2407 | CVE-2026-33725 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2408 | CVE-2025-30401 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2409 | CVE-2024-2658 (CWE-427: Uncontrolled Search Path Element) | critical | 10.0 | 1 | Privilege Escalation |
| 2410 | CVE-2025-21042 (Samsung Android image processing library) | critical | 10.0 | 1 | spyware |
| 2411 | Infected Barcode Scanners | critical | 10.0 | 1 | Data Breach |
| 2412 | CVE-2025-49156 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2413 | LLM scope violation (CVE-2025-32711) | critical | 10.0 | 1 | Data Breach Vulnerability |
| 2414 | zero-day vulnerabilities in PDF readers | critical | 10.0 | 1 | ransomware |
| 2415 | Lack of End-to-End Email Encryption | critical | 10.0 | 1 | Data Breach |
| 2416 | Security Vulnerabilities in Verizon’s Web site | critical | 10.0 | 1 | Data Breach |
| 2417 | Data Sharing with Third-Party AI Services | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 2418 | End-of-support (EoS) devices (ASA 5500-X Series) | critical | 10.0 | 1 | Zero-day exploitation |
| 2419 | weak supply chain links | critical | 10.0 | 1 | ransomware |
| 2420 | CVE-2026-20181 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2421 | CVE-2026-54400 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2422 | CVE-2024-12345 | critical | 10.0 | 1 | Cyber Espionage |
| 2423 | Lack of Data Handling Training | critical | 10.0 | 1 | Data Breach |
| 2424 | Unpatched IoT/OT Systems | critical | 10.0 | 1 | EDR/XDR Evasion |
| 2425 | Lack of adequate security measures for USIM data (SK Telecom) | critical | 10.0 | 1 | Data Breach |
| 2426 | CVE-2024-12297 | critical | 10.0 | 1 | Vulnerability Exploit |
| 2427 | Weak Endpoint Detection | critical | 10.0 | 1 | Targeted Cyberattack |
| 2428 | unpatched software (suspected) | critical | 10.0 | 1 | data breach |
| 2429 | CVE-2026-1995 (Improper file permission handling in id_service.exe) | critical | 10.0 | 1 | Privilege Escalation |
| 2430 | Exposed credentials and access tokens | critical | 10.0 | 1 | Ransomware |
| 2431 | Over-Permissioned IAM Roles | critical | 10.0 | 1 | Predictive Analysis |
| 2432 | Unauthorized access to cloud servers | critical | 10.0 | 1 | Data Breach |
| 2433 | CVE-2025-69258 (LoadLibraryEX vulnerability in MsgReceiver.exe) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2434 | Vulnerability in Ivanti's security products | critical | 10.0 | 1 | Malware |
| 2435 | CVE-2026-48172 (CWE-266: Improper Privilege Management) | critical | 10.0 | 1 | Privilege Escalation |
| 2436 | Type confusion vulnerabilities in Java Card | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2437 | insufficient incident response plans | critical | 10.0 | 1 | phishing |
| 2438 | Unmonitored Privileged Accounts | critical | 10.0 | 1 | Data Breach |
| 2439 | CVE-2026-3055 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2440 | Zero-day vulnerability in a third-party application (unspecified) | critical | 10.0 | 1 | Ransomware Attack |
| 2441 | Insufficient data access controls | critical | 10.0 | 1 | Data Exfiltration |
| 2442 | Known vulnerabilities in backbone routers | critical | 10.0 | 1 | Cyber Espionage |
| 2443 | CVE-2019-7192 | critical | 10.0 | 1 | Cyber Intrusion |
| 2444 | Lack of Centralized Log Management | critical | 10.0 | 1 | Data Breach |
| 2445 | Firewall rule exposing RDP on a management server | critical | 10.0 | 1 | Ransomware |
| 2446 | CVE-2026-34908 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2447 | CVE-2016-10033 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2448 | Untrusted App Sources | critical | 10.0 | 1 | Awareness Campaign |
| 2449 | outdated web forms | critical | 10.0 | 1 | ransomware |
| 2450 | Publicly accessible Raiko SGX enclave signing key on GitHub | critical | 10.0 | 1 | Exploit |
| 2451 | Shared-Service Model Vulnerabilities | critical | 10.0 | 1 | Cyberattack |
| 2452 | Default/weak passwords | critical | 10.0 | 1 | Cyber Espionage |
| 2453 | Social engineering (MFA bypass via Teams screen-sharing) | critical | 10.0 | 1 | Espionage |
| 2454 | VMware vSphere vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2455 | GHSA-7xvx-8pf2-pv5g (CVSS 9.1) | critical | 10.0 | 1 | Sandbox Escape Vulnerability |
| 2456 | CVE-2025-2492 | critical | 10.0 | 1 | botnet |
| 2457 | Insufficient Backup Protocols | critical | 10.0 | 1 | Ransomware |
| 2458 | CVE-2025-7027 | critical | 10.0 | 1 | Firmware Vulnerability |
| 2459 | Modified Files on Server | critical | 10.0 | 1 | Data Breach |
| 2460 | Unpatched VPN Devices | critical | 10.0 | 1 | Supply Chain Attack |
| 2461 | CVE-2026-4372 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2462 | Design Flaws | critical | 10.0 | 1 | Data Breach |
| 2463 | Human Trust, Lack of Investment Verification | critical | 10.0 | 1 | Investment Scam, Money Laundering, Cryptocurrency Fraud |
| 2464 | Lack of real-time detection for initial intrusion (May 14 to August 24) | critical | 10.0 | 1 | Ransomware Attack |
| 2465 | weaknesses in AIS protocol | critical | 10.0 | 1 | spoofing |
| 2466 | Stale Identity Tokens | critical | 10.0 | 1 | Data Breach |
| 2467 | CVE-2025-8876 (Command Injection via Improper Input Sanitization) | critical | 10.0 | 1 | Vulnerability Exposure |
| 2468 | Lack of Access Controls During Layoffs | critical | 10.0 | 1 | Data Breach |
| 2469 | CVE-2024-1709 (ScreenConnect) | critical | 10.0 | 1 | Ransomware |
| 2470 | CVEs in Cisco's routers | critical | 10.0 | 1 | Data Breach |
| 2471 | Undisclosed Zero-Day in Oracle E-Business Suite | critical | 10.0 | 1 | Data Breach |
| 2472 | CVE-2026-35273 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2473 | Bypassed consent protocols, vulnerabilities in offshored data-management tools | critical | 10.0 | 1 | Data Breach |
| 2474 | Disabled authentication in VNC servers | critical | 10.0 | 1 | Exposed Servers |
| 2475 | unpatched VPN appliances | critical | 10.0 | 1 | ransomware |
| 2476 | Human Error (Compliance with Fraudulent Requests) | critical | 10.0 | 1 | Data Breach |
| 2477 | CVE-2026-57807 (Broken Authentication - CWE-288) | critical | 10.0 | 1 | Authentication Bypass |
| 2478 | Unauthorized disclosure of SL2000 and SL3000 certificates | critical | 10.0 | 1 | Data Breach |
| 2479 | MFA bypass techniques | critical | 10.0 | 1 | phishing |
| 2480 | 20+ Vulnerabilities | critical | 10.0 | 1 | AI-Powered Cyberattack |
| 2481 | Customer Edge (CE) routers | critical | 10.0 | 1 | Cyber Espionage |
| 2482 | Excessive agent authority | critical | 10.0 | 1 | AI-driven breach |
| 2483 | Unauthenticated Reboot Commands | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2484 | AES-CMAC algorithm flaw | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2485 | over-reliance on technological defenses | critical | 10.0 | 1 | phishing |
| 2486 | VPN weaknesses | critical | 10.0 | 1 | ransomware |
| 2487 | Gaps in anomaly detection for behavioral baselines | critical | 10.0 | 1 | Ransomware |
| 2488 | Lack of anti-jamming protection for GPS systems | critical | 10.0 | 1 | GPS jamming |
| 2489 | MOVEit software | critical | 10.0 | 1 | Data Breach |
| 2490 | Improper input sanitization in GNU InetUtils telnetd (USER environment variable handling) | critical | 10.0 | 1 | Authentication Bypass |
| 2491 | Potential vulnerabilities in NSCC’s infrastructure, outdated 2020 admin manual for HPC3 supercomputer cluster | critical | 10.0 | 1 | Data Breach |
| 2492 | CVE-2026-46316 (ITScape) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2493 | Fragmented security standards across subcontractors | critical | 10.0 | 1 | Ransomware |
| 2494 | Insecure support ticketing platform (bulk data export without rate-limiting or access controls) | critical | 10.0 | 1 | Data Breach |
| 2495 | Misconfigured Elasticsearch Cluster | critical | 10.0 | 1 | Data Breach |
| 2496 | Human error (opening infected email attachment) | critical | 10.0 | 1 | cyber espionage |
| 2497 | Microsoft Silverlight plugin flaw | critical | 10.0 | 1 | Ransomware |
| 2498 | CVE-2026-22755 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2499 | Exposed industrial control ports (TCP/44818, TCP/2222, TCP/502, TCP/22) | critical | 10.0 | 1 | Cyber Espionage |
| 2500 | Weak Token Management in Drift Integration | critical | 10.0 | 1 | Supply Chain Attack |
| 2501 | Windows minifilter drivers | critical | 10.0 | 1 | Ransomware |
| 2502 | Unsecured Kibana Dashboard | critical | 10.0 | 1 | Data Leak |
| 2503 | Unlocked AWS S3 bucket | critical | 10.0 | 1 | Data Breach |
| 2504 | Windows kernel vulnerabilities | critical | 10.0 | 1 | Data Exfiltration, Ransomware, Extortion |
| 2505 | Malicious macros in a document titled 'Act.doc' | critical | 10.0 | 1 | Cyberattack |
| 2506 | CVE-2023-20269 (Cisco) | critical | 10.0 | 1 | ransomware |
| 2507 | network security issues | critical | 10.0 | 1 | third-party breach |
| 2508 | Critical vulnerabilities, unpatched systems, dark web credentials | critical | 10.0 | 1 | Supply Chain Attack |
| 2509 | React2Shell (CVE-2025-29927) | critical | 10.0 | 1 | Cloud Exploitation Campaign |
| 2510 | Mutable version tags | critical | 10.0 | 1 | Supply Chain Attack, Extortion Campaign |
| 2511 | Insecure Backups | critical | 10.0 | 1 | Compliance Failure |
| 2512 | Unpatched vulnerability in appointment system software | critical | 10.0 | 1 | Data Breach |
| 2513 | Poorly secured ATG systems | critical | 10.0 | 1 | Cyberattack |
| 2514 | Inadequately tested code in Token Bridge smart contracts, lack of secure coding practices, and absence of automated fraud monitoring | critical | 10.0 | 1 | Data Breach, Cryptocurrency Theft |
| 2515 | Cryptographic Implementation Flaws | critical | 10.0 | 1 | Security Vulnerability |
| 2516 | Self-Service Password Reset (SSPR) | critical | 10.0 | 1 | Data Exfiltration |
| 2517 | flat network architectures | critical | 10.0 | 1 | ransomware |
| 2518 | Hardware Vulnerabilities | critical | 10.0 | 1 | Hardware Vulnerability Exploitation |
| 2519 | IoT Device Vulnerabilities | critical | 10.0 | 1 | Cybercrime |
| 2520 | Lack of multifactor authentication (MFA) on administrator accounts | critical | 10.0 | 1 | Data Breach |
| 2521 | xfrm-ESP Page-Cache Write | critical | 10.0 | 1 | Local Privilege Escalation (LPE) |
| 2522 | human error (employee downloading malware-laced tool) | critical | 10.0 | 1 | ransomware |
| 2523 | Fraudulently obtained digital certificates, Lack of Azure tenant credential security | critical | 10.0 | 1 | Malware Distribution / Ransomware Enablement |
| 2524 | CVE-2024-12297 (Frontend Authorization Logic Disclosure) | critical | 10.0 | 1 | Authentication Bypass |
| 2525 | Direct Internet Exposure | critical | 10.0 | 1 | Cyber-Physical Attack |
| 2526 | Weak credentials (e.g., built-in *sa* account) | critical | 10.0 | 1 | Ransomware |
| 2527 | CVE-2026-41940 (cPanel Authentication Bypass) | critical | 10.0 | 1 | Data Breach |
| 2528 | CVE-2025-10035 | critical | 10.0 | 1 | Ransomware Attack |
| 2529 | Weak governance mechanisms | critical | 10.0 | 1 | DeFi Exploit |
| 2530 | CVE-2021-22681 (Rockwell Automation ICS) | critical | 10.0 | 1 | ransomware |
| 2531 | PROMISQROUTE (Prompt-based Router Open-Mode Manipulation Induced via SSRF-like Queries, Reconfiguring Operations Using Trust Evasion) | critical | 10.0 | 1 | AI System Vulnerability |
| 2532 | CVE-2022-22948 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 2533 | Compromised LiteLLM library | critical | 10.0 | 1 | Supply Chain Attack |
| 2534 | known vulnerabilities | critical | 10.0 | 1 | ransomware |
| 2535 | excessive email/mailbox permissions (shared read access) | critical | 10.0 | 1 | cyberespionage |
| 2536 | Lack of Real-Time Threat Detection | critical | 10.0 | 1 | Third-Party Breach |
| 2537 | Stolen credentials, malicious links in trusted email chains, phishing campaigns | critical | 10.0 | 1 | Supply Chain Attack, Cargo Theft |
| 2538 | SonicWall | critical | 10.0 | 1 | Supply Chain Attack |
| 2539 | Inadequate identity verification processes | critical | 10.0 | 1 | Espionage |
| 2540 | Lack of IT Oversight | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 2541 | CVE-2025-36535 (Missing Authentication in MB-Gateway Devices) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2542 | Stale service accounts | critical | 10.0 | 1 | Ransomware |
| 2543 | Fragmented security in third-party hardware | critical | 10.0 | 1 | Privacy Breach |
| 2544 | Improper Use of Collaboration Tools (WhatsApp, Microsoft Forms) | critical | 10.0 | 1 | Data Breach |
| 2545 | Compromised contractor credentials (specific vulnerability undisclosed) | critical | 10.0 | 1 | Data Breach |
| 2546 | insecure credential storage in CI/CD environments | critical | 10.0 | 1 | supply chain attack |
| 2547 | Azure RBAC Misconfiguration | critical | 10.0 | 1 | Data Exfiltration |
| 2548 | zero-day vulnerabilities in SaaS provider cloud environments | critical | 10.0 | 1 | cyberespionage |
| 2549 | Poor key management and access controls | critical | 10.0 | 1 | Data Breach |
| 2550 | CVE-2026-1731 (OS command injection, CWE-78) | critical | 10.0 | 1 | Zero-Day Vulnerability |
| 2551 | CVE-2026-32202 (Windows Shell Spoofing) | critical | 10.0 | 1 | Data Breach |
| 2552 | Infection via official website | critical | 10.0 | 1 | Ransomware |
| 2553 | Unspecified (32% of attacks involved exploited vulnerabilities) | critical | 10.0 | 1 | ransomware |
| 2554 | unknown (zero-day) | critical | 10.0 | 1 | cyberattack |
| 2555 | Unpatched Software (50% of CVEs in last 5 years) | critical | 10.0 | 1 | Ransomware |
| 2556 | Human Error (Support Staff Tricked via Impersonation) | critical | 10.0 | 1 | Data Breach |
| 2557 | CVE-2026-3854 (GitHub Enterprise Server RCE) | critical | 10.0 | 1 | Data Breach |
| 2558 | CVE-2026-0826 (Stack-based buffer overflow in SDP attribute parsing) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2559 | CVE-2025-7026 | critical | 10.0 | 1 | Firmware Vulnerability |
| 2560 | Overwhelmed network infrastructure, misconfigurations, unused ports | critical | 10.0 | 1 | DDoS |
| 2561 | Blind SQL Vulnerability | critical | 10.0 | 1 | Data Breach |
| 2562 | Ivanti Cloud Service Appliances | critical | 10.0 | 1 | Supply Chain Attack |
| 2563 | Misaligned agent workflows | critical | 10.0 | 1 | AI-driven breach |
| 2564 | CVE-2026-49102 | critical | 10.0 | 1 | XSS |
| 2565 | Interconnexion entre datacenter et réseau internet | critical | 10.0 | 1 | DDoS |
| 2566 | weak Wi-Fi security | critical | 10.0 | 1 | cyber-espionage |
| 2567 | AI guardrail bypass | critical | 10.0 | 1 | AI-powered cyberattack |
| 2568 | Lack of multi-factor authentication (MFA) on a critical server | critical | 10.0 | 1 | ransomware |
| 2569 | Typosquatted Zoom links | critical | 10.0 | 1 | Phishing |
| 2570 | Unpinned GitHub Actions dependencies | critical | 10.0 | 1 | Supply Chain Attack |
| 2571 | Velociraptor CVE-2025-6264 (privilege escalation to arbitrary command execution) | critical | 10.0 | 1 | Ransomware |
| 2572 | Obfuscation Techniques | critical | 10.0 | 1 | Malware Infection |
| 2573 | Broken Authentication (CWE-287) | critical | 10.0 | 1 | Unauthorized Access |
| 2574 | failures in basic cyber hygiene | critical | 10.0 | 1 | ransomware |
| 2575 | Exposed secrets in S3 buckets and CI/CD environments, overly permissive cloud permissions | critical | 10.0 | 1 | Cloud Intrusion |
| 2576 | UNECE R155 Non-Compliance (Insecure Deployed Software) | critical | 10.0 | 1 | Cybersecurity Vulnerability Assessment |
| 2577 | Weak Authentication (e.g., VPN Passwords) | critical | 10.0 | 1 | Cyber Espionage |
| 2578 | Insufficient multi-factor authentication (MFA) protections | critical | 10.0 | 1 | Ransomware |
| 2579 | CVE-2020-35730 | critical | 10.0 | 1 | Cyberespionage |
| 2580 | Weak or default credentials ('Password123', 'Austal123') purchased on the dark web | critical | 10.0 | 1 | ransomware |
| 2581 | SQL Injection in Main Application | critical | 10.0 | 1 | Data Breach |
| 2582 | Legacy system integration vulnerabilities during platform consolidation | critical | 10.0 | 1 | Ransomware Attack |
| 2583 | CVE-2023-28252 (Cisco) | critical | 10.0 | 1 | ransomware |
| 2584 | lack of continuous verification | critical | 10.0 | 1 | phishing |
| 2585 | identity and access weaknesses | critical | 10.0 | 1 | ransomware |
| 2586 | CVE-2025-8875 (Insecure Deserialization Leading to Command Execution) | critical | 10.0 | 1 | Vulnerability Exposure |
| 2587 | CVE-2015-2291 | critical | 10.0 | 1 | Cyberattack |
| 2588 | Compliance Blind Spots in Cross-Border AI Data Flows | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 2589 | Weak Access Controls (e.g., AWS Misconfigurations) | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 2590 | CVE-2020-3580 (Cisco) | critical | 10.0 | 1 | ransomware |
| 2591 | Weak Identity Management (Lack of Privileged Account Separation) | critical | 10.0 | 1 | Cyber Espionage |
| 2592 | CVE-2023-41345 | critical | 10.0 | 1 | botnet |
| 2593 | unpatched Veeam backup servers | critical | 10.0 | 1 | ransomware |
| 2594 | CVE-2025-20362 (Memory corruption in Cisco ASA Software) | critical | 10.0 | 1 | Zero-day exploitation |
| 2595 | CVE-2025-0282 (Ivanti Pulse Connect VPN) | critical | 10.0 | 1 | cyberespionage |
| 2596 | Insufficient Input Validation (CWE-20) | critical | 10.0 | 1 | Unauthorized Access |
| 2597 | CVE-2023-41347 | critical | 10.0 | 1 | botnet |
| 2598 | JIT compiler hijacking, .NET Reactor obfuscation, static constructor execution | critical | 10.0 | 1 | Supply Chain Attack |
| 2599 | Outdated Fortinet VPNs | critical | 10.0 | 1 | Ransomware |
| 2600 | Outdated IT infrastructure, obsolete software (Lotus Notes), aging hardware | critical | 10.0 | 1 | Infrastructure Vulnerability |
| 2601 | Overwhelming a server or website with excessive fake traffic | critical | 10.0 | 1 | DDoS Attack |
| 2602 | Actively exploited CVEs | critical | 10.0 | 1 | Ransomware |
| 2603 | cloud migration risks | critical | 10.0 | 1 | ransomware |
| 2604 | Lack of contractual compliance and oversight, unauthorized offshore access | critical | 10.0 | 1 | Data Breach |
| 2605 | Mobile Device Management (MDM) system | critical | 10.0 | 1 | Espionage, Data Breach |
| 2606 | Log4j (CVE-2021-44228) | critical | 10.0 | 1 | ransomware |
| 2607 | Predictable bucket naming in Google Cloud Vertex AI, lack of bucket ownership verification, unsafe Python pickle deserialization | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2608 | CVE-2024-12686 | critical | 10.0 | 1 | Breach |
| 2609 | Lax network security | critical | 10.0 | 1 | Data Breach |
| 2610 | Excessive user permissions | critical | 10.0 | 1 | Ransomware |
| 2611 | Authenticated Local File Inclusion | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2612 | Security flaw in Neighbors app | critical | 10.0 | 1 | Data Breach |
| 2613 | gaps in patching | critical | 10.0 | 1 | Ransomware |
| 2614 | Inadequate input validation and output encoding in Jira’s custom priority settings | critical | 10.0 | 1 | Stored Cross-Site Scripting (XSS) |
| 2615 | CVE-2024-20353 (Infinite Loop DoS) | critical | 10.0 | 1 | Cyberattack |
| 2616 | Check Point gateway devices | critical | 10.0 | 1 | Supply Chain Attack |
| 2617 | Unburied or Lightly Buried Cables in Steep Terrain | critical | 10.0 | 1 | Physical Sabotage |
| 2618 | Publicly Indexed 'Recent Links' Pages | critical | 10.0 | 1 | Data Leak |
| 2619 | Insecure Protocols (e.g., Telnet) | critical | 10.0 | 1 | Cyber Espionage |
| 2620 | CEA-852 Standard Weaknesses | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2621 | Vulnerabilities in AI development platforms | critical | 10.0 | 1 | AI-driven cyber threats |
| 2622 | Lack of anti-jamming measures in ferry's GPS system | critical | 10.0 | 1 | GPS jamming |
| 2623 | CVE-2026-55200 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2624 | ProxyLogon (Microsoft Exchange) | critical | 10.0 | 1 | cyberespionage |
| 2625 | Publicly Accessible Industrial Control Systems | critical | 10.0 | 1 | Ransomware |
| 2626 | GPS reliance | critical | 10.0 | 1 | GPS spoofing (disputed) |
| 2627 | Unpatched zero-day vulnerability in Oracle E-Business Suite (arbitrary code execution) | critical | 10.0 | 1 | ransomware |
| 2628 | CVE-2025-20352 (Cisco IOS SNMP Flaw) | critical | 10.0 | 1 | Ransomware |
| 2629 | CVE-2024-7587 | critical | 10.0 | 1 | Vulnerabilities in SCADA Systems |
| 2630 | Uncontrolled AI Tool Integration | critical | 10.0 | 1 | Data Breach Risk |
| 2631 | Compromised third-party vendor credentials | critical | 10.0 | 1 | Data Breach |
| 2632 | CVE-2026-21902 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2633 | On Device Fraud (ODF) techniques | critical | 10.0 | 1 | Malware |
| 2634 | Legitimate Identity Abuse | critical | 10.0 | 1 | Data Breach |
| 2635 | Lack of AI Agent Safeguards | critical | 10.0 | 1 | Espionage |
| 2636 | Unsecured internet-facing devices (used by China-affiliated actors) | critical | 10.0 | 1 | Extortion |
| 2637 | Misconfigured cloud infrastructure | critical | 10.0 | 1 | Cloud Exploitation Campaign |
| 2638 | Cultural Gap Between IT/OT Teams | critical | 10.0 | 1 | Cyber-Physical Attack |
| 2639 | Claude Code Model Safeguard Bypass | critical | 10.0 | 1 | Espionage |
| 2640 | Oracle zero-day (Clop gang) | critical | 10.0 | 1 | ransomware |
| 2641 | Human Trust Vulnerability | critical | 10.0 | 1 | Data Breach |
| 2642 | outdated business continuity plans | critical | 10.0 | 1 | ransomware |
| 2643 | CVE-2025-42957 (ABAP Code Injection in SAP S/4HANA) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2644 | Windows Defender Disabling | critical | 10.0 | 1 | Ransomware |
| 2645 | SonicWall SSL VPN Misconfiguration | critical | 10.0 | 1 | Unauthorized Access |
| 2646 | Time-Triggered Ethernet (TTEthernet) vulnerabilities | critical | 10.0 | 1 | Time Synchronization Attack |
| 2647 | CVE-2026-33634 (CWE-506) | critical | 10.0 | 1 | Supply Chain Attack |
| 2648 | CVE-2026-9082 | critical | 10.0 | 1 | SQL Injection |
| 2649 | Windows Driver Signature Enforcement bypass via signed driver abuse | critical | 10.0 | 1 | Ransomware |
| 2650 | default LDAP group configurations | critical | 10.0 | 1 | ransomware |
| 2651 | Outdated Security Software | critical | 10.0 | 1 | Awareness Campaign |
| 2652 | Deteriorating cyber defenses | critical | 10.0 | 1 | Cyberattack |
| 2653 | CVE-2023-3519 | critical | 10.0 | 1 | Ransomware |
| 2654 | Lack of In-House Cybersecurity Expertise (17% of shipyards) | critical | 10.0 | 1 | Ransomware |
| 2655 | Internal System Compromise (mechanism unspecified) | critical | 10.0 | 1 | Data Breach |
| 2656 | Lack of encryption or authentication in GPS signals | critical | 10.0 | 1 | GPS spoofing |
| 2657 | CVE-2022-41328 | critical | 10.0 | 1 | Advanced Persistent Threat (APT) |
| 2658 | Previously undetected vulnerability | critical | 10.0 | 1 | Ransomware Attack |
| 2659 | BACnet/Modbus Protocol Flaws (No Encryption/Authentication) | critical | 10.0 | 1 | Cybersecurity Vulnerability Exposure |
| 2660 | Static Authentication Methods (vulnerable to deepfakes) | critical | 10.0 | 1 | Predictive Analysis |
| 2661 | Vulnerability in Canvas’s 'Free for Teacher' accounts | critical | 10.0 | 1 | Data Breach, Ransomware |
| 2662 | CVE-2026-10520 | critical | 10.0 | 1 | OS Command Injection |
| 2663 | Fake suspicious activity notifications | critical | 10.0 | 1 | Phishing |
| 2664 | CVE-2026-34910 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2665 | Lack of Monitoring for Insider Threats | critical | 10.0 | 1 | SCADA Tampering / Insider Threat |
| 2666 | Outdated remote access policies | critical | 10.0 | 1 | Ransomware |
| 2667 | Browser Sandbox Exploitation (Clipboard Access) | critical | 10.0 | 1 | Social Engineering |
| 2668 | Critical RCE vulnerability in widely used VPN | critical | 10.0 | 1 | RCE (Remote Code Execution) |
| 2669 | CVE-2025-61155 | critical | 10.0 | 1 | Ransomware |
| 2670 | Insecure systems | critical | 10.0 | 1 | Ransomware Attack |
| 2671 | blind spots in network visibility | critical | 10.0 | 1 | ransomware |
| 2672 | CVE-2026-0489 (DOM-based XSS in SAP Business One Job Service) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2673 | Sonatype Nexus | critical | 10.0 | 1 | Cyberattack (Reconnaissance Campaign) |
| 2674 | Volume Shadow Copy Service | critical | 10.0 | 1 | Ransomware |
| 2675 | Malware in plug-ins | critical | 10.0 | 1 | Data Privacy and Cybersecurity Advisory |
| 2676 | RenderShock 0-Click Vulnerability | critical | 10.0 | 1 | Zero-Click Attack |
| 2677 | Employee Use of Unvetted AI Tools | critical | 10.0 | 1 | Unauthorized AI Deployment |
| 2678 | Physical Infrastructure | critical | 10.0 | 1 | Sabotage |
| 2679 | Zero-day vulnerability in Oracle E-Business Suite | critical | 10.0 | 1 | Ransomware |
| 2680 | Weaknesses and biases in AI models | critical | 10.0 | 1 | Red-Teaming Event |
| 2681 | Access to sensitive infrastructure data | critical | 10.0 | 1 | Insider Threat |
| 2682 | CVE-2025-10035 (Critical, CVSS 10.0) in Fortra GoAnywhere MFT | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2683 | Browser session tokens | critical | 10.0 | 1 | Ransomware |
| 2684 | CVE-2021-33044 (Dahua - authentication bypass) | critical | 10.0 | 1 | Cyber Espionage, Reconnaissance |
| 2685 | Unsafe `pull_request_target` trigger | critical | 10.0 | 1 | Supply Chain Attack |
| 2686 | UnDefend | critical | 10.0 | 1 | Zero-Day Exploitation |
| 2687 | Exposure of GitHub token | critical | 10.0 | 1 | Vulnerability |
| 2688 | Interconnexion non sécurisée entre IT et OT | critical | 10.0 | 1 | Cyberattaque ciblée |
| 2689 | LiteLLM | critical | 10.0 | 1 | Ransomware |
| 2690 | Zero-day vulnerabilities in cloud infrastructure/SaaS platforms | critical | 10.0 | 1 | Cybercriminal Alliance Formation |
| 2691 | CVE-2023-46805 (Ivanti Connect Secure/Policy Secure) | critical | 10.0 | 1 | Ransomware |
| 2692 | Unpatched system (not disclosed) | critical | 10.0 | 1 | Ransomware |
| 2693 | Data blind spots | critical | 10.0 | 1 | Ransomware Prediction |
| 2694 | SonicWall SSLVPN (Weak MFA/Access Controls) | critical | 10.0 | 1 | Ransomware |
| 2695 | Newly disclosed global software vulnerabilities | critical | 10.0 | 1 | Ransomware |
| 2696 | Supply chain vulnerabilities in financial transaction software | critical | 10.0 | 1 | Ransomware |
| 2697 | Inadequate Data Redaction in Spreadsheets | critical | 10.0 | 1 | Data Breach |
| 2698 | Over-Permissive Guest/External User Access | critical | 10.0 | 1 | Social Engineering |
| 2699 | missing security patches | critical | 10.0 | 1 | data breach |
| 2700 | Publicly accessible links to call recordings/transcripts | critical | 10.0 | 1 | Data Breach |
| 2701 | Modified OpenSSH binaries, tampered PAM modules, custom implants (e.g., auditdb, SOCKS5 proxies) | critical | 10.0 | 1 | Cyber Espionage |
| 2702 | lack of physical security for copper wiring | critical | 10.0 | 1 | physical security breach |
| 2703 | Excessive Access Privileges | critical | 10.0 | 1 | Insider Threat |
| 2704 | exposed SMB services | critical | 10.0 | 1 | ransomware |
| 2705 | Supply chain compromise (malicious Axios update) | critical | 10.0 | 1 | Data Breach |
| 2706 | Authentication tokens harvested from Anodot, bypassing multi-factor authentication | critical | 10.0 | 1 | Data Breach |
| 2707 | Undocumented WordPress Installation | critical | 10.0 | 1 | Data Breach |
| 2708 | CVE-2026-9862 (OS Command Injection - CWE-78) | critical | 10.0 | 1 | Command Injection |
| 2709 | Insecure External Storage Device | critical | 10.0 | 1 | Data Breach |
| 2710 | SAP software vulnerability | critical | 10.0 | 1 | Cyberattack |
| 2711 | Weak internal security segmentation | critical | 10.0 | 1 | Data Breach |
| 2712 | Unpatched Software Vulnerabilities | critical | 10.0 | 1 | Malware |
| 2713 | Trojanized update | critical | 10.0 | 1 | Supply Chain Attack |
| 2714 | Lack of Secure Boot/Trust Anchor in ASA 5500-X Series | critical | 10.0 | 1 | Zero-day exploitation |
| 2715 | Public-facing file-sharing folder | critical | 10.0 | 1 | Ransomware |
| 2716 | Backup compromise | critical | 10.0 | 1 | Ransomware |
| 2717 | SolarWinds Orion Software | critical | 10.0 | 1 | Supply Chain Attack |
| 2718 | package registries | critical | 10.0 | 1 | ransomware |
| 2719 | Unpatched Self-Managed GitLab Community Edition | critical | 10.0 | 1 | Data Breach |
| 2720 | CVE-2026-31431 (Linux Kernel Privilege Escalation) | critical | 10.0 | 1 | Data Breach |
| 2721 | CVE-2026-55115 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2722 | Unsanitized Metadata | critical | 10.0 | 1 | Data Leak |
| 2723 | Unpatched bugs in internet-connected cameras | critical | 10.0 | 1 | Espionage |
| 2724 | Weakness in `url_safe` feature (Bing.com tracking link evasion) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2725 | Public Internet Exposure | critical | 10.0 | 1 | Exposure of Vulnerable Systems |
| 2726 | Lateral Movement via Salesforce OAuth | critical | 10.0 | 1 | Supply Chain Attack |
| 2727 | Poor IAM practices | critical | 10.0 | 1 | Ransomware |
| 2728 | Unsecured Data Storage | critical | 10.0 | 1 | Data Breach |
| 2729 | Ungoverned AI Systems | critical | 10.0 | 1 | Data Breach |
| 2730 | Microsoft Defender Race Condition | critical | 10.0 | 1 | AI Cybersecurity Risk |
| 2731 | CVE-2025-26399 | critical | 10.0 | 1 | Ransomware |
| 2732 | CVE-2025-8110 (Path traversal in PutContents API via symbolic links) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2733 | Compromised logistics systems and load boards | critical | 10.0 | 1 | Cyber-Enabled Cargo Theft |
| 2734 | CVE-2026-45247 (PHP object injection, CWE-502) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2735 | Exposed credentials through configuration API calls | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2736 | Spoofable Workflow Notifications | critical | 10.0 | 1 | Social Engineering |
| 2737 | Absence de formation des employés en cybersécurité | critical | 10.0 | 1 | Cyberattaque ciblée |
| 2738 | Improper oversight and mismanagement of data protection protocols | critical | 10.0 | 1 | Data Breach |
| 2739 | CVE-2023-28252 | critical | 10.0 | 1 | Ransomware |
| 2740 | Unsecured remote access tools | critical | 10.0 | 1 | Cyber Espionage |
| 2741 | Compromised Microsoft Entra account | critical | 10.0 | 1 | Data Breach |
| 2742 | CVE-2026-54402 | critical | 10.0 | 1 | Vulnerability Disclosure |
| 2743 | human error (weakness in operational security) | critical | 10.0 | 1 | cyber theft |
| 2744 | Dangling DNS records | critical | 10.0 | 1 | Subdomain Hijacking |
| 2745 | CVE-2024-24919 | critical | 10.0 | 1 | Ransomware |
| 2746 | Known flaws in outdated software | critical | 10.0 | 1 | Ransomware |
| 2747 | 23 exploits across five attack chains (iOS 13-17.2.1) | critical | 10.0 | 1 | Espionage |
| 2748 | CVE-2026-20963 (Microsoft SharePoint Server) | critical | 10.0 | 1 | ransomware |
| 2749 | Command Injection (QVD-2026-14149) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2750 | Unencrypted AI Training Datasets/Model Checkpoints | critical | 10.0 | 1 | Data Breach (AI Models/Applications) |
| 2751 | CVE-2026-20965 | critical | 10.0 | 1 | Unauthorized Access |
| 2752 | Insufficient Authentication and Verification Procedures | critical | 10.0 | 1 | Financial Fraud |
| 2753 | CVE-2026-46817 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2754 | Policy Non-Compliance | critical | 10.0 | 1 | Data Breach (Alleged) |
| 2755 | CVE-2026-44962 (Improper Neutralization of Data within XPath Expressions - CWE-643) | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2756 | CVE-2025-31324 (SAP NetWeaver) | critical | 10.0 | 1 | Ransomware |
| 2757 | CVE-2025-20281 | critical | 10.0 | 1 | Remote Code Execution |
| 2758 | Bun runtime environment detection | critical | 10.0 | 1 | supply chain attack |
| 2759 | VMware ESXi infrastructure (Linux ransomware) | critical | 10.0 | 1 | ransomware |
| 2760 | User Trust in Browser Prompts (Copy-Paste Commands, Fake Error Messages) | critical | 10.0 | 1 | Browser-Based Attack |
| 2761 | human error (clicking suspicious links) | critical | 10.0 | 1 | general cybersecurity awareness |
| 2762 | Weakened power grid infrastructure | critical | 10.0 | 1 | Cyberattack |
| 2763 | BlueKeep flaw | critical | 10.0 | 1 | Exposed Servers |
| 2764 | Spring4Shell | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2765 | Heap overflow in FFmpeg’s MagicYUV decoder (CVE-2026-8461) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2766 | Unauthorized physical access to sensitive data | critical | 10.0 | 1 | Data Theft |
| 2767 | CVE-2026-24135 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2768 | Lack of Behavioral Anomaly Detection | critical | 10.0 | 1 | Insider Threat |
| 2769 | Potential lack of redundant navigation systems | critical | 10.0 | 1 | GPS spoofing (disputed) |
| 2770 | Endpoint Detection and Response (EDR) and antivirus process termination | critical | 10.0 | 1 | Malware, Ransomware |
| 2771 | Saved Credentials in Browsers/Email Clients | critical | 10.0 | 1 | Account Compromise |
| 2772 | CVE-2024-32114 | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2773 | Broad systemic vulnerabilities including reliance on foreign manufacturing for supply chains, dependency on cyber-vulnerable space systems (GPS, satellite communications), and weaknesses in infrastructure resilience against climate events. | critical | 10.0 | 1 | Ransomware Attack |
| 2774 | Compromised open-source development tools | critical | 10.0 | 1 | Ransomware |
| 2775 | CVE-2025-37164 | critical | 10.0 | 1 | Botnet Campaign |
| 2776 | Weak password (no MFA) on internet-facing system | critical | 10.0 | 1 | Ransomware Attack |
| 2777 | Poor Vendor Security Practices | critical | 10.0 | 1 | Third-Party Breach |
| 2778 | Google Play Store Security | critical | 10.0 | 1 | Malware |
| 2779 | Lack of encryption and authentication in Modbus protocol | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2780 | Coding error in liquidity pools | critical | 10.0 | 1 | Cryptocurrency Heist |
| 2781 | CVE-2025-27520 | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2782 | CVE-2026-20266 (CWE-78) | critical | 10.0 | 1 | Vulnerability |
| 2783 | CVE-2026-43499 (GhostLock) | critical | 10.0 | 1 | Privilege Escalation, Container Escape |
| 2784 | Lack of proper security policies post-migration due to human error (single employee responsible for manual compilation without second-layer checks) | critical | 10.0 | 1 | data breach |
| 2785 | Lack of multi-factor authentication (MFA) on an outsourced partner’s administrator account | critical | 10.0 | 1 | Ransomware |
| 2786 | Unsecured Public Wi-Fi | critical | 10.0 | 1 | Awareness Campaign |
| 2787 | Zero-day vulnerability in enterprise software | critical | 10.0 | 1 | Data Breach, Ransomware |
| 2788 | Remote Control Software Vulnerability | critical | 10.0 | 1 | Phishing Attack |
| 2789 | Accessibility Services Permission, Device Admin Permission | critical | 10.0 | 1 | Malware (Ransomware-like) |
| 2790 | Ivanti Policy Secure | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2791 | CVE-2025-69263 (CVSS 7.5) | critical | 10.0 | 1 | Supply Chain Attack |
| 2792 | Over-Permissive Tool Access (e.g., Password Crackers, Network Scanners) | critical | 10.0 | 1 | Espionage |
| 2793 | Driver Vulnerability (eskle.sys for Anti-AV Bypass) | critical | 10.0 | 1 | Social Engineering |
| 2794 | Undisclosed vulnerabilities in F5 BIG-IP (actively patched but stolen pre-disclosure) | critical | 10.0 | 1 | Supply Chain Compromise |
| 2795 | Reused Apple ID logins | critical | 10.0 | 1 | Data Breach, Phishing |
| 2796 | outdated configurations | critical | 10.0 | 1 | ransomware |
| 2797 | Sinkclose vulnerability | critical | 10.0 | 1 | Vulnerability Exploitation |
| 2798 | Unauthorized transaction approvals | critical | 10.0 | 1 | Security Breach |
| 2799 | Delayed Response to Security Alerts | critical | 10.0 | 1 | Data Breach |
| 2800 | Content-Type confusion flaw in n8n's webhook and file handling mechanism (CVE-2026-21858) | critical | 10.0 | 1 | Remote Code Execution (RCE) |
| 2801 | Weak or Stolen Login Credentials | critical | 9.0 | 1 | Data Breach |
| 2802 | Unauthorized Access by Terminated Employee | critical | 9.0 | 1 | Data Breach |
| 2803 | Multiple vulnerabilities in Cisco Small Business RV Series routers | critical | 9.0 | 1 | Vulnerability Exploitation |
| 2804 | Misplaced Portable Flash Drive | critical | 9.0 | 1 | Data Breach |
| 2805 | Customer Accounts | critical | 9.0 | 1 | Credential Stuffing |
| 2806 | Lack of authentication controls | critical | 9.0 | 1 | Data Exposure |
| 2807 | File Transfer Service Provider | critical | 9.0 | 1 | Data Breach |
| 2808 | Accellion FTA server vulnerability | critical | 9.0 | 1 | Data Breach |
| 2809 | Past Data Breach | critical | 9.0 | 1 | Phishing Campaign |
| 2810 | Sophos Firewall versions 18.5 MR3 (18.5.3) | critical | 9.0 | 1 | Vulnerability Exploitation |
| 2811 | Charting software | critical | 9.0 | 1 | Ransomware |
| 2812 | Trusted Hiring Pipelines | critical | 8.5 | 1 | Malware Deployment |
| 2813 | Lack of access controls / improper employee oversight | critical | 8.5 | 1 | Unauthorized Access / Insider Threat |
| 2814 | Remote Access to Car Functions | critical | 8.5 | 1 | Vulnerability Exploit |
| 2815 | Vulnerability in Progress Software Corporation's MOVEit Transfer product | critical | 8.5 | 1 | Data Breach |
| 2816 | Insufficient identity verification in remote hiring processes, reliance on AI-assisted deception | critical | 8.5 | 1 | Employment Fraud / Identity Theft / Cyber Espionage |
| 2817 | Unfixed JavaScript execution flaw in Chromium Service Worker | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 2818 | Human error in file-sharing settings (Google Workspace for Education/Microsoft Education) | critical | 8.5 | 1 | Data Exposure |
| 2819 | CVE-2025-1080 | critical | 8.5 | 1 | Remote Code Execution |
| 2820 | Lack of user consent for data sharing with third-party ad platforms | critical | 8.5 | 1 | Privacy Violation |
| 2821 | Employee Bypass of Sanctioned Tools | critical | 8.5 | 1 | Data Leakage |
| 2822 | Lack of runtime risk controls | critical | 8.5 | 1 | AI-related identity breach |
| 2823 | Employee Access Abuse | critical | 8.5 | 1 | Data Leak |
| 2824 | Critical vulnerability in VIGI camera series | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2825 | GoAnywhere MFT (specific CVE not mentioned) | critical | 8.5 | 1 | Data Breach |
| 2826 | CVE-2025-22231 | critical | 8.5 | 1 | Vulnerability |
| 2827 | Server Security Issue | critical | 8.5 | 1 | Data Breach |
| 2828 | Abandoned domain takeover, lack of runtime URL validation in Microsoft add-ins | critical | 8.5 | 1 | Phishing |
| 2829 | Temporary unsecured storage of user data and PGP keys | critical | 8.5 | 1 | Data Breach |
| 2830 | Insufficient Bot Detection/Prevention | critical | 8.5 | 1 | Cyberattack |
| 2831 | Undocumented API endpoints, CORS misconfigurations, pagination bypasses | critical | 8.5 | 1 | Data Exposure / Alleged Breach |
| 2832 | Use of Pirated Corporate Software | critical | 8.5 | 1 | Info-Stealing |
| 2833 | Lack of AI Governance Policies | critical | 8.5 | 1 | Data Leakage |
| 2834 | WhatsApp Web | critical | 8.5 | 1 | Malware Campaign |
| 2835 | CVE-2026-44413 | critical | 8.5 | 1 | Privilege Escalation |
| 2836 | Improper pinning of user pages in `rds_message_zcopy_from_user()` function (RDS zerocopy send path) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 2837 | Systemic weaknesses in cybersecurity infrastructure | critical | 8.5 | 1 | Data Breach |
| 2838 | CVE-2026-42208 | critical | 8.5 | 1 | SQL Injection |
| 2839 | F5 BIG-IP AMP vulnerability | critical | 8.5 | 1 | data_breach |
| 2840 | Weak point in the network | critical | 8.5 | 1 | Data Breach |
| 2841 | Compromised package versions (2.6.0, 2.6.1, 2.6.2) | critical | 8.5 | 1 | Supply Chain Attack |
| 2842 | Mali GPU Data Compression | critical | 8.5 | 1 | Data Theft |
| 2843 | Broad permissions granted to browser extensions | critical | 8.5 | 1 | Data Theft |
| 2844 | Zero-day flaw in Oracle E-Business Suite (EBS) | critical | 8.5 | 1 | Data Breach |
| 2845 | CVE-2026-20163 (Improper Neutralization of Special Elements used in a Command - CWE-77) | critical | 8.5 | 1 | Remote Command Execution (RCE) |
| 2846 | Abuse of Bubble’s no-code platform infrastructure, complex JavaScript bundles, Shadow DOM structures | critical | 8.5 | 1 | Phishing |
| 2847 | CWE-601: URL Redirection to Untrusted Site (Open Redirect) (via token manipulation) | critical | 8.5 | 1 | Data Breach |
| 2848 | CVE-2026-20700 (Memory-corruption in dyld component) | critical | 8.5 | 1 | Zero-Day Exploit |
| 2849 | Zcash’s privacy layer vulnerability (4-year-old) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2850 | Unauthorized use of Stripe API key | critical | 8.5 | 1 | Data Breach |
| 2851 | Resource Constraints in DHS | critical | 8.5 | 1 | Security Oversight |
| 2852 | Third-party Salesforce tenant misconfiguration/access controls | critical | 8.5 | 1 | Data Breach |
| 2853 | Shared AWS infrastructure misconfiguration | critical | 8.5 | 1 | Data Breach |
| 2854 | Employee Impersonation | critical | 8.5 | 1 | Data Breach |
| 2855 | MOVEit application by IBM | critical | 8.5 | 1 | Data Breach |
| 2856 | Major Security Flaw in Website | critical | 8.5 | 1 | Data Exposure |
| 2857 | Human Error / Social Engineering | critical | 8.5 | 1 | Phishing Attack |
| 2858 | Chrome’s App-Bound Encryption (ABE) Bypass | critical | 8.5 | 1 | Infostealer Attack |
| 2859 | CVE-2026-25750 (Insecure `baseUrl` parameter in LangSmith Studio) | critical | 8.5 | 1 | API Misconfiguration |
| 2860 | CVE-2026-45585, CERT/CC VU#226679 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2861 | Server Vulnerabilities | critical | 8.5 | 1 | Smishing Scam |
| 2862 | Human Trust (Job Seekers) | critical | 8.5 | 1 | APT (Advanced Persistent Threat) |
| 2863 | CVE-2026-22218 (CVSS 7.1) | critical | 8.5 | 1 | Data Breach |
| 2864 | CVE-2026-21992 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 2865 | Lack of encryption in radio communications used by public health systems | critical | 8.5 | 1 | Data Breach |
| 2866 | CVE-2016-5817 (Critical SQL injection in Navis WebAccess) | critical | 8.5 | 1 | cyberattack |
| 2867 | MOVEit Transfer environment vulnerability | critical | 8.5 | 1 | Data Breach |
| 2868 | CVE-2026-23550 (CVSS 10.0) | critical | 8.5 | 1 | Privilege Escalation |
| 2869 | Microsoft 365 Android app flaw | critical | 8.5 | 1 | phishing |
| 2870 | lack of encryption and authentication (non-password-protected database) | critical | 8.5 | 1 | data exposure |
| 2871 | CVE-2025-54897 (SharePoint RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 2872 | CVE-2024-38200 (MSHTML/Trident engine RCE) | critical | 8.5 | 1 | Zero-Day Exploit |
| 2873 | Lack of Visibility into AI Data Flows | critical | 8.5 | 1 | AI Security Vulnerabilities |
| 2874 | Critical vulnerability | critical | 8.5 | 1 | Data Breach, Account Hijacking |
| 2875 | CVE-2025-60727 (Out-of-bounds read, CWE-125) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 2876 | Improper permission handling in Windows Error Reporting Service (wersvc.dll) | critical | 8.5 | 1 | Privilege Escalation |
| 2877 | previously_compromised_data | critical | 8.5 | 1 | data_breach |
| 2878 | Lack of user verification for extension authenticity and over-permissioned access | critical | 8.5 | 1 | Malware (Malicious Browser Extension) |
| 2879 | Vulnerability in SonicWall firewall | critical | 8.5 | 1 | Data Breach |
| 2880 | Social Engineering (Urgent KYC/Billing Alerts) | critical | 8.5 | 1 | Phishing Scam |
| 2881 | unsecured teacher credentials | critical | 8.5 | 1 | unauthorized access |
| 2882 | unencrypted patient records | critical | 8.5 | 1 | ransomware |
| 2883 | No Authentication by Default | critical | 8.5 | 1 | Misconfiguration |
| 2884 | Disabled security tools, outdated cyber hygiene practices | critical | 8.5 | 1 | Cyber Intrusion |
| 2885 | Insufficient Monitoring of EHR Access | critical | 8.5 | 1 | Data Breach |
| 2886 | MOVEit® Secure File Transfer software | critical | 8.5 | 1 | Data Breach |
| 2887 | Poor Staff Awareness of Insider Threats | critical | 8.5 | 1 | Unauthorized Access |
| 2888 | Path traversal (27.3%) | critical | 8.5 | 1 | API Security Breach |
| 2889 | SS7/Diameter Protocol Flaws | critical | 8.5 | 1 | Data Breach |
| 2890 | Gaps in safeguarding technical identifiers under the IAB Europe Transparency and Consent Framework (TCF) | critical | 8.5 | 1 | Data Exposure |
| 2891 | Inadequate Data Handling Controls | critical | 8.5 | 1 | Data Breach |
| 2892 | CVE-2026-25049 | critical | 8.5 | 1 | Supply Chain Attack |
| 2893 | CVE-2026-6684 (GPT partition scan loop) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 2894 | configuration gap in Amazon S3 server | critical | 8.5 | 1 | data breach |
| 2895 | Hardcoded file path in OpenSSL integration (CVE-2026-3991) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 2896 | Insufficient data security policies and controls | critical | 8.5 | 1 | Data Leak |
| 2897 | Unpatched Cloud Services | critical | 8.5 | 1 | Cloud Security Breach |
| 2898 | identity weaknesses | critical | 8.5 | 1 | credential compromise |
| 2899 | ClickFix technique | critical | 8.5 | 1 | phishing |
| 2900 | SSRF bypasses | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 2901 | Contact Discovery Mechanism Flaw | critical | 8.5 | 1 | Privacy Violation |
| 2902 | AI-Specific Attack Vectors (Prompt Injection, Model Poisoning) | critical | 8.5 | 1 | Supply Chain Attack |
| 2903 | Flawed eagerParseCliFlag function in main.tsx, improper CLI flag parsing, and workspace trust dialog bypass | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 2904 | CVE-2026-22219 (SSRF) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2905 | DOM-Based UI Manipulation | critical | 8.5 | 1 | Vulnerability Disclosure |
| 2906 | Inactive user accounts not deactivated | critical | 8.5 | 1 | Data Breach |
| 2907 | API key and access token theft | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2908 | Lack of authentication controls, Aftermarket modifications, Unrestricted AI-driven data collection, Subcontractor access to sensitive data | critical | 8.5 | 1 | Data Breach, Compliance Violation, Privacy Violation |
| 2909 | Lack of Timely Incident Reporting | critical | 8.5 | 1 | Data Breach |
| 2910 | open-source_software_vulnerabilities | critical | 8.5 | 1 | data_breach |
| 2911 | Fundamental trust vulnerability in AI safety guardrails (context-aware manipulation) | critical | 8.5 | 1 | AI Security Vulnerability Exploitation |
| 2912 | Misconfigured Redis Services | critical | 8.5 | 1 | Botnet Infection |
| 2913 | Pointer authentication (PAC) bypasses | critical | 8.5 | 1 | Exploit Kit |
| 2914 | Third-party vendor vulnerabilities (historical reference: Target 2013 breach) | critical | 8.5 | 1 | Data Breach |
| 2915 | Aeries Software | critical | 8.5 | 1 | Data Breach |
| 2916 | CVE-2025-47934 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2917 | Misconfigured Stravito Access (Internal Documents) | critical | 8.5 | 1 | Data Exposure |
| 2918 | CVE-2024-38197 | critical | 8.5 | 1 | Identity Spoofing |
| 2919 | Password recovery and sharing features | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 2920 | CVE-2026-5509 | critical | 8.5 | 1 | Command Injection |
| 2921 | Default Password on Code Repository | critical | 8.5 | 1 | Data Exposure |
| 2922 | CVE-2026-7312 (CVSS 10.0) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2923 | Improper packaging oversight | critical | 8.5 | 1 | Source Code Leak |
| 2924 | Lack of Authentication (No Password Protection) | critical | 8.5 | 1 | Data Exposure / Unsecured Database |
| 2925 | Hardcoded API Keys in Public Repositories and Websites | critical | 8.5 | 1 | Data Exposure |
| 2926 | Stolen Usernames and Passwords | critical | 8.5 | 1 | Data Breach |
| 2927 | missing server-side encryption | critical | 8.5 | 1 | data breach |
| 2928 | Accellion FTA (specific CVE not mentioned) | critical | 8.5 | 1 | Data Breach |
| 2929 | Zero-day vulnerability in third-party software platform | critical | 8.5 | 1 | Data Breach |
| 2930 | Improper handling of IPv6 extension headers in Comodo Internet Security | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 2931 | Feature flag misconfiguration (Split.io-based system) | critical | 8.5 | 1 | Data Exposure |
| 2932 | Progress MOVEit Transfer | critical | 8.5 | 1 | Data Breach |
| 2933 | Weak or Stolen OAuth Token Management (External App Connection to Salesforce) | critical | 8.5 | 1 | Data Breach |
| 2934 | ZombieAgent (prompt injection in ChatGPT Connectors/Apps feature) | critical | 8.5 | 1 | Prompt Injection |
| 2935 | delayed_software_patches | critical | 8.5 | 1 | data_breach |
| 2936 | CVE-2026-32996 | critical | 8.5 | 1 | Privilege Escalation |
| 2937 | CVE-2026-3519 | critical | 8.5 | 1 | vulnerability |
| 2938 | Cisco Unified Communications Manager (CM) bug | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2939 | Improper input sanitization (CWE-74) | critical | 8.5 | 1 | Information Disclosure |
| 2940 | Previously unknown vulnerability in Oracle E-Business Suite | critical | 8.5 | 1 | Data Breach |
| 2941 | Vulnerabilities in Google’s Salesforce environment | critical | 8.5 | 1 | Data Breach |
| 2942 | Unauthenticated file upload flaw in Magento Open Source, Magento Enterprise, Adobe Commerce, and Adobe Commerce with the B2B module | critical | 8.5 | 1 | Defacement, Unauthorized File Upload |
| 2943 | Unknown vulnerability in the spam quarantine server software | critical | 8.5 | 1 | Data Breach |
| 2944 | CVE-2025-33229 | critical | 8.5 | 1 | Vulnerability |
| 2945 | E-commerce Site Vulnerability | critical | 8.5 | 1 | Data Breach |
| 2946 | Stack-based buffer overflow (Libbiosig) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 2947 | Human Error (Employee Susceptibility to Social Engineering) | critical | 8.5 | 1 | Data Breach (Social Engineering) |
| 2948 | SQLi in Postgres MCP (bypassing read-only restrictions) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 2949 | CVE-2025-59489 (Unity Editor Command-Line Argument Injection) | critical | 8.5 | 1 | Vulnerability |
| 2950 | Third-party Cloud Service | critical | 8.5 | 1 | Data Breach |
| 2951 | third-party security gaps | critical | 8.5 | 1 | data breach |
| 2952 | Unencrypted HTTP update mechanism in FireAnt MetaKit | critical | 8.5 | 1 | Supply-chain attack |
| 2953 | improper access controls in the Texas Integrated Grant Reporting system | critical | 8.5 | 1 | data breach |
| 2954 | Unsecured admin panel, IDOR vulnerability | critical | 8.5 | 1 | Data Exposure |
| 2955 | Weak Password Reset Mechanisms | critical | 8.5 | 1 | Cyberattack |
| 2956 | Soliton Systems K.K FileZen | critical | 8.5 | 1 | APT Activity |
| 2957 | CVE-2025-49870 (Unauthenticated SQL Injection in PayPal IPN handling) | critical | 8.5 | 1 | Vulnerability |
| 2958 | Client-side vulnerabilities | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 2959 | Dormant but active credential from a prototype integration | critical | 8.5 | 1 | Data Breach, Extortion |
| 2960 | BeyondTrust (CVE-2026-1731) | critical | 8.5 | 1 | APT Activity |
| 2961 | CVE-2026-39987 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 2962 | Incorrect authorization (Lovable, CVE-2025-48757) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 2963 | CVE-2025-64496 | critical | 8.5 | 1 | Code Injection |
| 2964 | Critical security flaw allowing unauthorized 'super admin' account creation | critical | 8.5 | 1 | Data Breach |
| 2965 | AirSnitch (exploits gaps in MAC address, encryption key, and IP address linking across network layers) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2966 | Over-reliance on mutable version tags in CI/CD pipelines, stolen credentials | critical | 8.5 | 1 | Supply Chain Attack |
| 2967 | Improper Firebase security rules (publicly accessible database) | critical | 8.5 | 1 | Data Breach |
| 2968 | Visual Studio Code tasks.json | critical | 8.5 | 1 | Supply Chain Attack |
| 2969 | Persistent refresh_token in OpenAI Codex authentication | critical | 8.5 | 1 | Supply Chain Attack |
| 2970 | unprotected storage bucket | critical | 8.5 | 1 | data breach |
| 2971 | Unverified dependencies in development pipelines | critical | 8.5 | 1 | Supply-Chain Attack |
| 2972 | Lack of Security Reviews | critical | 8.5 | 1 | Security Oversight |
| 2973 | Lack of multi-factor authentication (MFA), Basic security lapses (MMH) | critical | 8.5 | 1 | Data Breach |
| 2974 | Confidential Virtual Machine (CVM) exploitation | critical | 8.5 | 1 | Zero-day vulnerability |
| 2975 | Weak Third-party Security | critical | 8.5 | 1 | Data Breach |
| 2976 | Human error in CMS settings (defaulted to public URLs unless manually restricted) | critical | 8.5 | 1 | Data Leak |
| 2977 | CVE-2024-55591 (FortiOS/FortiProxy) | critical | 8.5 | 1 | ransomware |
| 2978 | CVE-2026-1234 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 2979 | SonicWall SSL VPN vulnerabilities | critical | 8.5 | 1 | ransomware |
| 2980 | Absence of phishing-resistant MFA | critical | 8.5 | 1 | Data Breach |
| 2981 | MOVEit file transfer tool (global exploit) | critical | 8.5 | 1 | Data Breach |
| 2982 | CVE-2025-3155 | critical | 8.5 | 1 | Vulnerability Exploit |
| 2983 | Oracle E-Business Suite vulnerabilities | critical | 8.5 | 1 | Cyberattack |
| 2984 | CVE-2026-20191 (Path Traversal - CWE-22) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 2985 | weaknesses in backend systems | critical | 8.5 | 1 | data breach |
| 2986 | CVE-2025-9142 (JWT manipulation and directory traversal in Perimeter81 service component) | critical | 8.5 | 1 | Privilege Escalation |
| 2987 | Trust boundary violation in *externally_connectable* setting, lack of sender verification, DOM manipulation, approval looping | critical | 8.5 | 1 | Vulnerability Exploitation |
| 2988 | Inadequate access controls in AI system for privileged actions | critical | 8.5 | 1 | Account Hijacking |
| 2989 | Unsecured Kafka Broker instance | critical | 8.5 | 1 | Data Exposure |
| 2990 | Malicious postinstall scripts | critical | 8.5 | 1 | Supply Chain Attack |
| 2991 | Multi-Factor Authentication (MFA) bypass, Session token hijacking, Credential theft via phishing kits | critical | 8.5 | 1 | Phishing/Vishing, Credential Theft, Data Breach, Session Hijacking |
| 2992 | Plug-in on e-commerce platform | critical | 8.5 | 1 | Data Breach |
| 2993 | Improper Disposal of Sensitive Data | critical | 8.5 | 1 | Data Breach |
| 2994 | Unrestricted failed authentication attempts, weak encryption for passwords and resident registration numbers | critical | 8.5 | 1 | Data Breach |
| 2995 | CVE-2026-26980 (SQL Injection in Ghost CMS) | critical | 8.5 | 1 | SQL Injection, Malware Campaign |
| 2996 | Unencrypted backup media, unlocked storage cabinet | critical | 8.5 | 1 | Data Breach |
| 2997 | Hardcoded Supabase API key in client-side JavaScript with no Row Level Security (RLS) policies | critical | 8.5 | 1 | Data Breach |
| 2998 | Missile defense system vulnerability | critical | 8.5 | 1 | Data Breach |
| 2999 | internal API vulnerability (details undisclosed) | critical | 8.5 | 1 | data breach |
| 3000 | Authentication failures | critical | 8.5 | 1 | API Security Breach |
| 3001 | Programming Errors | critical | 8.5 | 1 | Data Breach |
| 3002 | Lack of Encryption on Portable Device | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 3003 | GitHub Agentic Workflows (AI-powered automation) | critical | 8.5 | 1 | Data Leak |
| 3004 | Insufficient Identity Management | critical | 8.5 | 1 | Data Breach |
| 3005 | Vulnerability in MOBO subscriber management tool | critical | 8.5 | 1 | Data Breach |
| 3006 | Starlink network access control | critical | 8.5 | 1 | Data Breach |
| 3007 | Automatic Opt-Ins | critical | 8.5 | 1 | Data Privacy Issue |
| 3008 | User Trust in Signature Requests | critical | 8.5 | 1 | DNS Hijacking |
| 3009 | CVE-2026-20131 | critical | 8.5 | 1 | Cyberespionage |
| 3010 | CVE-2021-47960 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3011 | CVE-2026-27913 (Improper Input Validation - CWE-20) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3012 | weak password practices | critical | 8.5 | 1 | data breach |
| 3013 | CVE-2025-41115 (Improper Mapping of SCIM 'externalId' to Internal 'user.uid') | critical | 8.5 | 1 | Vulnerability |
| 3014 | lack of secret scanning | critical | 8.5 | 1 | data exposure |
| 3015 | Postinstall hook abuse, self-dependency trick | critical | 8.5 | 1 | Supply Chain Attack |
| 3016 | Google Analytics and Google Ads misconfiguration | critical | 8.5 | 1 | Data Breach |
| 3017 | Unpatched vulnerability in Apple’s *Hide My Email* feature | critical | 8.5 | 1 | Privacy Vulnerability |
| 3018 | Publicly Accessible Files | critical | 8.5 | 1 | Data Leak |
| 3019 | CVE-2026-26133 | critical | 8.5 | 1 | Cross-Prompt Injection Attack (XPIA) |
| 3020 | Lack of Physical Security for Devices Containing Sensitive Data | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 3021 | GHSA-wpqr-6v78-jr5g (workspace trust bypass, tool allowlisting bypass, improper input validation, OS command injection) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3022 | Social engineering (verification code sharing) | critical | 8.5 | 1 | Phishing, Account Takeover |
| 3023 | CVE-2026-3102 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3024 | Auto-installation of GX Mods without user interaction | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3025 | Limited IT Infrastructure | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 3026 | Auto-execution of URL parameters in Microsoft Copilot Personal sessions | critical | 8.5 | 1 | Prompt Injection Attack |
| 3027 | macOS Script Editor (applescript:// links), Refined ClickFix Technique | critical | 8.5 | 1 | Malware Campaign |
| 3028 | outdated software (13 months without updates) | critical | 8.5 | 1 | data breach |
| 3029 | Personal devices infected with malware | critical | 8.5 | 1 | Credential Leak |
| 3030 | Authentication bypass via insecure API | critical | 8.5 | 1 | Data Breach |
| 3031 | Outdated Security Protocols (vendor) | critical | 8.5 | 1 | Data Breach |
| 3032 | CVE-2026-26144 | critical | 8.5 | 1 | Vulnerability |
| 3033 | Spree IDOR Flaws (CVE-2026-22588/22589) | critical | 8.5 | 1 | Supply Chain Attack |
| 3034 | Misconfigured Ollama endpoints (port 11434) | critical | 8.5 | 1 | LLMjacking |
| 3035 | CVE-2025-30247 (OS Command Injection in My Cloud UI) | critical | 8.5 | 1 | Vulnerability |
| 3036 | lack of multi-factor authentication (MFA) enforcement on phishing sites | critical | 8.5 | 1 | phishing |
| 3037 | UAC bypass via COM auto-elevation (ICMLuaUtil through cmlua.dll) | critical | 8.5 | 1 | Trojan |
| 3038 | Token Sprawl | critical | 8.5 | 1 | Data Breach |
| 3039 | CVE-2026-3336 | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 3040 | lack of sandboxing for physical GPU-equipped machines | critical | 8.5 | 1 | malware |
| 3041 | CVE-2026-7195 (CVSS 8.8) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3042 | Insufficient Authentication/Authorization Controls for Reimbursement Account Access | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 3043 | Unknown vulnerability in warehouse management system | critical | 8.5 | 1 | Data Breach |
| 3044 | Compromised contributor credentials, orphan commit in GitHub repository, Sigstore OIDC token abuse | critical | 8.5 | 1 | Supply Chain Attack |
| 3045 | Weak multi-factor authentication (MFA) enforcement, password reuse, exposed network edge devices (e.g., Fortinet FortiGate-60E with open ports) | critical | 8.5 | 1 | Credential Stuffing |
| 3046 | URL fetcher failing to block internal domains | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 3047 | Incorrect data validation protocols | critical | 8.5 | 1 | Data Exposure |
| 3048 | Gemini Search Personalization Model (Prompt Injection via Browsing History) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3049 | Delayed Incident Reporting | critical | 8.5 | 1 | Data Breach |
| 3050 | Outdated SCADA systems, integrated IT/OT environment | critical | 8.5 | 1 | Ransomware |
| 3051 | Insufficient Monitoring | critical | 8.5 | 1 | Data Breach |
| 3052 | Security vulnerability in a third-party service provider | critical | 8.5 | 1 | Cyberattack |
| 3053 | Fragmented Token Extraction via Optical/Transcription Methods | critical | 8.5 | 1 | Prompt Extraction |
| 3054 | Sophisticated hacking attempts | critical | 8.5 | 1 | Data Breach |
| 3055 | CVE-2026-20896 | critical | 8.5 | 1 | Authentication Bypass |
| 3056 | Private Code Repositories (GitLab, Visual Studio Code) | critical | 8.5 | 1 | Malware Deployment |
| 3057 | Human error (deception of individuals into disclosing confidential information) | critical | 8.5 | 1 | Data Breach |
| 3058 | Remote Dynamic Dependencies (RDD) | critical | 8.5 | 1 | Supply Chain Attack |
| 3059 | MOVEit secure file transfer solution vulnerability | critical | 8.5 | 1 | Data Breach |
| 3060 | Operational security lapse (SSH authentication key reuse across servers) | critical | 8.5 | 1 | phishing |
| 3061 | CVE-2026-26111 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3062 | User trust in AI-themed extensions, lack of stringent Chrome Web Store security checks | critical | 8.5 | 1 | Malicious Browser Extensions |
| 3063 | CVE-2026-4782 (CVSS 6.5) | critical | 8.5 | 1 | SQL Injection |
| 3064 | improper data retention | critical | 8.5 | 1 | data breach |
| 3065 | Context Poisoning in AI Conversation History | critical | 8.5 | 1 | Data Breach |
| 3066 | Unknown (zero-day) vulnerability in Oracle E-Business Suite (EBS) | critical | 8.5 | 1 | Data Breach |
| 3067 | CVE-2026-3061 (Out-of-bounds read in Media component) | critical | 8.5 | 1 | Vulnerability Patch |
| 3068 | Long-Term Data Retention | critical | 8.5 | 1 | Data Breach |
| 3069 | Fractured auditability across communication channels | critical | 8.5 | 1 | Data Governance Blind Spot |
| 3070 | CWE-200: Exposure of Sensitive Information | critical | 8.5 | 1 | Data Exposure |
| 3071 | NPM Dependencies | critical | 8.5 | 1 | Malware Deployment |
| 3072 | Unsecured Public LLM Interactions | critical | 8.5 | 1 | Data Leakage |
| 3073 | CVE-2025-54136 (MCPoison - MCP Trust Bypass) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3074 | CVE-2025-43520 | critical | 8.5 | 1 | Exploit Kit |
| 3075 | Lack of DNS query monitoring in ChatGPT's execution environment | critical | 8.5 | 1 | Data Exfiltration |
| 3076 | Trusted developer workflows, npm package installation (no user interaction required) | critical | 8.5 | 1 | Supply-Chain Attack, Malware Campaign |
| 3077 | Compromised employees | critical | 8.5 | 1 | Extortion |
| 3078 | Lack of software updates for gear shifters | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3079 | Listable Algolia Search Indexes (PII Exposure) | critical | 8.5 | 1 | Data Exposure |
| 3080 | CVE-2015-2051 (D-Link Dir-645) | critical | 8.5 | 1 | Exploit Trends |
| 3081 | lack of encryption for stored data | critical | 8.5 | 1 | data breach |
| 3082 | NULL Pointer Dereference | critical | 8.5 | 1 | Privilege Escalation |
| 3083 | Trust in enterprise software (Microsoft Teams), SaaS vulnerabilities | critical | 8.5 | 1 | Phishing/Social Engineering, Malware Deployment |
| 3084 | CVE-2023-28771 | critical | 8.5 | 1 | Remote Code Execution |
| 3085 | Inadequate cybersecurity measures (alleged) | critical | 8.5 | 1 | Data Breach |
| 3086 | Hardcoded Google API keys with expanded authentication capabilities | critical | 8.5 | 1 | Data Exposure |
| 3087 | Lack of Monitoring for Existing Threats | critical | 8.5 | 1 | Data Breach |
| 3088 | CVE-2026-22153 (FG-IR-25-1052), CWE-305 (Authentication Bypass by Primary Weakness) | critical | 8.5 | 1 | Authentication Bypass |
| 3089 | Vulnerability identified and patched | critical | 8.5 | 1 | Data Breach |
| 3090 | Improper handling and sharing of restricted voter data | critical | 8.5 | 1 | Data Breach |
| 3091 | Critical vulnerabilities from CISA’s Known Exploited Vulnerabilities (KEV) catalog | critical | 8.5 | 1 | Insider Threat |
| 3092 | Cloud Vendor Compromise | critical | 8.5 | 1 | Data Breach |
| 3093 | Oracle’s eBusiness Suite software vulnerability | critical | 8.5 | 1 | Data Breach |
| 3094 | Misuse of partner-managed repository credentials | critical | 8.5 | 1 | Data Breach |
| 3095 | CVE-2025-48927 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3096 | human trust in legacy inheritance process | critical | 8.5 | 1 | phishing |
| 3097 | CVE-2025-8424 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3098 | Unauthorized Access to API Key | critical | 8.5 | 1 | Data Breach |
| 3099 | CVE-2026-20435 (MediaTek chipset boot chain weakness) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3100 | Architectural flaw in GitHub MCP server allowing AI agents to access and exfiltrate data from private repositories | critical | 8.5 | 1 | Prompt Injection |
| 3101 | Stolen credentials from 2025 Salesloft breach | critical | 8.5 | 1 | Data Breach |
| 3102 | Endpoint-level credential theft | critical | 8.5 | 1 | Data Breach |
| 3103 | Debug flag (`setIsDebugMode(true)`) left active in production code | critical | 8.5 | 1 | Account Takeover |
| 3104 | trust in open-source dependencies | critical | 8.5 | 1 | supply-chain attack |
| 3105 | Unrestricted access to AWS buckets | critical | 8.5 | 1 | Data Exposure |
| 3106 | Weakness in OAuth token security for Salesloft Drift integrations | critical | 8.5 | 1 | Data Breach |
| 3107 | Internal Glitch | critical | 8.5 | 1 | Data Exposure |
| 3108 | Unsecured personal information handling | critical | 8.5 | 1 | Data Breach |
| 3109 | Gemini Browsing Tool (Web Page Summarization Data Exfiltration) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3110 | CVE-2025-10184 (Improper Permission Handling in OxygenOS Telephony Package) | critical | 8.5 | 1 | Vulnerability |
| 3111 | Shopping cart portions of the company's websites | critical | 8.5 | 1 | Data Breach |
| 3112 | Lack of Data Minimization | critical | 8.5 | 1 | Data Breach |
| 3113 | Legal loophole exempting political parties from provincial privacy regulations | critical | 8.5 | 1 | Data Breach |
| 3114 | Data Exposure | critical | 8.5 | 1 | Data Leak |
| 3115 | CVE-2026-22218 (Arbitrary File Read) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3116 | Inadequate cybersecurity protocols, weak security controls | critical | 8.5 | 1 | Data Breach |
| 3117 | Debug flag (`setIsDebugMode(true)`) left in production builds | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3118 | lack of enterprise-grade security for AI tools | critical | 8.5 | 1 | ransomware |
| 3119 | SOHO devices | critical | 8.5 | 1 | Credential Theft |
| 3120 | Hard-coded encryption keys | critical | 8.5 | 1 | Data Breach |
| 3121 | CVE-2026-42055 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3122 | GoAnywhere MFT SaaS | critical | 8.5 | 1 | Data Breach |
| 3123 | CVE-2025-XXXX (WebKit Zero-Day 1) | critical | 8.5 | 1 | Zero-Day Exploit |
| 3124 | CVE-2025-59449 (Incorrect Authorization) | critical | 8.5 | 1 | Denial-of-Service |
| 3125 | Compromised Administrator Account | critical | 8.5 | 1 | Ransomware |
| 3126 | Improper deployment of third-party tracking technologies on public website leading to unauthorized data transfer | critical | 8.5 | 1 | Data Privacy Violation |
| 3127 | Incomplete cross-origin controls (Ollama Desktop) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 3128 | CVE-2026-20251 (Unsafe deserialization via jsonpickle library) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3129 | misconfiguration in HR/finance team servers | critical | 8.5 | 1 | ransomware |
| 3130 | Unauthorized access by authorized user | critical | 8.5 | 1 | Data Breach |
| 3131 | Docker MCP Gateway RCE | critical | 8.5 | 1 | Supply Chain Attack |
| 3132 | CVE-2025-27889 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3133 | CVE-2026-23111 (Use-after-free in nftables subsystem) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3134 | Google Tag Manager | critical | 8.5 | 1 | Data Breach |
| 3135 | Bypassed multi-factor authentication (MFA) | critical | 8.5 | 1 | Data Breach |
| 3136 | third-party integrations (speculated) | critical | 8.5 | 1 | data breach |
| 3137 | Lack of Physical Security for Development Device | critical | 8.5 | 1 | Trade Secret Theft |
| 3138 | Lack of authentication, unsecured admin portals, weak club passwords, hardcoded Stripe API keys | critical | 8.5 | 1 | Data Exposure |
| 3139 | CVE-2025-23121 | critical | 8.5 | 1 | Vulnerability |
| 3140 | Poor Internal Access Controls | critical | 8.5 | 1 | Data Breach |
| 3141 | Misconfigured Docker Setups | critical | 8.5 | 1 | Misconfiguration |
| 3142 | RxGK subsystem flaw in `rxgk_decrypt_skb()` function (Linux kernel) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3143 | shadow_AI | critical | 8.5 | 1 | data_breach |
| 3144 | Publicly accessible sensitive data | critical | 8.5 | 1 | Data Exposure |
| 3145 | App cloning, Reverse engineering, Bypassing App Store security (iOS), JavaScript bundle interception, RSA-encrypted payload exfiltration | critical | 8.5 | 1 | Backdoor Attack, Cryptocurrency Wallet Hack |
| 3146 | CVE-2026-1235 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3147 | Mobile Application Vulnerability | critical | 8.5 | 1 | Data Breach |
| 3148 | Signal’s 'linked devices' feature | critical | 8.5 | 1 | Cyber Espionage |
| 3149 | Vulnerabilities in Salesforce-hosted databases | critical | 8.5 | 1 | Data Breach |
| 3150 | Recently patched vulnerability in Oracle E-Business Suite (for Cl0p ransomware incident) | critical | 8.5 | 1 | Data Breach |
| 3151 | CVE-2025-53652 | critical | 8.5 | 1 | Command Injection |
| 3152 | Insecure 'super admin' APIs allowing unauthenticated high-privilege account creation | critical | 8.5 | 1 | Data Exposure |
| 3153 | Inadequate security protections | critical | 8.5 | 1 | Data Breach / Cybersecurity Failure |
| 3154 | VMware Aria Operations | critical | 8.5 | 1 | APT Activity |
| 3155 | Policy/Procedural Failure | critical | 8.5 | 1 | Data Breach |
| 3156 | CVE-2026-21509 (Microsoft Office Security Feature Bypass) | critical | 8.5 | 1 | Cyber-Espionage |
| 3157 | Human Error (Misaddressed Email) | critical | 8.5 | 1 | Data Breach (Phishing / Unauthorized Disclosure) |
| 3158 | CVE-2024-23222 (WebKit RCE - cassowary) | critical | 8.5 | 1 | Exploit Kit / Malware Campaign |
| 3159 | Apple Notarization Bypass (ChillyHell) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3160 | Improper Access Control in SharePoint | critical | 8.5 | 1 | Data Exposure |
| 3161 | Server-Side Request Forgery (SSRF) via Bing’s image search endpoint | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3162 | Lack of account management (inactive accounts not decommissioned) | critical | 8.5 | 1 | Data Breach |
| 3163 | Human Vulnerability (Insider Recruitment) | critical | 8.5 | 1 | Insider Threat, Extortion |
| 3164 | DirtyClone (CVE-2026-43503) | critical | 8.5 | 1 | Local Privilege Escalation |
| 3165 | Clickjacking (CWE-1021) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3166 | CVE-2025-43300 (Apple Zero-Day) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3167 | Unauthenticated Admin Functions (GRS Panel, HTML Injection) | critical | 8.5 | 1 | Data Exposure |
| 3168 | Lack of Multi-Factor Authentication (MFA) (inferred) | critical | 8.5 | 1 | Data Breach |
| 3169 | Account recovery workflows (password resets, MFA re-enrollment, help-desk recovery requests) | critical | 8.5 | 1 | Identity Breach |
| 3170 | SureTriggers Vulnerability | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3171 | CVE-2026-25173 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3172 | Frontend Access Control | critical | 8.5 | 1 | DNS Hijacking |
| 3173 | Lack of multi-factor authentication (MFA) on file-transfer services (ShareFile, OwnCloud, Nextcloud) | critical | 8.5 | 1 | Data Breach |
| 3174 | MFA bypass via Evilginx-style reverse proxies, Device Code Flow abuse, session token interception | critical | 8.5 | 1 | Phishing |
| 3175 | CVE-2026-49157 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3176 | Unauthenticated AI services | critical | 8.5 | 1 | LLMjacking |
| 3177 | Vulnerability in Gladinet CentreStack | critical | 8.5 | 1 | Data Breach |
| 3178 | Unprotected personal data in financial/healthcare systems | critical | 8.5 | 1 | Identity Theft |
| 3179 | Human Error (Social Engineering via Phone Calls) | critical | 8.5 | 1 | Data Breach |
| 3180 | Lack of clear user consent | critical | 8.5 | 1 | Privacy Violation |
| 3181 | Unauthenticated Access | critical | 8.5 | 1 | Data Breach |
| 3182 | Inadequate security measures (unspecified) | critical | 8.5 | 1 | Data Breach |
| 3183 | Unprotected 'unlink()' call enabling unauthenticated file deletion | critical | 8.5 | 1 | SQL Injection |
| 3184 | Lack of organization-wide two-factor authentication | critical | 8.5 | 1 | Data Breach |
| 3185 | CVE-2026-40050 (Path-Traversal) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3186 | Unencrypted data storage on DJI servers | critical | 8.5 | 1 | Data Exposure |
| 3187 | Supply chain compromise in CI/CD dependencies | critical | 8.5 | 1 | Supply Chain Attack |
| 3188 | CVE-2025-54254 (Improper Restriction of XML External Entity Reference) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3189 | Supply chain weakness in analytics data handling | critical | 8.5 | 1 | Data Breach |
| 3190 | Stack-based buffer overflow (JVN#35567473) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3191 | Inadequate safeguards for 'Image ID' verification systems | critical | 8.5 | 1 | Data Breach |
| 3192 | limited_cybersecurity_resources | critical | 8.5 | 1 | data_breach |
| 3193 | Trust in the platform's review system and verification processes | critical | 8.5 | 1 | Disinformation and Scams |
| 3194 | Unauthorized data transmission via third-party integrations | critical | 8.5 | 1 | Data Breach |
| 3195 | Misconfiguration in Salesforce environment, lack of least privilege principle, absence of Zero Trust architecture, inadequate behavioral monitoring | critical | 8.5 | 1 | Data Breach |
| 3196 | Single Sign-On (SSO) accounts (Okta and other identity platforms), MFA manipulation | critical | 8.5 | 1 | Phishing (Vishing), Data Breach, Credential Theft |
| 3197 | CVE-2026-2285 | critical | 8.5 | 1 | Remote Code Execution |
| 3198 | CVE-2025-59452 (Cleartext Transmission) | critical | 8.5 | 1 | Denial-of-Service |
| 3199 | inadequate data retention policies | critical | 8.5 | 1 | data breach |
| 3200 | CVE-2026-0709 | critical | 8.5 | 1 | Supply Chain Attack |
| 3201 | Intermediate Data Leakage (Predictions, Losses) | critical | 8.5 | 1 | Privacy Breach |
| 3202 | Compromised OAuth app linked to Google Workspace | critical | 8.5 | 1 | Data Breach |
| 3203 | CVE-2026-3517 | critical | 8.5 | 1 | vulnerability |
| 3204 | Inadequate cybersecurity protections | critical | 8.5 | 1 | Data Breach |
| 3205 | Compromised GitHub Tokens | critical | 8.5 | 1 | Identity Compromise |
| 3206 | CVE-2026-28277 (Unsafe msgpack deserialization) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3207 | CVE-2026-20700 | critical | 8.5 | 1 | Exploit Kit |
| 3208 | Weak incident response policies and procedures | critical | 8.5 | 1 | Data Breach |
| 3209 | Misconfiguration in Electron framework | critical | 8.5 | 1 | Security Vulnerability |
| 3210 | Progress MOVEit platform | critical | 8.5 | 1 | Data Breach |
| 3211 | Unauthorized access to Microsoft Office 365 email account | critical | 8.5 | 1 | Data Breach |
| 3212 | CVE-2026-2287 | critical | 8.5 | 1 | Remote Code Execution |
| 3213 | Fail-open design in security scanning system (CWE-636: Not Failing Securely) | critical | 8.5 | 1 | Supply Chain Attack |
| 3214 | Gatekeeper bypass via notarized malware | critical | 8.5 | 1 | Infostealer |
| 3215 | Weak hiring verification, lack of device authenticity checks | critical | 8.5 | 1 | Insider Threat |
| 3216 | Unauthenticated DNS modification | critical | 8.5 | 1 | DNS Hijacking |
| 3217 | Bypassing Google’s *App-Bound Encryption* and endpoint security tools via remote decryption | critical | 8.5 | 1 | Infostealer Malware |
| 3218 | Lack of encryption for sensitive data | critical | 8.5 | 1 | Data Breach |
| 3219 | Absence of vendor security assessments for AI tools | critical | 8.5 | 1 | Data Leakage |
| 3220 | user susceptibility to phishing | critical | 8.5 | 1 | phishing |
| 3221 | Human vulnerability (bribery of customer support agents) | critical | 8.5 | 1 | Data Breach |
| 3222 | Vendor's security shortcomings (unspecified) | critical | 8.5 | 1 | Data Breach (Third-Party Vendor) |
| 3223 | Server-side request forgery (SSRF) (14.5%) | critical | 8.5 | 1 | API Security Breach |
| 3224 | inadequate segmentation between Discord and vendor systems | critical | 8.5 | 1 | data breach |
| 3225 | WhatsApp Desktop Client | critical | 8.5 | 1 | Malware Campaign |
| 3226 | CVE-2026-1603 | critical | 8.5 | 1 | Authentication Bypass |
| 3227 | Flaw in 'Image ID' parameter allowing URL manipulation | critical | 8.5 | 1 | Data Breach |
| 3228 | Vendor Software | critical | 8.5 | 1 | Data Breach |
| 3229 | inadequate staff training | critical | 8.5 | 1 | data breach |
| 3230 | Public URLs for client-worker communications instead of secured, expiring links | critical | 8.5 | 1 | Data Exposure |
| 3231 | Citrix Software Vulnerability (specific CVE unidentified) | critical | 8.5 | 1 | Data Breach |
| 3232 | Inadequate monitoring of low-volume, time-distributed unauthorized access | critical | 8.5 | 1 | Data Breach |
| 3233 | E-commerce System | critical | 8.5 | 1 | Data Breach |
| 3234 | Open Registration Endpoint (Design Hub) | critical | 8.5 | 1 | Data Exposure |
| 3235 | Website Migration | critical | 8.5 | 1 | Data Breach |
| 3236 | Inadequate safeguards in government online portals | critical | 8.5 | 1 | Credential Stuffing |
| 3237 | Lack of Policy Enforcement for AI Tool Usage | critical | 8.5 | 1 | Data Breach |
| 3238 | Improper disposal of hardware containing sensitive data | critical | 8.5 | 1 | Data Breach (Physical/Improper Disposal) |
| 3239 | Publicly Exposed API Token | critical | 8.5 | 1 | Data Breach (OAuth Token Compromise) |
| 3240 | Stolen credentials (password reuse, leaked credentials) | critical | 8.5 | 1 | Credential Theft |
| 3241 | Cloud Infrastructure Security | critical | 8.5 | 1 | Cyberattack |
| 3242 | CWE-798: Use of Hard-coded Credentials | critical | 8.5 | 1 | Data Breach |
| 3243 | Data Corruption | critical | 8.5 | 1 | Data Leak |
| 3244 | Weakly validated XPC connections, Interface Builder (NIB) file injection, kernel code-signing trust cache persistence | critical | 8.5 | 1 | Privilege Escalation / EDR Bypass |
| 3245 | Lack of least-privilege access controls | critical | 8.5 | 1 | Data Breach |
| 3246 | shared CDN resources | critical | 8.5 | 1 | ransomware |
| 3247 | Unsecured email API endpoints with improper input validation | critical | 8.5 | 1 | Phishing, Data Theft, Persistent Access |
| 3248 | resource constraints | critical | 8.5 | 1 | data breach |
| 3249 | Incorrect access settings | critical | 8.5 | 1 | Data Breach |
| 3250 | Inadequate security measures, potential internal mismanagement | critical | 8.5 | 1 | Data Breach |
| 3251 | Unsafe workspace trust handling | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3252 | Unpatched vulnerabilities in third-party applications | critical | 8.5 | 1 | Third-party data exploitation |
| 3253 | Unauthenticated vulnerabilities (56% of tracked vulnerabilities in 2025) | critical | 8.5 | 1 | Supply Chain Attack |
| 3254 | Unauthorized Access to Personal Information | critical | 8.5 | 1 | Data Theft |
| 3255 | Sending sensitive data in unencrypted emails | critical | 8.5 | 1 | Data Breach |
| 3256 | Authentication Bypass | critical | 8.5 | 1 | Authentication Bypass |
| 3257 | Weak cybersecurity defenses, lack of dedicated cybersecurity staff, reliance on ed-tech tools | critical | 8.5 | 1 | Ransomware |
| 3258 | CVE-2025-61884 (CVSS 7.5 - Information Disclosure in Runtime UI) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3259 | Mirasvit flaw in Magento servers | critical | 8.5 | 1 | Third-Party Risk Management Failure |
| 3260 | Sequentially numbered and guessable URLs | critical | 8.5 | 1 | Data Exposure |
| 3261 | Unrotated Service Account Token | critical | 8.5 | 1 | Data Breach (OAuth Token Compromise) |
| 3262 | CVE-2026-25592 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3263 | Default transmission of full Git repositories without explicit user consent | critical | 8.5 | 1 | Data Exposure |
| 3264 | Lack of multi-factor authentication (MFA), Third-party vendor compromise | critical | 8.5 | 1 | Data Breach |
| 3265 | Fragmented Data Access Controls | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 3266 | Contact-importing features | critical | 8.5 | 1 | Data Leak |
| 3267 | Exposed Elasticsearch Database | critical | 8.5 | 1 | Data Leak |
| 3268 | CVE-2025-43510 | critical | 8.5 | 1 | Exploit Kit |
| 3269 | Inadequate internal controls and monitoring mechanisms | critical | 8.5 | 1 | Unauthorized Data Access |
| 3270 | Legacy file-transfer software vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3271 | user trust in legitimate-looking emails/websites | critical | 8.5 | 1 | spear-phishing |
| 3272 | Failure to mask sensitive contact details during password reset requests | critical | 8.5 | 1 | Data Exposure |
| 3273 | Third-Party Platform Security (Salesforce) | critical | 8.5 | 1 | Data Breach |
| 3274 | Leak of User Emails | critical | 8.5 | 1 | Data Breach |
| 3275 | CVE-2026-21533 | critical | 8.5 | 1 | Elevation of Privilege |
| 3276 | weak phishing detection | critical | 8.5 | 1 | phishing |
| 3277 | MOVEit secure file transfer tool vulnerability | critical | 8.5 | 1 | Data Breach |
| 3278 | Absence of Visibility/Monitoring Tools | critical | 8.5 | 1 | Data Leakage |
| 3279 | lack of code signing verification for replaced applications | critical | 8.5 | 1 | malware |
| 3280 | Lack of Command-Line Execution Awareness | critical | 8.5 | 1 | APT (Advanced Persistent Threat) |
| 3281 | Weak DMARC/SPF policies, Missing MTA-STS, Unvalidated/Expired Server Certificates, Misconfigured Microsoft 365 Security Tools | critical | 8.5 | 1 | Data Breach |
| 3282 | Unverified third-party package installation | critical | 8.5 | 1 | Supply Chain Attack |
| 3283 | Inability to Distinguish Content from Directives in Prompts | critical | 8.5 | 1 | Data Exfiltration |
| 3284 | Lack of multi-factor authentication, Human error (victims sharing access codes) | critical | 8.5 | 1 | Phishing, Social Engineering, Identity Theft, Data Theft |
| 3285 | SMS phishing (smishing) attack | critical | 8.5 | 1 | Data Breach |
| 3286 | CVE-2026-14898 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) | critical | 8.5 | 1 | Data Exfiltration |
| 3287 | WebKit memory-related errors | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3288 | Unauthorized data sharing via embedded trackers | critical | 8.5 | 1 | Data Privacy Violation |
| 3289 | CVE-2018-25270 (ThinkPHP) | critical | 8.5 | 1 | Exploit Trends |
| 3290 | Human Error (Misconfigured Email Distribution List) | critical | 8.5 | 1 | Data Breach (Unintentional Disclosure) |
| 3291 | Social Engineering (Fake App Update) | critical | 8.5 | 1 | Cyberespionage |
| 3292 | Human Error (Employee Compromise) | critical | 8.5 | 1 | Data Breach |
| 3293 | High-severity CVEs (FortiWeb, React2Shell, Ivanti Sentry, PAN-OS, CheckPoint VPN) | critical | 8.5 | 1 | Supply-Chain Attack |
| 3294 | Failure to Follow Standard Operating Procedures | critical | 8.5 | 1 | Data Breach |
| 3295 | Lack of Email Spoofing Protections | critical | 8.5 | 1 | Data Breach |
| 3296 | CVE-2026-32635 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3297 | Blockchain immutability (append-only ledger), Lack of takedown mechanisms for decentralized infrastructure | critical | 8.5 | 1 | Info-Stealer / Malware |
| 3298 | CVE-2026-8932 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3299 | CVE-2025-59448 (Session Token Lifetimes) | critical | 8.5 | 1 | Denial-of-Service |
| 3300 | Cloaking | critical | 8.5 | 1 | Phishing |
| 3301 | Lack of user vigilance, Newly registered malicious domains | critical | 8.5 | 1 | Spoofing, Phishing, Brand Impersonation |
| 3302 | DNS Infrastructure Weakness (Box Domains) | critical | 8.5 | 1 | DNS Hijacking |
| 3303 | Insecure Direct Object Reference (Sapphos API) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3304 | Outdated cryptographic practices | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 3305 | CWE-506: Embedded Malicious Code | critical | 8.5 | 1 | Dependency Confusion |
| 3306 | CVE-2026-12473 | critical | 8.5 | 1 | Server-Side Request Forgery (SSRF) |
| 3307 | Autofill Functionality Abuse | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3308 | MFA bypass via session replay, exploitation of legitimate JavaScript library (rrweb) | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 3309 | CVE-2025-0994 | critical | 8.5 | 1 | Cyber Attack |
| 3310 | Improper handling of technical identifiers | critical | 8.5 | 1 | Data Exposure |
| 3311 | EngageLab SDK Vulnerability (Android) | critical | 8.5 | 1 | Data Breach |
| 3312 | Third-party vendor breach | critical | 8.5 | 1 | Data Breach |
| 3313 | CVE-2026-33826 (Improper Input Validation - CWE-20) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3314 | Publicly exposed Sentry DSN credentials | critical | 8.5 | 1 | AI Agent Hijacking |
| 3315 | CVE-2025-43300 (Image I/O framework - out-of-bounds write) | critical | 8.5 | 1 | Zero-day vulnerability |
| 3316 | Improper data storage practices | critical | 8.5 | 1 | Data Breach |
| 3317 | Supply-chain risks | critical | 8.5 | 1 | Third-party data exploitation |
| 3318 | Inadequate data handling and publication controls | critical | 8.5 | 1 | Data Exposure |
| 3319 | CVE-2025-61882 (Zero-day in Oracle E-Business Suite) | critical | 8.5 | 1 | Data Breach |
| 3320 | Abuse of Microsoft’s Artifact Signing system | critical | 8.5 | 1 | Malware-Signing-as-a-Service (MSaaS) Disruption |
| 3321 | CVE-2025-48561 | critical | 8.5 | 1 | Data Theft |
| 3322 | Weak authentication (Dior Instagram) | critical | 8.5 | 1 | Data Breach |
| 3323 | active former employee credentials | critical | 8.5 | 1 | data breach |
| 3324 | Incorrectly configured database | critical | 8.5 | 1 | Data Leak |
| 3325 | improper data retention practices (government IDs) | critical | 8.5 | 1 | data breach |
| 3326 | Citrix software vulnerability | critical | 8.5 | 1 | Data Breach |
| 3327 | Lack of End-to-End Encryption | critical | 8.5 | 1 | Data Collection |
| 3328 | Lack of access controls, default admin permissions, unmanaged AI-driven applications | critical | 8.5 | 1 | Data Exposure |
| 3329 | Cloud Database Platform | critical | 8.5 | 1 | Data Breach |
| 3330 | Silverlight | critical | 8.5 | 1 | Cyber Attack |
| 3331 | Zero-click indirect prompt injection (*PleaseFix*) | critical | 8.5 | 1 | AI Prompt Injection |
| 3332 | Mirasvit Full Page Cache Warmer flaw | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3333 | Free for Teacher environment vulnerability in Canvas LMS | critical | 8.5 | 1 | Data Breach |
| 3334 | CVE-2026-23594 | critical | 8.5 | 1 | Privilege Escalation |
| 3335 | CVE-2026-34486 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3336 | automated CI/CD pipeline execution | critical | 8.5 | 1 | supply-chain attack |
| 3337 | CVE-2025-5806 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3338 | Web application vulnerability (Click2Gov online payment system) | critical | 8.5 | 1 | Data Breach |
| 3339 | Improper validation of key descriptions in the CIFs.Spnego key type (logic flaw between Linux kernel’s CIFS client and cifs-utils package) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3340 | Unsecured AWS bucket with direct file access via backend bug | critical | 8.5 | 1 | Data Exposure |
| 3341 | CVE-2026-42167 | critical | 8.5 | 1 | SQL Injection |
| 3342 | MOVEit file transfer service vulnerability | critical | 8.5 | 1 | Data Breach |
| 3343 | Abuse of Wallpaper Engine’s 'application' wallpaper type to execute arbitrary code | critical | 8.5 | 1 | Malware Campaign |
| 3344 | Inherited permissions from privileged users | critical | 8.5 | 1 | Data Breach |
| 3345 | Flash Player | critical | 8.5 | 1 | Cyber Attack |
| 3346 | Human Trust and Error (Bypassed Security Awareness Training) | critical | 8.5 | 1 | Data Breach |
| 3347 | AI-generated_deepfakes | critical | 8.5 | 1 | data_breach |
| 3348 | Legacy system vulnerability | critical | 8.5 | 1 | Data Breach |
| 3349 | Lack of proper access controls or oversight during training | critical | 8.5 | 1 | Data Breach / Espionage |
| 3350 | CVE-2026-1591 | critical | 8.5 | 1 | Supply Chain Attack |
| 3351 | Insufficient Conditional Access Controls | critical | 8.5 | 1 | Cloud Security Breach |
| 3352 | CVE-2026-0709 (Insufficient Input Validation) | critical | 8.5 | 1 | Command Execution Vulnerability |
| 3353 | Composer’s regex validation failure due to GitHub’s new token format | critical | 8.5 | 1 | Data Exposure |
| 3354 | Employee Access | critical | 8.5 | 1 | Data Breach |
| 3355 | Unencrypted Computers | critical | 8.5 | 1 | Data Breach |
| 3356 | Account Credentials | critical | 8.5 | 1 | Data Breach |
| 3357 | Quantum Model Memorization of Training Data | critical | 8.5 | 1 | Privacy Breach |
| 3358 | SolarWinds Serv-U flaw | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3359 | Arbitrary Order Data Injection (CosMc’s App) | critical | 8.5 | 1 | Data Exposure |
| 3360 | Vulnerability in third-party contractor’s software | critical | 8.5 | 1 | Data Breach |
| 3361 | Malware on User Devices | critical | 8.5 | 1 | Credential Exposure |
| 3362 | Adobe Reader | critical | 8.5 | 1 | Cyber Attack |
| 3363 | CVE-2025-31334 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3364 | Exposed API Keys | critical | 8.5 | 1 | Cloud Security Breach |
| 3365 | Automated link preview generation in AI agents | critical | 8.5 | 1 | Data Exfiltration |
| 3366 | CVE-2025-9368 (Resource Allocation Without Limits) | critical | 8.5 | 1 | Denial-of-Service |
| 3367 | Inadequate safeguards for personal information | critical | 8.5 | 1 | Data Breach |
| 3368 | Human Error (Improper Document Upload) | critical | 8.5 | 1 | Data Breach (Inadvertent Disclosure) |
| 3369 | CVE-2025-59451 (Predictable Identifiers) | critical | 8.5 | 1 | Denial-of-Service |
| 3370 | Social Engineering (Fake Windows Update) | critical | 8.5 | 1 | Session Hijacking |
| 3371 | Lack of prompt injection detection | critical | 8.5 | 1 | Data Breach |
| 3372 | compromised personal data | critical | 8.5 | 1 | fraud |
| 3373 | Prompt Injection (AI agent misinterprets embedded commands in untrusted data as legitimate instructions) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3374 | CVE-2026-31790 | critical | 8.5 | 1 | Data Leak |
| 3375 | Citrix Software Vulnerability (unspecified) | critical | 8.5 | 1 | Data Breach |
| 3376 | Credential-based attack | critical | 8.5 | 1 | Data Breach |
| 3377 | System Setup Error | critical | 8.5 | 1 | Data Exposure |
| 3378 | CVE-2026-3844 (Breeze caching plugin) | critical | 8.5 | 1 | Webshell Attack |
| 3379 | Inadequate physical access controls | critical | 8.5 | 1 | Data Breach |
| 3380 | Progress Software's MOVEit Transfer application | critical | 8.5 | 1 | Data Breach |
| 3381 | Human error (phishing attack on staff) | critical | 8.5 | 1 | Data Breach |
| 3382 | Unspecified zero-day in FreePBX (versions 16 and 17 with endpoint module installed) | critical | 8.5 | 1 | Zero-day exploitation |
| 3383 | Agentic Supply Chain Vulnerability (OWASP AI Top 10 - December 2025) | critical | 8.5 | 1 | AI Agent Hijacking |
| 3384 | Model Context Protocol (MCP) flaws | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3385 | UAC bypass | critical | 8.5 | 1 | Malware (RAT) |
| 3386 | CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-41099 (CWE-284: Improper Access Control) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3387 | WooCommerce website vulnerabilities, third-party script injection | critical | 8.5 | 1 | Magecart (Digital Skimming) |
| 3388 | Inadequate Audit Logs | critical | 8.5 | 1 | Data Breach |
| 3389 | CVE-2026-23595 | critical | 8.5 | 1 | Privilege Escalation |
| 3390 | Excessive account permissions | critical | 8.5 | 1 | Data Breach |
| 3391 | CWE-269: Improper Privilege Management | critical | 8.5 | 1 | Data Exposure |
| 3392 | CVE-2026-0740 (Ninja Forms) | critical | 8.5 | 1 | Exploitation Campaign |
| 3393 | Inadequate data retention/deletion policies | critical | 8.5 | 1 | Data Breach Risk |
| 3394 | WebOTP API, Clipboard Access, Notification Control, PWA Installation Permissions, Android Permissions Abuse | critical | 8.5 | 1 | Phishing |
| 3395 | Log4Shell | critical | 8.5 | 1 | Ransomware |
| 3396 | Improperly configured AWS S3 storage | critical | 8.5 | 1 | Data Breach |
| 3397 | Progress Software’s MOVEit Transfer application | critical | 8.5 | 1 | Data Breach |
| 3398 | Browser extension permissions and network traffic interception | critical | 8.5 | 1 | Data Theft |
| 3399 | CWE-94 (Code Injection), Shared Execution Environment Misconfiguration, VPC Service Controls Bypass, IMDS Credential Leakage | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3400 | unsecured APIs | critical | 8.5 | 1 | ransomware |
| 3401 | CVE-2026-57992 (Use-After-Free in Microsoft Edge’s rendering engine) | critical | 8.5 | 1 | Vulnerability |
| 3402 | CVE-2026-1236 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3403 | Weak Wi-Fi Network Security | critical | 8.5 | 1 | Data Breach |
| 3404 | CW1226324 (Copilot DLP bypass) | critical | 8.5 | 1 | AI Integration Bug |
| 3405 | Unsecured System | critical | 8.5 | 1 | Data Breach |
| 3406 | MOVEit Transfer programme zero-day vulnerability | critical | 8.5 | 1 | Data Breach |
| 3407 | Unverified Assessment Domains | critical | 8.5 | 1 | APT (Advanced Persistent Threat) |
| 3408 | Insufficient VPN authentication, ineffective abnormal behavior detection | critical | 8.5 | 1 | Data Breach |
| 3409 | Hardcoded secrets in AI-generated code, MCP configurations, overprivileged access | critical | 8.5 | 1 | Data Leak |
| 3410 | MOVEit file transfer tool | critical | 8.5 | 1 | Data Breach |
| 3411 | Stolen credentials (PIN and government-issued ID) | critical | 8.5 | 1 | Fraud Scheme |
| 3412 | Unsecured Data Repositories | critical | 8.5 | 1 | Credential Exposure |
| 3413 | Lack of API Key Ownership Validation | critical | 8.5 | 1 | Data Exfiltration |
| 3414 | Claude Code flaws | critical | 8.5 | 1 | APT Activity |
| 3415 | CVE-2026-6688 (Long filename overflow) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3416 | Inadequate logging | critical | 8.5 | 1 | Data Breach |
| 3417 | CVE-2026-0628 (declarativeNetRequest API misconfiguration in Gemini AI panel) | critical | 8.5 | 1 | Privilege Escalation |
| 3418 | Failure to implement and maintain reasonable security measures | critical | 8.5 | 1 | Data Breach |
| 3419 | Auto-install mechanism of GX Mods, universal CSS injection, XS-Leak (cross-site leak) | critical | 8.5 | 1 | Data Theft |
| 3420 | CVE-2026-48019 (CWE-93 - CRLF Injection) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3421 | CVE-2025-8099 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3422 | Improper use of private email account | critical | 8.5 | 1 | Data Breach |
| 3423 | Access Control Mechanisms | critical | 8.5 | 1 | Data Breach |
| 3424 | BlueHammer (Windows zero-day) | critical | 8.5 | 1 | Zero-Day Vulnerability Disclosure |
| 3425 | No Rate Limiting | critical | 8.5 | 1 | Data Breach |
| 3426 | CVE-2026-50656 (RoguePlanet) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3427 | CVE-2024-XXXX (Oracle PeopleSoft Environment Management remote code execution flaw) | critical | 8.5 | 1 | Data Breach |
| 3428 | CVE-2025-54820 (Stack-based buffer overflow in *fgtupdates* service) | critical | 8.5 | 1 | Vulnerability |
| 3429 | Unprotected checkout endpoint in Funnel Builder WordPress plugin (versions prior to 3.15.0.3) | critical | 8.5 | 1 | Payment Card Skimming |
| 3430 | Discord's API | critical | 8.5 | 1 | Phishing |
| 3431 | Unsecured AWS bucket | critical | 8.5 | 1 | Data Breach |
| 3432 | Open-access data sharing model and inadvertent exposure of raw data through published code | critical | 8.5 | 1 | Data Breach |
| 3433 | Unspecified coding error in SchoolMessenger application | critical | 8.5 | 1 | Data Breach |
| 3434 | Lack of Data Loss Prevention (DLP) Controls | critical | 8.5 | 1 | Data Breach |
| 3435 | lack of identity response integration | critical | 8.5 | 1 | phishing |
| 3436 | Vulnerabilities in a property information-sharing system used exclusively by real estate companies | critical | 8.5 | 1 | Data Breach |
| 3437 | Lack of user awareness, 2FA bypass via fake prompts | critical | 8.5 | 1 | Phishing (AiTM - Adversary-in-the-Middle) |
| 3438 | Unencrypted data storage in an internet-accessible environment | critical | 8.5 | 1 | Data Breach |
| 3439 | LLM safety guardrails bypass via iterative dialogue | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3440 | CVE-2025-9242 (Out-of-bounds write in Fireware OS ‘iked’ process) | critical | 8.5 | 1 | Vulnerability Exposure |
| 3441 | CVE-2026-2447 (Heap buffer overflow in libvpx video codec) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3442 | Flaw in online portal allowing unauthorized access to personal annual benefit statements (ABS) | critical | 8.5 | 1 | Data Breach |
| 3443 | CVE-2026-7313 (CVSS 8.7) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3444 | Out-of-bounds read (Grassroot DICOM) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3445 | Insufficient input sanitization in Drupal’s database API | critical | 8.5 | 1 | SQL Injection |
| 3446 | DLL hijacking (USERENV.dll), RPC protocol manipulation, malformed parameters in spawn method | critical | 8.5 | 1 | Privilege Escalation |
| 3447 | CVE-2025-49596 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3448 | Human Weakness in Customer Service | critical | 8.5 | 1 | Data Breach |
| 3449 | Coruna (23 distinct security flaws) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3450 | Android Accessibility Services, lack of user awareness | critical | 8.5 | 1 | Banking Trojan |
| 3451 | Compromised Salesforce integrations, Zendesk customer support system | critical | 8.5 | 1 | Data Breach |
| 3452 | Internal Collaboration Tool | critical | 8.5 | 1 | Data Breach |
| 3453 | third-party_file_transfer_solutions | critical | 8.5 | 1 | data_breach |
| 3454 | legitimate credentials misuse | critical | 8.5 | 1 | phishing |
| 3455 | Lack of Robust Encryption/Monitoring in Data Flows | critical | 8.5 | 1 | Data Breach |
| 3456 | Lack of transparency in AI decision-making | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 3457 | CVE-2020-17103 | critical | 8.5 | 1 | Privilege Escalation |
| 3458 | malicious CI/CD pipeline injection | critical | 8.5 | 1 | supply-chain attack |
| 3459 | Lack of Robust Security Controls on Third-Party Platforms | critical | 8.5 | 1 | Data Breach |
| 3460 | CVE-2025-32896 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3461 | Cardinality-Based Rate Limiting Bypass | critical | 8.5 | 1 | Privacy Violation |
| 3462 | CVE-2026-46333 (Race condition in __ptrace_may_access()) | critical | 8.5 | 1 | Privilege Escalation |
| 3463 | CVE-2025-5777 (CitrixBleed 2) | critical | 8.5 | 1 | Reconnaissance |
| 3464 | CVE-2017-3881 (Cluster Management Protocol RCE in Cisco IOS/IOS XE) | critical | 8.5 | 1 | unauthorized access |
| 3465 | CVE-2026-3337 | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 3466 | Excessive permissions in AI agents | critical | 8.5 | 1 | Data Breach |
| 3467 | CVE-2025-34085 (Simple File List) | critical | 8.5 | 1 | Exploitation Campaign |
| 3468 | Application misconfiguration | critical | 8.5 | 1 | Data Breach |
| 3469 | Unauthorized data sharing via embedded tracking tools | critical | 8.5 | 1 | Data Breach |
| 3470 | Compromised OAuth tokens in Gainsight-published applications (no vulnerability in Salesforce platform itself) | critical | 8.5 | 1 | Data Breach |
| 3471 | Inadequate governance for AI systems | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 3472 | Weak password storage (base64 hashes or unhashed passwords) | critical | 8.5 | 1 | Data Breach |
| 3473 | CVE-2026-31431 | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3474 | CVE-2025-14847 (Improper handling of length parameter inconsistency, CWE-130) | critical | 8.5 | 1 | Memory-Read Vulnerability |
| 3475 | Unmonitored mass data downloads/email exfiltration | critical | 8.5 | 1 | Data Breach |
| 3476 | URL Vulnerability | critical | 8.5 | 1 | Data Breach |
| 3477 | SSO Credentials (Okta) | critical | 8.5 | 1 | Data Breach |
| 3478 | WebKit remote code execution (RCE) | critical | 8.5 | 1 | Exploit Kit |
| 3479 | CVE-2025-31191 | critical | 8.5 | 1 | Sandbox Escape Vulnerability |
| 3480 | CVE-2025-54236 (SessionReaper) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3481 | inadequate validation of third-party services (Cloudflare Pages) | critical | 8.5 | 1 | phishing |
| 3482 | CVE-2026-34070 | critical | 8.5 | 1 | Data Exfiltration |
| 3483 | Human Error (Impersonation) | critical | 8.5 | 1 | Data Breach |
| 3484 | Unrestricted internet access to real-time surveillance data without authentication | critical | 8.5 | 1 | Data Breach |
| 3485 | Inadequate employee training on cybersecurity risks | critical | 8.5 | 1 | Data Breach |
| 3486 | IDOR | critical | 8.5 | 1 | Data Breach |
| 3487 | Inadequate security awareness training | critical | 8.5 | 1 | Phishing |
| 3488 | CVE-2026-29146 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3489 | CVE-2026-39987 (Marimo RCE) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3490 | GitHub Actions OIDC tokens, trusted publishing subversion | critical | 8.5 | 1 | Supply Chain Attack |
| 3491 | Identity and Access Management (IAM) Failures | critical | 8.5 | 1 | Data Breach |
| 3492 | CVE-2024-3210 | critical | 8.5 | 1 | Data Breach |
| 3493 | Zero-day vulnerability in third-party software (patched post-incident) | critical | 8.5 | 1 | Data Breach |
| 3494 | Intent redirection vulnerability in EngageLab SDK (version 4.5.4) | critical | 8.5 | 1 | Supply Chain Vulnerability |
| 3495 | Social Engineering, macOS TCC Bypass (SQL Injection into Privacy Database) | critical | 8.5 | 1 | Phishing, Malware |
| 3496 | Multi-tenant SaaS identity platform vulnerabilities | critical | 8.5 | 1 | AI-related identity breach |
| 3497 | Third-party vulnerability | critical | 8.5 | 1 | Data Breach |
| 3498 | Oracle WebLogic Vulnerability (CVE not specified) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3499 | CVE-2026-21570 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3500 | GitHub Actions pull_request_target trigger | critical | 8.5 | 1 | Supply Chain Attack |
| 3501 | Lack of MFA resilience, Human susceptibility to social engineering | critical | 8.5 | 1 | Phishing/Social Engineering |
| 3502 | Unpatched vulnerabilities, Unintentional installation of malware by IT personnel with admin privileges | critical | 8.5 | 1 | Supply Chain Attack, Data Breach |
| 3503 | CVE-2025-54136 (MCPoison) - Trust Model Flaw in MCP Configuration Handling | critical | 8.5 | 1 | Vulnerability |
| 3504 | Unauthorized data transmission via third-party trackers | critical | 8.5 | 1 | Data Breach |
| 3505 | Oracle WebLogic Server vulnerability | critical | 8.5 | 1 | Data Breach |
| 3506 | TOCTOU (Time-of-Check Time-of-Use) race condition in a SETUID binary | critical | 8.5 | 1 | Privilege Escalation |
| 3507 | CVE-2026-3298 | critical | 8.5 | 1 | Memory Corruption |
| 3508 | Data Migration Error | critical | 8.5 | 1 | Data Breach |
| 3509 | Third-party mail service provider | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 3510 | Tracking code sharing data with third-party advertisers | critical | 8.5 | 1 | Data Breach |
| 3511 | Improper scoping of OAuth permissions in Salesloft Drift (Salesforce-integrated tool) | critical | 8.5 | 1 | Data Breach |
| 3512 | lack of data access controls | critical | 8.5 | 1 | data breach |
| 3513 | CVE-2026-31635 (Missing COW guard in rxgk_decrypt_skb() function) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3514 | Vulnerabilities in online quote tools | critical | 8.5 | 1 | data breach |
| 3515 | Weak third-party credential management | critical | 8.5 | 1 | Data Breach |
| 3516 | Potential unauthorized access to LDLC's customer database (timing suggests link to LDLC's server breach) | critical | 8.5 | 1 | phishing |
| 3517 | Social engineering, in-memory execution, process hollowing, AMSI/ETW bypass | critical | 8.5 | 1 | Spear-Phishing, Malware (Keylogger), Credential Theft |
| 3518 | Vulnerability management failures | critical | 8.5 | 1 | Data Breach |
| 3519 | Unknown vulnerability in Oracle E-Business Suite (CVE not specified) | critical | 8.5 | 1 | Data Breach / Ransomware Attack |
| 3520 | Social engineering, 2FA bypass via credential harvesting | critical | 8.5 | 1 | Phishing |
| 3521 | CVE-2026-0073 (Android Debug Bridge daemon - adbd) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3522 | Unverified Update Mechanism (Lack of Code Signing) | critical | 8.5 | 1 | Vulnerability |
| 3523 | exposed credentials | critical | 8.5 | 1 | phishing |
| 3524 | Human Error (Telecommunications Employee Deception) | critical | 8.5 | 1 | Data Breach |
| 3525 | GraphQL API Misconfiguration | critical | 8.5 | 1 | Data Leak |
| 3526 | CVE-2026-57221 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3527 | Decentralized data movement systems | critical | 8.5 | 1 | Data Governance Blind Spot |
| 3528 | Exposed NPM token from misconfigured CircleCI job (suspected) | critical | 8.5 | 1 | Supply-Chain Attack |
| 3529 | Account verification procedure | critical | 8.5 | 1 | Data Breach |
| 3530 | Outdated security protocols | critical | 8.5 | 1 | Data Breach |
| 3531 | Social engineering, exploitation of legitimate communication channels | critical | 8.5 | 1 | Phishing Scam |
| 3532 | CVE-2026-42897 | critical | 8.5 | 1 | Spoofing Vulnerability |
| 3533 | Human Trust and Psychological Manipulation | critical | 8.5 | 1 | Cryptocurrency Investment Fraud |
| 3534 | Hardcoded AES Encryption Key | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3535 | Weaknesses in university authentication processes | critical | 8.5 | 1 | Data Breach |
| 3536 | CVE-2025-52436 (Improper Neutralization of Input During Web Page Generation - CWE-79) | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 3537 | Unauthorized access to cloud system | critical | 8.5 | 1 | Data Exposure |
| 3538 | insufficient workforce training | critical | 8.5 | 1 | ransomware |
| 3539 | Misconfigured Storage Buckets | critical | 8.5 | 1 | Data Leak |
| 3540 | CVE-2026-0257 | critical | 8.5 | 1 | Authentication Bypass |
| 3541 | Inadequately secured network (Salesloft) | critical | 8.5 | 1 | Data Breach (Third-Party Vendor Compromise) |
| 3542 | improper access controls (configuration gap in S3 bucket permissions) | critical | 8.5 | 1 | data breach |
| 3543 | Lack of input validation in web configuration interfaces | critical | 8.5 | 1 | DNS Hijacking |
| 3544 | Insufficient de-identification | critical | 8.5 | 1 | Data Breach |
| 3545 | Malicious code in online store | critical | 8.5 | 1 | Data Breach |
| 3546 | Error in server configuration change | critical | 8.5 | 1 | Data Breach |
| 3547 | Gemini Cloud Assist (Log Summarization Flaw) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3548 | Oracle E-Business Suite (Zero-Day) | critical | 8.5 | 1 | Cyberattack (Data Breach) |
| 3549 | Lack of access controls and encryption | critical | 8.5 | 1 | Data Breach |
| 3550 | Misconfigured Database Access Controls | critical | 8.5 | 1 | Data Exposure |
| 3551 | Improper handling of branch names during task execution | critical | 8.5 | 1 | Command Injection |
| 3552 | CVE-2026-34040 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3553 | CVE-2026-23631 (DarkReplica) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3554 | Credential Reuse | critical | 8.5 | 1 | Credential Exposure |
| 3555 | E-commerce web platform | critical | 8.5 | 1 | Data Breach |
| 3556 | Trust in community integrations, lack of sandboxing in n8n community nodes | critical | 8.5 | 1 | Supply Chain Attack |
| 3557 | CVE-2026-20184 (CWE-295) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3558 | compromised Booking.com accounts | critical | 8.5 | 1 | phishing |
| 3559 | Broken object-level authorization (BOLA) (40%) | critical | 8.5 | 1 | API Security Breach |
| 3560 | Deceptive chats impersonating Signal Support chatbot | critical | 8.5 | 1 | Cyber Espionage |
| 3561 | Coding Transmission Error | critical | 8.5 | 1 | Data Breach |
| 3562 | Excessive permissions, hidden app functionality, cloud service abuse (Firebase, Google Apps Script, Telegram, Google Drive) | critical | 8.5 | 1 | Malware (Remote Access Trojan - RAT) |
| 3563 | Cisco Unified CM exploit | critical | 8.5 | 1 | Third-Party Risk Management Failure |
| 3564 | Typosquatting, impersonation, and automatic execution of post-install scripts | critical | 8.5 | 1 | Supply Chain Attack |
| 3565 | Unencrypted data on decommissioned equipment | critical | 8.5 | 1 | Data Breach |
| 3566 | Incomplete containment of earlier breach (hackerbot-claw), non-atomic token rotation, mutable version tags | critical | 8.5 | 1 | Supply Chain Attack |
| 3567 | CVE-2026-54432 | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 3568 | Deceptive imposter commit via attacker-controlled fork | critical | 8.5 | 1 | Supply Chain Attack |
| 3569 | CVE-2026-41651 (PackageKit authorization bypass) | critical | 8.5 | 1 | Privilege Escalation |
| 3570 | Improper Database Security | critical | 8.5 | 1 | Data Leak |
| 3571 | Infostealer malware distributed via compromised npm package (TanStack) | critical | 8.5 | 1 | Data Breach |
| 3572 | CVE-2025-1724 | critical | 8.5 | 1 | Authentication Vulnerability |
| 3573 | CVE-2026-6686 (Uninitialized cluster exposure) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3574 | Insufficient credential security | critical | 8.5 | 1 | Data Breach |
| 3575 | CVE-2026-25108 (OS Command Injection - CWE-78) | critical | 8.5 | 1 | Command Injection |
| 3576 | Overbroad OAuth Token Permissions | critical | 8.5 | 1 | Data Breach |
| 3577 | AI-Generated Convincing Impersonations | critical | 8.5 | 1 | Data Breach |
| 3578 | Third-party oversight failures | critical | 8.5 | 1 | Data Breach |
| 3579 | Bug in secondary code path failing to confirm email address match during password reset | critical | 8.5 | 1 | Account Takeover |
| 3580 | Six low-severity flaws | critical | 8.5 | 1 | Data Leak |
| 3581 | Microsoft Teams default external messaging settings | critical | 8.5 | 1 | Phishing |
| 3582 | Double-free flaw in `rds_message_zcopy_from_user()` function (CVE pending) | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 3583 | CVE-2025-54253 (Misconfiguration in AEM Forms - Apache Struts 'devMode' enabled + Authentication Bypass) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3584 | Sanctioned Platform Persistence | critical | 8.5 | 1 | Surveillance |
| 3585 | Architectural weakness in Google Gemini Enterprise and Vertex AI Search (RAG-based trust boundary exploitation) | critical | 8.5 | 1 | Zero-Click Vulnerability, Indirect Prompt Injection |
| 3586 | Lack of Multi-Factor Authentication (implied) | critical | 8.5 | 1 | Data Breach |
| 3587 | CVE-2026-3098 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3588 | Parking Permit System Flaw (since 2017) | critical | 8.5 | 1 | Data Breach |
| 3589 | A setting within one of Petco's software applications that inadvertently allowed certain files to be accessible online | critical | 8.5 | 1 | Data Breach |
| 3590 | Weak encryption in data-sharing mandates | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 3591 | Lack of sandboxing in AI-generated test cases (Claude Code) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 3592 | CVE-2026-21876 | critical | 8.5 | 1 | vulnerability |
| 3593 | CVE-2025-14560 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3594 | SIM swapping | critical | 8.5 | 1 | wire fraud |
| 3595 | Backup Database Access | critical | 8.5 | 1 | Data Breach |
| 3596 | Info-stealing malware infections, lack of multi-factor authentication | critical | 8.5 | 1 | Credential Stuffing |
| 3597 | Broken Object Level Authorization (BOLA) | critical | 8.5 | 1 | Data Breach |
| 3598 | Website Vulnerabilities | critical | 8.5 | 1 | Data Leak |
| 3599 | CWE-284: Improper Access Control | critical | 8.5 | 1 | Data Exposure |
| 3600 | Stolen credentials (Okta SSO account of a support agent) | critical | 8.5 | 1 | Data Breach |
| 3601 | Improper data retention (post-contract) | critical | 8.5 | 1 | Data Breach |
| 3602 | RoguePilot (GitHub Codespaces/Copilot) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3603 | CVE-2026-52830 (GHSA-rxw2-pc8j-vxwm) | critical | 8.5 | 1 | Authentication Bypass |
| 3604 | Weaknesses in IVR System Authentication | critical | 8.5 | 1 | Cyberattack |
| 3605 | Lack of Encryption on Laptop | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 3606 | Inadequate protection of sensitive consumer data | critical | 8.5 | 1 | Data Breach |
| 3607 | GitHub Account Security Weakness | critical | 8.5 | 1 | Data Breach |
| 3608 | CVE (3 high-severity with publicly available exploit code) | critical | 8.5 | 1 | Misconfiguration |
| 3609 | Social Engineering, Impersonation of Legitimate Services | critical | 8.5 | 1 | Phishing |
| 3610 | Abuse of Microsoft 365 mailbox rules and Outlook features | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 3611 | Trivial vulnerability | critical | 8.5 | 1 | Data Breach |
| 3612 | Incomplete deployment steps (live /install/install.php page), lack of reinstallation safeguards, server-side session state storage | critical | 8.5 | 1 | Security Misconfiguration |
| 3613 | Human error (social engineering of third-party employee) | critical | 8.5 | 1 | Data Breach |
| 3614 | CVE-2026-45447 (heap use-after-free in PKCS#7 signature verification) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3615 | CVE-2021-29441 (Nacos configuration server) | critical | 8.5 | 1 | Webshell Attack |
| 3616 | Improperly secured database | critical | 8.5 | 1 | Data Exposure |
| 3617 | CVE-2026-8451 | critical | 8.5 | 1 | Memory Disclosure Vulnerability Exploitation |
| 3618 | Lack of reasonable cyber security measures | critical | 8.5 | 1 | Data Breach |
| 3619 | Previously unknown security vulnerability in Oracle E-Business Suite | critical | 8.5 | 1 | Data Breach |
| 3620 | Unknown system flaws in retail/luxury brand infrastructure | critical | 8.5 | 1 | Data Breach |
| 3621 | Lack of monitoring for suspicious activity | critical | 8.5 | 1 | Data Breach |
| 3622 | CVE-2026-34500 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3623 | Progress Software MOVEit file transfer application vulnerability | critical | 8.5 | 1 | Data Breach |
| 3624 | Security flaw in third-party software | critical | 8.5 | 1 | Data Breach |
| 3625 | Phishing or Credential Compromise | critical | 8.5 | 1 | Data Breach |
| 3626 | Bypass of tool allowlisting under --yolo mode | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3627 | CVE-2026-2031 (CVSS 10.0), access control misconfigurations, IDOR, protobuf descriptor leakage | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3628 | Price oracle vulnerability in DeFi protocol | critical | 8.5 | 1 | DeFi Exploit |
| 3629 | Decentralized Security Coordination | critical | 8.5 | 1 | Data Breach |
| 3630 | Centralized biometric databases, Lack of robust safeguards, Third-party vendor vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 3631 | CVE-2024-28989 | critical | 8.5 | 1 | Vulnerability Exploit |
| 3632 | Hardcoded credentials in web code | critical | 8.5 | 1 | Data Breach |
| 3633 | CVE-2026-0629 | critical | 8.5 | 1 | Authentication Bypass |
| 3634 | Compromise of private keys | critical | 8.5 | 1 | Security Breach |
| 3635 | GX Mods automatic installation and CSS injection | critical | 8.5 | 1 | Data Exfiltration |
| 3636 | Software vulnerabilities (AI-accelerated identification) | critical | 8.5 | 1 | Cyber Espionage, Critical Infrastructure Attack, Data Breach |
| 3637 | Malicious package versions (PyTorch Lightning 2.6.2, 2.6.3; intercom-client 7.0.4) | critical | 8.5 | 1 | Supply Chain Attack |
| 3638 | weak validator key security | critical | 8.5 | 1 | blockchain exploit |
| 3639 | Insufficient URL Security | critical | 8.5 | 1 | Data Breach |
| 3640 | Windows automatic DLL loading | critical | 8.5 | 1 | Malware Campaign |
| 3641 | Poor M365 configurations | critical | 8.5 | 1 | Data Breach |
| 3642 | 15 security flaws in graphics drivers, including nine high-severity vulnerabilities | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3643 | Internet-exposed SSH (port 22 open to 0.0.0.0/0), Overly permissive IAM roles | critical | 8.5 | 1 | Cryptomining Attack |
| 3644 | CVE-2025-55232 (Microsoft HPC Pack RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3645 | Unpatched RCE vulnerabilities | critical | 8.5 | 1 | Botnet |
| 3646 | Cross-border data storage without GDPR-equivalent protections | critical | 8.5 | 1 | Data Breach Risk |
| 3647 | CVE-2025-54113 (Windows RRAS RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 3648 | Amazon S3 Storage Account | critical | 8.5 | 1 | Data Breach |
| 3649 | AutoConsent JS bridge in DuckDuckGo Android browser (UXSS) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3650 | MOVEit Secure File Transfer server | critical | 8.5 | 1 | Data Breach |
| 3651 | Vendor Error | critical | 8.5 | 1 | Data Breach |
| 3652 | SharePoint and Defender Zero-Days (Microsoft) | critical | 8.5 | 1 | Data Breach |
| 3653 | CVE-2021-44228 (Log4Shell) | critical | 8.5 | 1 | Exploit Trends |
| 3654 | account takeover (ATO) | critical | 8.5 | 1 | supply-chain attack |
| 3655 | CVE-2026-24281 | critical | 8.5 | 1 | Data Exposure |
| 3656 | Insider Access Abuse | critical | 8.5 | 1 | Data Breach |
| 3657 | Software vulnerability in the online shop portal | critical | 8.5 | 1 | Data Breach |
| 3658 | Credential theft via Microsoft Entra account | critical | 8.5 | 1 | Phishing Attack |
| 3659 | CVE-2026-45504 | critical | 8.5 | 1 | SSRF (Server-Side Request Forgery) |
| 3660 | Glitch in License Express website | critical | 8.5 | 1 | Data Exposure |
| 3661 | Insecure Amazon S3 databases | critical | 8.5 | 1 | Data Exposure |
| 3662 | CVE-2026-20643 (WebKit Navigation API improper input validation) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3663 | Excessive Data Access Permissions | critical | 8.5 | 1 | Data Breach |
| 3664 | Unauthorized access due to unverified data-sharing requests | critical | 8.5 | 1 | Data Breach |
| 3665 | Unauthorized access by staff | critical | 8.5 | 1 | Data Breach |
| 3666 | ConnectWise software vulnerability | critical | 8.5 | 1 | Data Breach |
| 3667 | CVE-2026-6683 (exFAT divide-by-zero) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3668 | Weaknesses in third-party integrations with Salesforce-connected applications (not Salesforce itself) | critical | 8.5 | 1 | Data Breach |
| 3669 | Three separate flaws in Automotive Grade Linux | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 3670 | lack of credential rotation | critical | 8.5 | 1 | data breach |
| 3671 | Password plugin session-injection flaws | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 3672 | CVE-2026-23597 | critical | 8.5 | 1 | Privilege Escalation |
| 3673 | misconfigured Azure Blob storage permissions | critical | 8.5 | 1 | data exposure |
| 3674 | CVE-2026-21514 (CWE-807) | critical | 8.5 | 1 | Security Feature Bypass |
| 3675 | Inconsistent security measures | critical | 8.5 | 1 | Phishing |
| 3676 | Steganography (hidden JavaScript in PNG files), lack of strict extension vetting | critical | 8.5 | 1 | Malware Campaign |
| 3677 | Plain text storage of login details | critical | 8.5 | 1 | Data Breach |
| 3678 | Social engineering (PIN disclosure) | critical | 8.5 | 1 | Phishing |
| 3679 | Irreversible Identity Linking in NFT Ownership | critical | 8.5 | 1 | Privacy Violation |
| 3680 | Excessive Discord SDK logging writing private data to local log files in plaintext | critical | 8.5 | 1 | Data Exposure |
| 3681 | user trust in legitimate cryptocurrency wallet applications | critical | 8.5 | 1 | malware |
| 3682 | Remote code execution vulnerability in Secure Mobile Access (SMA) appliances | critical | 8.5 | 1 | Remote Code Execution |
| 3683 | Accellion File Transfer Appliance vulnerability | critical | 8.5 | 1 | Data Breach |
| 3684 | Insufficient monitoring and control over non-human credentials | critical | 8.5 | 1 | Data Breach / Lateral Movement |
| 3685 | Kademlia-based P2P Network | critical | 8.5 | 1 | Zero-day Exploitation |
| 3686 | Indirect prompt injection in AI agents | critical | 8.5 | 1 | Indirect Prompt Injection Attack |
| 3687 | Network Access Feature in Claude (Sandbox Environment) | critical | 8.5 | 1 | Data Exfiltration |
| 3688 | Unauthorized administrative access | critical | 8.5 | 1 | Data Leak |
| 3689 | Gateway between the airline and a payment processor | critical | 8.5 | 1 | Data Breach |
| 3690 | Session management vulnerability in cookie-based authentication | critical | 8.5 | 1 | Authentication Bypass |
| 3691 | CVE-2025-3648 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3692 | Full takeover of Tesla’s infotainment system | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 3693 | Ivanti Endpoint Manager Mobile flaw | critical | 8.5 | 1 | Data Breach |
| 3694 | CVE-2026-4048 | critical | 8.5 | 1 | vulnerability |
| 3695 | Human Error (Employee Susceptibility to Phishing) | critical | 8.5 | 1 | Data Breach |
| 3696 | Weak User Authentication | critical | 8.5 | 1 | Data Breach |
| 3697 | Static Credentials in Setup Files | critical | 8.5 | 1 | Misconfiguration |
| 3698 | Trusted domain abuse (googletagmanager.com, api.stripe.com), lack of strict content security policies (CSP) | critical | 8.5 | 1 | Magecart (Digital Skimming) |
| 3699 | DoS in compressed-RTF attachments | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 3700 | Progress MOVEit Transfer tool | critical | 8.5 | 1 | Data Breach |
| 3701 | CVE-2026-4798 (CVSS 7.5) | critical | 8.5 | 1 | SQL Injection |
| 3702 | Delayed breach detection | critical | 8.5 | 1 | Data Breach |
| 3703 | Weak security practices | critical | 8.5 | 1 | Fraud/Scam |
| 3704 | Hardcoded login credentials in the source code | critical | 8.5 | 1 | Data Breach |
| 3705 | CVE-2026-40372 | critical | 8.5 | 1 | Privilege Escalation |
| 3706 | CBC encryption padding oracle | critical | 8.5 | 1 | Data Breach |
| 3707 | Governance gap in data access controls | critical | 8.5 | 1 | Third-party data exploitation |
| 3708 | Reuse of leaked personal data, Lack of user awareness | critical | 8.5 | 1 | Phishing / Social Engineering |
| 3709 | Progress Software's MOVEit secure file transfer tool | critical | 8.5 | 1 | Data Breach |
| 3710 | Unsecured legacy server | critical | 8.5 | 1 | Data Exposure |
| 3711 | Social engineering (fake software downloads) | critical | 8.5 | 1 | Infostealer Campaign |
| 3712 | Human (Employee Susceptibility to Phishing) | critical | 8.5 | 1 | Data Breach |
| 3713 | Unauthorized access to medical records | critical | 8.5 | 1 | Data Breach |
| 3714 | Several vulnerabilities in the Likud app | critical | 8.5 | 1 | Data Breach |
| 3715 | CVE-2025-61984 (Inadequate filtering of control characters in usernames for ProxyCommand in OpenSSH) | critical | 8.5 | 1 | Vulnerability |
| 3716 | CVE-2026-26123 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3717 | CVE-2026-3055 (Citrix NetScaler) | critical | 8.5 | 1 | data_breach |
| 3718 | Debug Log File | critical | 8.5 | 1 | Data Breach |
| 3719 | Unauthenticated access via installed apps on streaming devices | critical | 8.5 | 1 | Unauthorized Proxy Network |
| 3720 | Notification data retention flaw in iOS | critical | 8.5 | 1 | Privacy Flaw / Data Retention Vulnerability |
| 3721 | Unauthorized AI Data Access | critical | 8.5 | 1 | Data Breach |
| 3722 | CVE-2026-32647 (Out-of-bounds read in ngx_http_mp4_module) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3723 | CVE-2025-8088 (WinRAR path traversal flaw in Windows versions < 7.13) | critical | 8.5 | 1 | Zero-day exploit |
| 3724 | Service Account Credential | critical | 8.5 | 1 | Data Breach |
| 3725 | ShadowLeak (CVE pending) | critical | 8.5 | 1 | Data Exfiltration |
| 3726 | CVE-2026-25089 | critical | 8.5 | 1 | Data Breach |
| 3727 | Improper Input/Output Sanitization in AI Chatbot (XSS) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3728 | Potential Weak Email Security Controls | critical | 8.5 | 1 | Phishing |
| 3729 | CVE-2026-11645 (Out-of-bounds memory access in V8 JavaScript engine) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3730 | Generic Out-of-Bounds Read/Write in C/C++ (e.g., unchecked array indexing, `strcpy` overflows) | critical | 8.5 | 1 | Memory Corruption |
| 3731 | Zero-day vulnerability in MOVEit Transfer application | critical | 8.5 | 1 | Data Breach |
| 3732 | CVE-2026-50656 | critical | 8.5 | 1 | Data Breach |
| 3733 | CVE-2026-25172 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3734 | Weak or default SSH credentials | critical | 8.5 | 1 | Botnet |
| 3735 | Use-After-Free | critical | 8.5 | 1 | Privilege Escalation |
| 3736 | Training gaps | critical | 8.5 | 1 | Data Breach |
| 3737 | Phone signal interception | critical | 8.5 | 1 | Surveillance |
| 3738 | Misconfiguration in Trivy vulnerability scanner | critical | 8.5 | 1 | Supply Chain Attack |
| 3739 | Employee email account compromise | critical | 8.5 | 1 | Phishing Attack |
| 3740 | Lack of end-to-end encryption for ID uploads | critical | 8.5 | 1 | Data Breach Risk |
| 3741 | User trust and lack of awareness | critical | 8.5 | 1 | Phishing |
| 3742 | Authorization control bypass in Google Gemini | critical | 8.5 | 1 | Indirect Prompt Injection |
| 3743 | persistent background execution via detached screen sessions | critical | 8.5 | 1 | malware |
| 3744 | Human error (employee susceptibility to scams), lack of robust multi-factor authentication (MFA) enforcement | critical | 8.5 | 1 | Data Breach |
| 3745 | Improper handling of inter-app data access in EngageLab SDK | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3746 | Java | critical | 8.5 | 1 | Cyber Attack |
| 3747 | Unpatched React frontend application | critical | 8.5 | 1 | Data Breach |
| 3748 | CVE-2025-67601 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3749 | manque de protection des terminaux personnels | critical | 8.5 | 1 | cyberattaque |
| 3750 | Unpatched 'n-day' vulnerability in end-of-life software | critical | 8.5 | 1 | Data Breach |
| 3751 | Bias and Unverified Data Propagation | critical | 8.5 | 1 | Data Privacy Issue |
| 3752 | CVE-2026-27728 | critical | 8.5 | 1 | Command Injection |
| 3753 | social engineering targeting IT helpdesks | critical | 8.5 | 1 | data breach |
| 3754 | Lack of input sanitization in AI agents parsing GitHub content | critical | 8.5 | 1 | Indirect Prompt-Injection Vulnerability |
| 3755 | Insufficient access controls / Policy violation | critical | 8.5 | 1 | Unauthorized Access / Data Breach |
| 3756 | Lack of Robust Guardrails for Non-Text Modalities | critical | 8.5 | 1 | Prompt Extraction |
| 3757 | Bias in AI algorithms (e.g., loan approvals, credit scoring) | critical | 8.5 | 1 | Cybersecurity Risk Assessment |
| 3758 | Lack of security audits for employee-facing ecommerce platforms | critical | 8.5 | 1 | Keylogger Attack |
| 3759 | Unsecured Data Transmission | critical | 8.5 | 1 | Data Breach |
| 3760 | Abandoned software in trusted repository | critical | 8.5 | 1 | Phishing |
| 3761 | Human Error (Inadvertent Publication of Sensitive Data) | critical | 8.5 | 1 | Data Breach (Inadvertent Disclosure) |
| 3762 | Lateral Movement within Internal Systems | critical | 8.5 | 1 | Data Breach |
| 3763 | Cisco SD-WAN flaws | critical | 8.5 | 1 | APT Activity |
| 3764 | CVE-2025-33230 | critical | 8.5 | 1 | Vulnerability |
| 3765 | Preventable authorization flaw, path manipulation in web address | critical | 8.5 | 1 | Data Breach |
| 3766 | CVE-2023-50224 (TP-Link WR841N routers) | critical | 8.5 | 1 | Cyberespionage |
| 3767 | Unprotected Cloud Repository | critical | 8.5 | 1 | Data Leak |
| 3768 | Weak or Stolen Employee Credentials | critical | 8.5 | 1 | Data Breach |
| 3769 | CVE-2026-21513 | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3770 | CVE-2026-23596 | critical | 8.5 | 1 | Privilege Escalation |
| 3771 | Unusual access to GitHub repositories | critical | 8.5 | 1 | Hacking/Unauthorized Access |
| 3772 | Unspecified vulnerability in OT security solutions | critical | 8.5 | 1 | Data Breach |
| 3773 | Out-of-bounds write flaw in Alpitronic HYC50 EV charger | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 3774 | Inadequate cloud storage security | critical | 8.5 | 1 | Data Breach |
| 3775 | Clerical Error | critical | 8.5 | 1 | Data Breach |
| 3776 | Insufficient Access Controls / Lack of Monitoring | critical | 8.5 | 1 | Unauthorized Access / Data Breach |
| 3777 | Fake Kubernetes tools | critical | 8.5 | 1 | Supply Chain Attack |
| 3778 | Legacy email protections | critical | 8.5 | 1 | Phishing |
| 3779 | VS Code zero-day | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3780 | Improper FOIA Redaction Procedures | critical | 8.5 | 1 | Data Breach |
| 3781 | AI-driven systems and expanded attack surfaces | critical | 8.5 | 1 | Data Breach |
| 3782 | Insufficient access controls, disabled security measures | critical | 8.5 | 1 | Data Breach, Election Security Tampering |
| 3783 | CREATE EXTERNAL MODEL (NTLM coercion) | critical | 8.5 | 1 | Data Exfiltration |
| 3784 | CVE-2026-23598 | critical | 8.5 | 1 | Privilege Escalation |
| 3785 | Improper Token Management | critical | 8.5 | 1 | Data Breach |
| 3786 | Failure to follow internal procedures and licensing obligations | critical | 8.5 | 1 | SIM Swap Attack |
| 3787 | Fake Office 365 login pages | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 3788 | CVE-2025-59145 (Invisible Markdown Comment Syntax Abuse) | critical | 8.5 | 1 | Data Exfiltration |
| 3789 | CVE-2026-34926 (Directory Traversal - CWE-23) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3790 | Weak incident response plans | critical | 8.5 | 1 | Data exfiltration |
| 3791 | Lack of cybersecurity hygiene, insufficient vendor expertise | critical | 8.5 | 1 | Security Probe |
| 3792 | CVE-2026-26030 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3793 | CVE-2026-46376 (Use of Hard-coded Credentials - CWE-798) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3794 | Centralized Points of Failure in Hybrid Platforms | critical | 8.5 | 1 | Privacy Violation |
| 3795 | Test mode left enabled allowing OTP login via email keyword | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 3796 | CVE-2026-20204 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3797 | Improper TLS Certificate Validation (CWE-295) | critical | 8.5 | 1 | Vulnerability |
| 3798 | CVE-2026-3518 | critical | 8.5 | 1 | vulnerability |
| 3799 | Shared Inbox Access | critical | 8.5 | 1 | Data Breach |
| 3800 | Lack of Authentication or Access Restrictions | critical | 8.5 | 1 | Data Leak |
| 3801 | CVE-2026-5281 (Use-After-Free in Google Dawn/WebGPU) | critical | 8.5 | 1 | Zero-Day Vulnerability Exploitation |
| 3802 | Technical failure in recognizing court updates | critical | 8.5 | 1 | Data Leak |
| 3803 | CVE-2026-7198 (CVSS 9.8) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3804 | Human Manipulation (Social Engineering) | critical | 8.5 | 1 | Phishing (Vishing) |
| 3805 | CVE-2026-4387 | critical | 8.5 | 1 | Authentication Flaw |
| 3806 | Weaknesses in vendor credential management | critical | 8.5 | 1 | Data Breach |
| 3807 | Weaknesses in lock systems | critical | 8.5 | 1 | Hardware vulnerability |
| 3808 | Publicly Accessible Firebase Storage Bucket | critical | 8.5 | 1 | Data Breach |
| 3809 | Software vulnerabilities in AI tools (e.g., backdoors, bugs) | critical | 8.5 | 1 | Data Leakage |
| 3810 | CVE-2026-2835 | critical | 8.5 | 1 | HTTP Request Smuggling |
| 3811 | Name-squatting and postinstall script execution | critical | 8.5 | 1 | Supply Chain Attack |
| 3812 | weak cybersecurity safeguards in third-party vendor (Salesforce) | critical | 8.5 | 1 | data breach |
| 3813 | Human error (tricked customer support employees into granting access) | critical | 8.5 | 1 | Data Breach |
| 3814 | Insecure defaults in Google Cloud Platform (GCP) API key architecture | critical | 8.5 | 1 | Data Exposure |
| 3815 | Insecure APIs | critical | 8.5 | 1 | Data Breach |
| 3816 | Legacy encryption | critical | 8.5 | 1 | Data Breach/Vulnerability Exposure |
| 3817 | Lack of Network Segmentation in Cloud | critical | 8.5 | 1 | Cloud Security Breach |
| 3818 | Human Factor (Social Engineering) | critical | 8.5 | 1 | Data Breach |
| 3819 | Stolen Login Information | critical | 8.5 | 1 | Data Breach |
| 3820 | CVE-2026-0073 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3821 | CVE-2026-1220 (Race Condition in V8 JavaScript Engine) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3822 | Insider access to patient records | critical | 8.5 | 1 | Data Breach |
| 3823 | nx npm Package Compromise | critical | 8.5 | 1 | Zero-day Exploitation |
| 3824 | Lack of person-of-interest threat profiling, limited protective measures for non-executive employees, absence of automated defenses against AI agents | critical | 8.5 | 1 | AI-driven impersonation attack |
| 3825 | Misconfigured Google Firebase database | critical | 8.5 | 1 | Data Breach |
| 3826 | AI guardrail bypass via social engineering (framing requests as legitimate research) | critical | 8.5 | 1 | AI-Powered Cyberattack |
| 3827 | MOVEit Transfer Vulnerability (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 3828 | API scraping via automated harvesting of user profiles | critical | 8.5 | 1 | Data Breach |
| 3829 | Incomplete redaction of sensitive documents | critical | 8.5 | 1 | Data Exposure |
| 3830 | Potential Configuration Flaws in Shared Platforms (e.g., Salesforce-like systems) | critical | 8.5 | 1 | Data Breach |
| 3831 | Android Activity Layering | critical | 8.5 | 1 | Data Theft |
| 3832 | Unsecured Data Transfer Methods | critical | 8.5 | 1 | Insider Threat |
| 3833 | Lack of Physical Security / Unencrypted Device | critical | 8.5 | 1 | Data Breach (Physical Theft) |
| 3834 | CVE-2026-11645 (Out-of-bounds read and write in V8 JavaScript engine) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 3835 | Insecure Third-Party Integration (Drift-Salesforce/Google Workspace) | critical | 8.5 | 1 | Data Breach |
| 3836 | Secure file transfer software | critical | 8.5 | 1 | Data Breach |
| 3837 | Inconsistent DLP controls | critical | 8.5 | 1 | Data Breach |
| 3838 | Unprotected Elasticsearch instance | critical | 8.5 | 1 | Data Exposure |
| 3839 | Coding error in PayPal Working Capital (PPWC) loan application | critical | 8.5 | 1 | Data Breach |
| 3840 | Improperly configured Amazon S3 bucket | critical | 8.5 | 1 | Data Exposure |
| 3841 | CVE-2026-48907 (Joomla JCE editor) | critical | 8.5 | 1 | Webshell Attack |
| 3842 | Unmaintained VPN remote access server, inadequate network monitoring, ambiguous division of responsibilities, accumulation of unmanaged data on network drives | critical | 8.5 | 1 | Data Breach |
| 3843 | Public chat rooms unencrypted and accessible to any user, hardcoded LDAP credentials in shared scripts | critical | 8.5 | 1 | Data Breach |
| 3844 | Microsoft Entra SSO Code | critical | 8.5 | 1 | Data Breach |
| 3845 | CVE-2025-54236 (SessionReaper - Session Data Storage on File System) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3846 | Lack of Authentication on Cloud Storage | critical | 8.5 | 1 | Data Exposure |
| 3847 | limited cybersecurity resources | critical | 8.5 | 1 | data breach |
| 3848 | SQL injection (20.0%) | critical | 8.5 | 1 | API Security Breach |
| 3849 | PHP Backdoor in WordPress Plugins | critical | 8.5 | 1 | Data Breach |
| 3850 | Windows’ Restart Manager (RstrtMgr.dll) exploitation for disabling security processes | critical | 8.5 | 1 | Potentially Unwanted Application (PUA) |
| 3851 | Social Engineering (Employee Compromise) | critical | 8.5 | 1 | Data Breach |
| 3852 | Technical error in user data retrieval/logic (likely session or caching misconfiguration) | critical | 8.5 | 1 | Data Exposure (Unintentional Disclosure) |
| 3853 | Backend API endpoint lacking proper authentication checks | critical | 8.5 | 1 | Data Breach |
| 3854 | Publicly Accessible Cloud Database | critical | 8.5 | 1 | Data Exposure |
| 3855 | Third-Party CRM Security Weaknesses | critical | 8.5 | 1 | Data Breach |
| 3856 | Branch Predictor Race Conditions (BPRC) in Intel Processors (Speculative Execution Side Channel) | critical | 8.5 | 1 | Hardware Vulnerability |
| 3857 | Unsanitized parameters in database queries leading to SQL injection | critical | 8.5 | 1 | SQL Injection |
| 3858 | CVE-2025-67644 | critical | 8.5 | 1 | Data Exfiltration |
| 3859 | Redis code execution | critical | 8.5 | 1 | Supply Chain Attack |
| 3860 | Obfuscated Payloads | critical | 8.5 | 1 | Phishing |
| 3861 | Instagram API (alleged) | critical | 8.5 | 1 | Data Scrape / Alleged Breach |
| 3862 | Lack of user awareness, Apple *Activation Lock* bypass tools (e.g., *FMI OFF*), iCloud Webkit phishing kits | critical | 8.5 | 1 | Phishing, Unauthorized Unlocking, Black Market Operations |
| 3863 | CVE-2025-68664 | critical | 8.5 | 1 | Data Exfiltration |
| 3864 | AI Supply Chain Weaknesses | critical | 8.5 | 1 | Supply Chain Attack |
| 3865 | ATM switch server compromise | critical | 8.5 | 1 | ATM cash-out fraud |
| 3866 | CVE-2026-48282 (Path Traversal) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3867 | lack of multi-signature validation for critical operations | critical | 8.5 | 1 | blockchain exploit |
| 3868 | unpatched cloud tools (speculated) | critical | 8.5 | 1 | data breach |
| 3869 | Unsecured Amazon Web Services (AWS) S3 bucket lacking proper access controls | critical | 8.5 | 1 | Data Breach |
| 3870 | CVE-2025-0033 (Race Condition in AMD SEV-SNP RMP Initialization) | critical | 8.5 | 1 | Vulnerability |
| 3871 | Improper access controls on PDF-generating page | critical | 8.5 | 1 | Data Exposure |
| 3872 | System update flaw (October 2023) | critical | 8.5 | 1 | Data Exposure |
| 3873 | CVE-2023-32409 (WebKit Sandbox Escape - IronLoader) | critical | 8.5 | 1 | Exploit Kit / Malware Campaign |
| 3874 | Confused Deputy (CWE-441) | critical | 8.5 | 1 | Privilege Escalation |
| 3875 | OPENROWSET (file-level exfiltration) | critical | 8.5 | 1 | Data Exfiltration |
| 3876 | AWS Bedrock’s AgentCore Code Interpreter Sandbox Bypass | critical | 8.5 | 1 | Data Exfiltration |
| 3877 | Lack of Cybersecurity Leadership | critical | 8.5 | 1 | Potential Data Breach |
| 3878 | MOVEit Server | critical | 8.5 | 1 | Data Breach |
| 3879 | Progress Software’s MOVEit Transfer solution | critical | 8.5 | 1 | Data Breach |
| 3880 | FortiGate VPN vulnerabilities | critical | 8.5 | 1 | Ransomware |
| 3881 | CVE-2026-21513 (Security Feature Bypass - CWE-693) | critical | 8.5 | 1 | Zero-Day Exploit |
| 3882 | Meraki API keys, unsecured surveillance systems | critical | 8.5 | 1 | Data Breach |
| 3883 | unpatched vulnerabilities in network devices | critical | 8.5 | 1 | ransomware |
| 3884 | Software Vulnerability in InvestorCOM’s systems | critical | 8.5 | 1 | Data Breach |
| 3885 | Misconfigured or repurposed API keys (e.g., Google Maps keys used for Gemini access) | critical | 8.5 | 1 | API Key Exploitation |
| 3886 | CVE-2026-24252 (OS Command Injection) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3887 | Hard-coded passwords in HTML/APIs | critical | 8.5 | 1 | Unauthorized Access |
| 3888 | Server Message Block (SMB) | critical | 8.5 | 1 | phishing |
| 3889 | Cryptographic Flaw in Infineon Microcontroller | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 3890 | Plain text credential storage in memory | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3891 | Inadequate encryption, insufficient vendor security vetting | critical | 8.5 | 1 | Data Breach |
| 3892 | Misunderstandings over Data Ownership | critical | 8.5 | 1 | Insider Threat |
| 3893 | CVE-2023-33538 | critical | 8.5 | 1 | Botnet Deployment |
| 3894 | Legitimate plugin disguise, credential harvesting via hardcoded server | critical | 8.5 | 1 | Malware Campaign |
| 3895 | Misconfigured Amazon Web Services S3 buckets | critical | 8.5 | 1 | Data Leak |
| 3896 | Lack of input validation controls | critical | 8.5 | 1 | Data Security Audit |
| 3897 | Technical Issue with Third-Party Service Provider | critical | 8.5 | 1 | Data Breach |
| 3898 | Key Reuse Vulnerability (Android) | critical | 8.5 | 1 | Privacy Violation |
| 3899 | CVE-2026-42824 | critical | 8.5 | 1 | Data Breach |
| 3900 | Unsecured server, weak account security | critical | 8.5 | 1 | Data Breach |
| 3901 | CVE-2026-0234 (Improper Verification of Cryptographic Signature - CWE-347) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3902 | Human Error (Compromised Employee Email Account) | critical | 8.5 | 1 | Data Breach |
| 3903 | CVE-2023-43000 (WebKit RCE - terrorbird) | critical | 8.5 | 1 | Exploit Kit / Malware Campaign |
| 3904 | lack_of_comprehensive_security_measures | critical | 8.5 | 1 | data_breach |
| 3905 | Biometric authentication exploitation | critical | 8.5 | 1 | Data Breach |
| 3906 | CVE-2024-12847 (Netgear DGN1000/DGN2000) | critical | 8.5 | 1 | Exploit Trends |
| 3907 | Broken Access Control (OWASP Top 10) | critical | 8.5 | 1 | Data Exposure |
| 3908 | Flawed auto-populate feature in online quote platform | critical | 8.5 | 1 | Data Exposure |
| 3909 | GrafanaGhost (flaw in URL validation for AI components) | critical | 8.5 | 1 | Data Exfiltration |
| 3910 | Over-Permissioned OAuth Applications, Exposed Credentials, Weak Monitoring of Environment Variables | critical | 8.5 | 1 | OAuth Abuse, Credential Theft, Lateral Movement |
| 3911 | third-party_integrations | critical | 8.5 | 1 | data_breach |
| 3912 | Software Flaw | critical | 8.5 | 1 | Ransomware |
| 3913 | Net-NTLMv1 Authentication Protocol | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3914 | CVE-2025-13915 (CWE-305: Authentication Bypass by Primary Weakness) | critical | 8.5 | 1 | Authentication Bypass |
| 3915 | Design bug in the FOIA request search feature | critical | 8.5 | 1 | Data Exposure |
| 3916 | Reliance on phone numbers for multi-factor authentication (SMS-based), weak email security, reused passwords, exposed personal data from breaches | critical | 8.5 | 1 | Mobile Fraud (SIM Swapping/Account Takeover) |
| 3917 | DockerDash | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3918 | Credential harvesting via fake Zimbra login portal | critical | 8.5 | 1 | Phishing |
| 3919 | CVE-2026-50107 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 3920 | CVE-2025-14847 (MongoBleed) - unverified | critical | 8.5 | 1 | In-game abuse |
| 3921 | CSRF Protection Mechanism in Ruby on Rails | critical | 8.5 | 1 | Vulnerability |
| 3922 | Unspecified vulnerability in Oracle EBS | critical | 8.5 | 1 | Data Breach |
| 3923 | Semantic Drift in Multimodal AI | critical | 8.5 | 1 | Prompt Extraction |
| 3924 | Use of Unlicensed Software | critical | 8.5 | 1 | Malware |
| 3925 | Awareness of Medicare data breach | critical | 8.5 | 1 | Phishing/Scam |
| 3926 | weak threat-detection system | critical | 8.5 | 1 | data breach |
| 3927 | Mishandling of sensitive data by workers | critical | 8.5 | 1 | Data Breach |
| 3928 | CVE-2025-14174 | critical | 8.5 | 1 | Exploit Kit |
| 3929 | Improper access control in cloud storage | critical | 8.5 | 1 | Data Breach |
| 3930 | Inadequate Third-Party Vetting | critical | 8.5 | 1 | Data Breach |
| 3931 | no encryption | critical | 8.5 | 1 | data breach |
| 3932 | Unprotected publicly accessible database | critical | 8.5 | 1 | Data Leak |
| 3933 | Public web server misconfiguration | critical | 8.5 | 1 | Data Breach |
| 3934 | Insufficient identity verification in hiring processes, reliance on social media badges | critical | 8.5 | 1 | Identity Fraud, Insider Threat, Cyber Espionage |
| 3935 | Lack of Content Verification Mechanisms | critical | 8.5 | 1 | Content Theft and Fraud |
| 3936 | Legislative gap in privacy protections for political parties | critical | 8.5 | 1 | Data Breach |
| 3937 | Weak MD5 hashing | critical | 8.5 | 1 | Data Exposure |
| 3938 | Flaw in the project’s website | critical | 8.5 | 1 | Data Breach |
| 3939 | CVE-2026-22219 (CVSS 8.3) | critical | 8.5 | 1 | Data Breach |
| 3940 | Insufficient sanitization of user input in XML processing | critical | 8.5 | 1 | XML External Entity (XXE) Injection |
| 3941 | Oracle EBS zero-day flaw | critical | 8.5 | 1 | Data Breach |
| 3942 | Download of malicious apps | critical | 8.5 | 1 | Malware |
| 3943 | CVE-2025-51683 (Blind SQL Injection) | critical | 8.5 | 1 | SQL Injection |
| 3944 | Checkout page code issue | critical | 8.5 | 1 | Data Breach |
| 3945 | Unauthorized access to internal systems | critical | 8.5 | 1 | Data Breach, Extortion |
| 3946 | Inadequate safeguards for international data transfers | critical | 8.5 | 1 | Data Breach |
| 3947 | Lack of encryption, plaintext password storage, default passwords, no access restrictions or detection mechanisms | critical | 8.5 | 1 | Data Breach |
| 3948 | CVE-2026-5721 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3949 | Unspecified security flaw | critical | 8.5 | 1 | Data Leak |
| 3950 | Unauthorized access via subcontractor credentials | critical | 8.5 | 1 | Data Breach |
| 3951 | Unsecured cloud storage, inadequate access controls, insufficient monitoring | critical | 8.5 | 1 | Data Exposure |
| 3952 | Third-Party Application Misconfiguration | critical | 8.5 | 1 | Data Breach |
| 3953 | Progress Software | critical | 8.5 | 1 | Data Breach |
| 3954 | CVE-2026-6685 (Unsigned subtraction wrap) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 3955 | CVE-2025-40778 (Logic Flaw in BIND 9’s Resolver - Bailiwick Principle Violation) | critical | 8.5 | 1 | Vulnerability |
| 3956 | Android Accessibility Services | critical | 8.5 | 1 | Malware (Banking Trojan) |
| 3957 | Skimming | critical | 8.5 | 1 | Data Breach |
| 3958 | Unregulated AI Tool Integration | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 3959 | Unpatched Security Gaps | critical | 8.5 | 1 | Security Oversight |
| 3960 | Unsecured VPN | critical | 8.5 | 1 | Data Breach |
| 3961 | CVE-2025-5775 | critical | 8.5 | 1 | Reconnaissance |
| 3962 | Unverified execution of README instructions by AI coding agents | critical | 8.5 | 1 | Semantic Injection |
| 3963 | Poor credential hygiene (hard-coded/exposed credentials) | critical | 8.5 | 1 | Data Breach |
| 3964 | Insufficient data filtering in AI screenshot feature | critical | 8.5 | 1 | Data Breach |
| 3965 | Human error, lack of phishing awareness | critical | 8.5 | 1 | Data Breach |
| 3966 | Insufficient Behavioral Monitoring for Authorized Users | critical | 8.5 | 1 | Data Breach |
| 3967 | Inadequate Technology and Agency Understaffing | critical | 8.5 | 1 | Data Exposure |
| 3968 | hardcoded secrets in code | critical | 8.5 | 1 | data exposure |
| 3969 | OpenClaw WebSocket API Authentication Bypass | critical | 8.5 | 1 | Supply Chain Attack |
| 3970 | Prior data exposures | critical | 8.5 | 1 | Data Breach |
| 3971 | Lack of segmentation between IT and operational systems | critical | 8.5 | 1 | Data Breach |
| 3972 | Third-Party Tracking Tools | critical | 8.5 | 1 | Data Collection |
| 3973 | CVE-pending (Overly Permissive Origin Allowlist, DOM-Based XSS in Arkose Labs CAPTCHA component) | critical | 8.5 | 1 | Zero-Click Vulnerability, Prompt-Injection Attack |
| 3974 | known vulnerabilities in open-source software | critical | 8.5 | 1 | AI-powered cyberattack |
| 3975 | Perimeter security measures | critical | 8.5 | 1 | Data Breach |
| 3976 | Shared contractor accounts, API key exposure, URL convention deduction | critical | 8.5 | 1 | Unauthorized Access |
| 3977 | delayed breach notifications | critical | 8.5 | 1 | ransomware |
| 3978 | CVE-2025-54236 (Improper Input Validation in Adobe Commerce/Magento) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3979 | Abuse of Android’s Accessibility Service | critical | 8.5 | 1 | Malware (Remote Access Trojan - RAT) |
| 3980 | CVE-2025-13834 | critical | 8.5 | 1 | Information Leak |
| 3981 | Known security flaw (back door) in License Express system | critical | 8.5 | 1 | Data Exposure |
| 3982 | Inadequate access controls, lack of data encryption | critical | 8.5 | 1 | Data Breach |
| 3983 | Lack of Multi-Factor Authentication (MFA) for Call-In Access | critical | 8.5 | 1 | Cyberattack |
| 3984 | Unauthorized access due to exposed credentials | critical | 8.5 | 1 | Data Breach |
| 3985 | Weak authentication checks, lack of rate-limiting controls in AI-driven password reset process | critical | 8.5 | 1 | Account Takeover |
| 3986 | Unsecured Microsoft Azure cloud server | critical | 8.5 | 1 | Data exfiltration |
| 3987 | CVE-2024-34102 (CosmicSting) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3988 | Heap buffer overread in Squid’s FTP directory listing parser (CVE pending) | critical | 8.5 | 1 | Memory Disclosure Vulnerability |
| 3989 | Session hijacking | critical | 8.5 | 1 | Malware (RAT) |
| 3990 | CVE-2026-14191 (Heap Overflow) | critical | 8.5 | 1 | Vulnerability |
| 3991 | Exposed SSH services | critical | 8.5 | 1 | Malware |
| 3992 | MOVEit Transfer Server Vulnerability | critical | 8.5 | 1 | Data Breach |
| 3993 | Compromised third-party OAuth integration | critical | 8.5 | 1 | Data Breach |
| 3994 | CVE-2025-3102 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 3995 | Weak Authentication (SSO) | critical | 8.5 | 1 | Data Breach |
| 3996 | CVE-2025-30248 (CWE-427: Uncontrolled Search Path Element) | critical | 8.5 | 1 | DLL Hijacking |
| 3997 | Overly permissive guest user configurations in Salesforce Experience Cloud | critical | 8.5 | 1 | Data Theft |
| 3998 | Lack of Monitoring for Unauthorized Data Exfiltration | critical | 8.5 | 1 | Data Breach |
| 3999 | CVE-2021-24917 (GiveWP) | critical | 8.5 | 1 | ransomware |
| 4000 | First Party Authentication (FPA) v2 Exploitation | critical | 8.5 | 1 | API Vulnerability |
| 4001 | Insufficient network monitoring for suspicious activity | critical | 8.5 | 1 | Data Breach |
| 4002 | Critical CVEs | critical | 8.5 | 1 | Identity Compromise |
| 4003 | CVE-2025-49844 | critical | 8.5 | 1 | Botnet Infection |
| 4004 | lack of access controls and encryption for cloud-hosted databases | critical | 8.5 | 1 | data breach |
| 4005 | Lack of Privacy-Preserving Mechanisms in QML | critical | 8.5 | 1 | Privacy Breach |
| 4006 | CVE-2025-27920 (Directory Traversal), CVE-2025-27921 (Reflected XSS - unused) | critical | 8.5 | 1 | Cyber Espionage |
| 4007 | Juniper PTX router RCE flaw | critical | 8.5 | 1 | APT Activity |
| 4008 | improper access controls / misconfigured storage | critical | 8.5 | 1 | data exposure |
| 4009 | MOVEit Transfer Critical Vulnerability (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 4010 | Hardcoded LDAP credentials | critical | 8.5 | 1 | Data Breach |
| 4011 | Inconsistent Compliance Practices | critical | 8.5 | 1 | Data Privacy Fragmentation |
| 4012 | Unauthorized access to INEC portal and improper data handling protocols | critical | 8.5 | 1 | Data Breach |
| 4013 | Email and SharePoint account access | critical | 8.5 | 1 | Data Breach |
| 4014 | Universal CSS injection in Opera GX's GX Mods feature | critical | 8.5 | 1 | Data Exfiltration |
| 4015 | Accidental source code leak (Claude Code) | critical | 8.5 | 1 | Malware Distribution |
| 4016 | CVE-2025-43509, Plaintext Token Storage, Lack of Token Validation, Weak Keychain Access Controls | critical | 8.5 | 1 | Data Breach, Privilege Escalation, Denial-of-Service (DoS) |
| 4017 | CVE-2025-43300 (Apple OS-level vulnerability) | critical | 8.5 | 1 | Zero-day vulnerability |
| 4018 | Partner system compromise leading to unauthorized API access | critical | 8.5 | 1 | Data Exposure |
| 4019 | CVE-2026-20098 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4020 | Automatic execution of npm preinstall scripts | critical | 8.5 | 1 | Supply Chain Attack |
| 4021 | Network Segmentation Protocols | critical | 8.5 | 1 | Data Breach |
| 4022 | Abuse of Shared Access Signature (SAS) tokens and trusted cloud tools | critical | 8.5 | 1 | Ransomware |
| 4023 | CVE-2025-41244 (VMware Aria Operations and VMware Tools Privilege Escalation) | critical | 8.5 | 1 | Privilege Escalation |
| 4024 | absence of suspicious login alerts | critical | 8.5 | 1 | data breach |
| 4025 | CVE-2026-3888 | critical | 8.5 | 1 | Local Privilege Escalation (LPE) |
| 4026 | Path traversal in Microsoft NLWeb (reading `/etc/passwd`, `.env`) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4027 | Static default password in remote desktop software | critical | 8.5 | 1 | Data Breach |
| 4028 | Third-party authentication (Okta SSO) | critical | 8.5 | 1 | Data Breach |
| 4029 | Legacy email protocols (IMAP/POP3) | critical | 8.5 | 1 | Data Breach |
| 4030 | Verbose error messages exposing OAuth 2.0 bearer tokens | critical | 8.5 | 1 | Phishing, Data Theft, Persistent Access |
| 4031 | CVE-2026-2286 | critical | 8.5 | 1 | Remote Code Execution |
| 4032 | Insufficient internal access controls | critical | 8.5 | 1 | Data Breach |
| 4033 | CVE-2025-67644 (SQL Injection) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4034 | Insufficient validation process for third-party API access | critical | 8.5 | 1 | Data Breach |
| 4035 | Open-source web administration tool (undisclosed) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4036 | unsecured backup databases co-located with active databases | critical | 8.5 | 1 | data breach |
| 4037 | Lack of domain verification during account creation | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 4038 | Unencrypted student data | critical | 8.5 | 1 | Data Breach |
| 4039 | Insecure processing of untrusted input by AI agents in GitHub Actions | critical | 8.5 | 1 | Prompt Injection Attack |
| 4040 | Sleeping Beauty | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4041 | Authentication disabled by default in Flask-based API server | critical | 8.5 | 1 | Misconfiguration |
| 4042 | Setting turned on by Patient Portal vendor | critical | 8.5 | 1 | Data Breach |
| 4043 | ProxyLogon/ProxyShell/ProxyNotShell (Microsoft Exchange) | critical | 8.5 | 1 | Exploit Trends |
| 4044 | CVE-2024-5806 | critical | 8.5 | 1 | Supply Chain Attack, Data Breach, Ransomware |
| 4045 | publicly accessible repositories | critical | 8.5 | 1 | data exposure |
| 4046 | Social Engineering, VoIP Spoofing, Abuse of Legitimate Email Flows (SPF/DKIM Bypass) | critical | 8.5 | 1 | Phishing |
| 4047 | Ray on Vertex AI Insecure Default Access | critical | 8.5 | 1 | Privilege Escalation |
| 4048 | Unsecured digital identities for AI agents | critical | 8.5 | 1 | Data Leakage |
| 4049 | CVE-2026-24512 | critical | 8.5 | 1 | Supply Chain Attack |
| 4050 | Light-touch KYC, Instant SEPA transfers, Gaps in point-in-time checks | critical | 8.5 | 1 | Money Laundering, Fraud, Account Takeover |
| 4051 | Weak Authentication in AI Hiring System (Password '123456') | critical | 8.5 | 1 | Data Exposure |
| 4052 | Unauthorized Plugin | critical | 8.5 | 1 | Data Breach |
| 4053 | Undisclosed zero-day vulnerability in WhatsApp calling feature | critical | 8.5 | 1 | Zero-Day Exploit |
| 4054 | CVE-2026-41241 | critical | 8.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 4055 | compromised user devices (suspected) | critical | 8.5 | 1 | data breach (unverified) |
| 4056 | Microsoft Windows Vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4057 | MOVEit file-transfer vulnerability | critical | 8.5 | 1 | Data Breach |
| 4058 | CVE-2026-5281 (Use-after-free in Dawn GPU abstraction layer) | critical | 8.5 | 1 | Zero-Day Exploitation |
| 4059 | compromised signed access token | critical | 8.5 | 1 | data breach |
| 4060 | n8n flaws | critical | 8.5 | 1 | ransomware |
| 4061 | Unknown vulnerability (zero-day) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4062 | misconfigured AWS S3 bucket (lack of access controls) | critical | 8.5 | 1 | data exposure |
| 4063 | poorly secured AI tools | critical | 8.5 | 1 | ransomware |
| 4064 | CVE-2026-20046 | critical | 8.5 | 1 | Privilege Escalation |
| 4065 | Browser Blob URL APIs | critical | 8.5 | 1 | Phishing |
| 4066 | SWIFT system vulnerability | critical | 8.5 | 1 | ATM cash-out fraud |
| 4067 | Third-party data breaches | critical | 8.5 | 1 | Identity Theft |
| 4068 | Weak security measures in credit card terminals | critical | 8.5 | 1 | Cyber Crime |
| 4069 | Third-party system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4070 | fragmented infrastructure | critical | 8.5 | 1 | ransomware |
| 4071 | CVE-2025-13328 | critical | 8.5 | 1 | Information Leak |
| 4072 | Excessive guest user permissions, misconfigured guest access to public APIs | critical | 8.5 | 1 | Data Theft |
| 4073 | CVE-2025-60727 (Out-of-bounds read condition - CWE-125) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4074 | Misconfigured Remote Access Systems | critical | 8.5 | 1 | Data Breach |
| 4075 | AWS Trusted Advisor Bypass via S3 Bucket Policy Misconfiguration (Deny Rules for `s3:GetBucketPolicyStatus`, `s3:GetBucketPublicAccessBlock`, `s3:GetBucketAcl`) | critical | 8.5 | 1 | Misconfiguration |
| 4076 | Supply chain vulnerability in SaaS integrations | critical | 8.5 | 1 | Extortion-as-a-Service (EaaS) |
| 4077 | Software Vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4078 | unpatched_systems | critical | 8.5 | 1 | data_breach |
| 4079 | Notepad++ WinGUp Update Verification Flaw | critical | 8.5 | 1 | Supply Chain Attack |
| 4080 | improper access controls / lack of authentication for cloud storage | critical | 8.5 | 1 | data breach |
| 4081 | Inadequate data security controls / unauthorized access by insider | critical | 8.5 | 1 | Data Breach |
| 4082 | SIM-swapping | critical | 8.5 | 1 | SIM-swapping |
| 4083 | Missing row-level security (RLS), role-based access controls, and logic flaws in authentication | critical | 8.5 | 1 | Data Breach |
| 4084 | Social Engineering (Fake VPN Software), Lack of User Awareness | critical | 8.5 | 1 | Credential Theft |
| 4085 | Mishandled private keys in AI-generated JavaScript | critical | 8.5 | 1 | Data Breach |
| 4086 | mDNS Misconfiguration | critical | 8.5 | 1 | Misconfiguration |
| 4087 | CVE-Pending (CamoLeak: Copilot Chat's parsing of invisible markdown + Camo image-proxy exfiltration) | critical | 8.5 | 1 | Data Exfiltration |
| 4088 | CVE-2025-4632 (Improper Pathname Limitation Leading to Arbitrary File Write) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4089 | Publicly accessible database without proper security measures | critical | 8.5 | 1 | Data Exposure |
| 4090 | Unverified JWT payload | critical | 8.5 | 1 | Vulnerability Exploit |
| 4091 | MongoDB database vulnerability | critical | 8.5 | 1 | Data Breach |
| 4092 | User Privacy | critical | 8.5 | 1 | Privacy Breach |
| 4093 | Parser differential between JavaScript and libc (getaddrinfo()) | critical | 8.5 | 1 | Sandbox Bypass |
| 4094 | CVE-2026-54433 | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 4095 | Social Engineering, Lack of User Awareness | critical | 8.5 | 1 | Phishing |
| 4096 | Unsecured Internet-Connected Database | critical | 8.5 | 1 | Data Exposure |
| 4097 | improper data retention by third-party vendor | critical | 8.5 | 1 | data breach |
| 4098 | Lack of organizational safeguards for AI chatbot usage | critical | 8.5 | 1 | Data Breach |
| 4099 | FG-IR-26-060 (CWE-288: Authentication Bypass Using an Alternate Path or Channel) | critical | 8.5 | 1 | Authentication Bypass |
| 4100 | Node.js workflows | critical | 8.5 | 1 | Supply Chain Attack |
| 4101 | Windows Shell Spoofing (CVE-2026-32202) | critical | 8.5 | 1 | Data Breach |
| 4102 | Incorrect privacy settings on public maps | critical | 8.5 | 1 | Data Exposure |
| 4103 | Windows Script Host | critical | 8.5 | 1 | Malware Campaign |
| 4104 | Insufficient Third-Party Vendor Security | critical | 8.5 | 1 | Data Breach |
| 4105 | Weak or Compromised Employee Credentials | critical | 8.5 | 1 | Data Breach |
| 4106 | Third-party secure file transfer tool vulnerability | critical | 8.5 | 1 | Data Breach |
| 4107 | No lockout after repeated failed login attempts, weak encryption algorithms, unlawful data collection and storage, retention of outdated records | critical | 8.5 | 1 | Data Breach |
| 4108 | Lack of separation between instructions and data in large language models | critical | 8.5 | 1 | AI Vulnerability Misunderstanding |
| 4109 | Salesforce Environments | critical | 8.5 | 1 | Data Breach |
| 4110 | Lack of Privacy Controls | critical | 8.5 | 1 | Surveillance |
| 4111 | Lack of access controls and monitoring | critical | 8.5 | 1 | Unauthorized Data Access |
| 4112 | Exposed Magicbell API Keys and Secrets | critical | 8.5 | 1 | Data Exposure |
| 4113 | CWE-798: Hard-coded Credentials | critical | 8.5 | 1 | Data Exposure |
| 4114 | CVE-2026-24228 (Deserialization of Untrusted Data) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4115 | Insecure facial recognition databases, Lack of encryption, Third-party vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4116 | CVE-2025-14756 | critical | 8.5 | 1 | Command Injection |
| 4117 | Default Data Retention Policies in LLMs (e.g., OpenAI’s 30-day deletion lag) | critical | 8.5 | 1 | Data Leakage |
| 4118 | Improper key management, lack of automated key rotation | critical | 8.5 | 1 | Data Leak |
| 4119 | Unencrypted data stored in an internet-accessible environment | critical | 8.5 | 1 | Data Breach |
| 4120 | Lack of authentication and access controls in Firebase instances | critical | 8.5 | 1 | Data Breach |
| 4121 | Insecure data transmission by browser extensions | critical | 8.5 | 1 | Data Leakage |
| 4122 | Default Network Access Settings (Pro/Max accounts) | critical | 8.5 | 1 | Data Exfiltration |
| 4123 | Unencrypted data at rest in shared app containers, macOS sandbox bypass (CVE-2026-28910) | critical | 8.5 | 1 | Data Exposure |
| 4124 | CVE-2025-68428 | critical | 8.5 | 1 | Local File Inclusion / Path Traversal |
| 4125 | Bing SSRF bypass | critical | 8.5 | 1 | Data Exfiltration |
| 4126 | Online customer service system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4127 | Squidbleed (CVE-2026-47729) | critical | 8.5 | 1 | Memory Leak Vulnerability |
| 4128 | CVE-2026-2836 | critical | 8.5 | 1 | HTTP Request Smuggling |
| 4129 | Improperly secured file on public-facing website | critical | 8.5 | 1 | Data Breach |
| 4130 | Zero-Click Prompt Injection in ChatGPT's Deep Research Tool | critical | 8.5 | 1 | Data Breach |
| 4131 | Misconfigured AWS Storage Bucket | critical | 8.5 | 1 | Data Exposure |
| 4132 | Default public settings in low-code/AI tools | critical | 8.5 | 1 | Data Exposure |
| 4133 | Trusted domain chaining, search engine trust exploitation | critical | 8.5 | 1 | Phishing |
| 4134 | MOVEit Transfer application vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4135 | Integer Overflow | critical | 8.5 | 1 | Privilege Escalation |
| 4136 | Weak Password ('123456') | critical | 8.5 | 1 | Data Breach |
| 4137 | Account Compromise | critical | 8.5 | 1 | Data Breach |
| 4138 | Misconfigured Salesforce instances | critical | 8.5 | 1 | Data Breach |
| 4139 | Human vulnerability (bribery of overseas support agents) | critical | 8.5 | 1 | Data Breach |
| 4140 | Opportunistic scanning for sensitive file extensions (e.g., `.openclaw`) | critical | 8.5 | 1 | Infostealer Attack |
| 4141 | Vulnerable API endpoint | critical | 8.5 | 1 | Data Breach |
| 4142 | Android and Linux Kernel vulnerabilities | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4143 | Insufficient access controls and monitoring for employee data handling | critical | 8.5 | 1 | Unauthorized Data Transfer |
| 4144 | Legitimate third-party cloud systems bypass | critical | 8.5 | 1 | Data Breach |
| 4145 | CVE-2026-42824 (Parameter-to-Prompt Injection, HTML Injection Race Condition, SSRF via Bing) | critical | 8.5 | 1 | Data Exfiltration |
| 4146 | CVE-2026-6687 (exFAT label-length stack overflow) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4147 | Unauthenticated access flaw in API endpoint `/api/now/related_list_edit/create` with `requires_authentication=false` | critical | 8.5 | 1 | Unauthorized Data Access |
| 4148 | E-commerce Website | critical | 8.5 | 1 | Data Breach |
| 4149 | Over-Permissive Third-Party Access | critical | 8.5 | 1 | Data Breach |
| 4150 | Customer Contract Search Tool | critical | 8.5 | 1 | Data Breach |
| 4151 | Outdated TEE image reuse | critical | 8.5 | 1 | Zero-day vulnerability |
| 4152 | CVE-2026-42253 | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4153 | session tokens | critical | 8.5 | 1 | phishing |
| 4154 | ThemeREX Addons (WordPress) | critical | 8.5 | 1 | Webshell Attack |
| 4155 | Human error (tricked employees into handing over login credentials for internal Salesforce software) | critical | 8.5 | 1 | Data Breach |
| 4156 | Unsecured LLM infrastructure | critical | 8.5 | 1 | Security Vulnerability |
| 4157 | Inadequate protection of sensitive data | critical | 8.5 | 1 | Data Breach |
| 4158 | unauthorized data upload to external platform | critical | 8.5 | 1 | data breach |
| 4159 | Accellion File Transfer Appliance (FTA) software vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4160 | Back-end system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4161 | Unencrypted and non-password-protected database | critical | 8.5 | 1 | Data Leak |
| 4162 | Unsecured storage of sensitive data | critical | 8.5 | 1 | Data Breach |
| 4163 | Side API compromise | critical | 8.5 | 1 | Supply Chain Attack |
| 4164 | CVE-2026-27739 | critical | 8.5 | 1 | SSRF (Server-Side Request Forgery) |
| 4165 | Social Engineering, Native Messaging Manifest Bypass | critical | 8.5 | 1 | Phishing, Backdoor Deployment, Malicious Browser Extension |
| 4166 | Single extracted key bypassing authentication | critical | 8.5 | 1 | Unauthorized Access |
| 4167 | Over-Permissive Access to CRM/Donor Data | critical | 8.5 | 1 | Data Breach |
| 4168 | Inadequate internal monitoring and access controls | critical | 8.5 | 1 | Data Breach |
| 4169 | sp_invoke_external_rest_endpoint (arbitrary HTTP requests) | critical | 8.5 | 1 | Data Exfiltration |
| 4170 | CVE-2021-47961 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4171 | Weak Internal Access Controls | critical | 8.5 | 1 | Data Breach |
| 4172 | CVE-2025-54106 (Windows RRAS RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4173 | CVE-2026-2275 | critical | 8.5 | 1 | Remote Code Execution |
| 4174 | Unauthorized code in third-party vendor's application | critical | 8.5 | 1 | Data Breach |
| 4175 | CVE-2026-21519 (Type Confusion - CWE-843) | critical | 8.5 | 1 | Elevation of Privilege |
| 4176 | Social Engineering, Lack of Multi-Factor Authentication (MFA) awareness | critical | 8.5 | 1 | Phishing, Credential Harvesting |
| 4177 | CVE-2025-12057 (WavePlayer) | critical | 8.5 | 1 | Exploitation Campaign |
| 4178 | CVE-2026-XXXXX (Local WebSocket Gateway Authentication Bypass) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4179 | ProxyNotShell (Microsoft Exchange Server vulnerability) | critical | 8.5 | 1 | Cyber Espionage |
| 4180 | CVE-2026-6682 (FAT32 integer overflow) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4181 | Expired domain takeover, lack of ongoing security validation for Office add-ins | critical | 8.5 | 1 | Phishing, Credential Theft, Data Exfiltration |
| 4182 | High-severity vulnerability in ADSelfService Plus software | critical | 8.5 | 1 | Vulnerability Exploit |
| 4183 | cloud application misconfigurations | critical | 8.5 | 1 | phishing |
| 4184 | unsecured Azure Blob Storage | critical | 8.5 | 1 | data breach |
| 4185 | Excessive data access privileges | critical | 8.5 | 1 | Data Breach |
| 4186 | CVE-2026-27970 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4187 | CVE-2026-25903 | critical | 8.5 | 1 | Authorization Bypass |
| 4188 | MOVEit file transfer platform | critical | 8.5 | 1 | Data Breach |
| 4189 | CVE-2025-7399 (Unauthenticated RCE in Samsung MagicINFO 9 Server) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4190 | CVE-2026-46331 (pedit COW) | critical | 8.5 | 1 | Privilege Escalation |
| 4191 | Weak Authentication in AI Platforms | critical | 8.5 | 1 | Data Leakage |
| 4192 | Legacy accounts | critical | 8.5 | 1 | Phishing |
| 4193 | Network-connected systems | critical | 8.5 | 1 | Business Email Compromise (BEC) |
| 4194 | Ineffective Security Configurations | critical | 8.5 | 1 | Data Breach |
| 4195 | Stolen Personal Data from External Sources | critical | 8.5 | 1 | Data Breach |
| 4196 | Exposed Elasticsearch Database without Password | critical | 8.5 | 1 | Data Breach |
| 4197 | misconfigured third-party integrations | critical | 8.5 | 1 | ransomware |
| 4198 | hardcoded credentials in source code | critical | 8.5 | 1 | data breach |
| 4199 | MOVEit® Transfer application | critical | 8.5 | 1 | Data Breach |
| 4200 | Support Credentials | critical | 8.5 | 1 | Data Breach |
| 4201 | Valid Log-in Credentials | critical | 8.5 | 1 | Data Breach |
| 4202 | Fragmented policies for data in motion | critical | 8.5 | 1 | Data Governance Blind Spot |
| 4203 | Disabled Workspace Trust (Cursor Editor) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4204 | CWE-352: Cross-Site Request Forgery (CSRF) (via API manipulation) | critical | 8.5 | 1 | Data Breach |
| 4205 | Oracle E-Business Suite (versions 12.2.3 to 12.2.14) | critical | 8.5 | 1 | Data Breach |
| 4206 | CVE-2026-11311 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4207 | Lack of Access Controls / Insider Threat | critical | 8.5 | 1 | Data Breach |
| 4208 | Remote-viewing software | critical | 8.5 | 1 | Data Breach |
| 4209 | Customer inadvertent disclosure of credentials | critical | 8.5 | 1 | Data Breach |
| 4210 | CVE-2026-45585 (Windows BitLocker Zero-Day in WinRE) | critical | 8.5 | 1 | Security Feature Bypass |
| 4211 | TrueConf Client Flaw | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4212 | Improper data handling during system restoration | critical | 8.5 | 1 | Data Breach |
| 4213 | Misconfigured integrations, exposed credentials, authentication tokens | critical | 8.5 | 1 | Data Breach, Extortion |
| 4214 | Lack of AI Governance Frameworks | critical | 8.5 | 1 | Data Leakage |
| 4215 | CVE-2025-7775 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4216 | vBulletin security hole | critical | 8.5 | 1 | Data Breach |
| 4217 | CVE-2025-31277 | critical | 8.5 | 1 | Exploit Kit |
| 4218 | Unsecured Amazon S3 bucket with backend bug allowing unauthorized access to file directory | critical | 8.5 | 1 | Data Exposure |
| 4219 | CVE-2025-20333 & CVE-2025-20363 (Cisco ASA VPN) | critical | 8.5 | 1 | Ransomware |
| 4220 | Weak Access Controls (Absent MFA, Insufficient Lockout Policies) in SonicWall SSLVPN | critical | 8.5 | 1 | Ransomware |
| 4221 | Social Engineering (Tax-Season Lures), Spoofed Login Pages, Trusted RMM Tools Abuse | critical | 8.5 | 1 | Phishing, Credential Harvesting, Malware Deployment |
| 4222 | Unpatched vulnerabilities in end-of-life PHP versions (e.g., PHP 7.4) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4223 | Unlimited Coupon Redemptions (CosMc’s App) | critical | 8.5 | 1 | Data Exposure |
| 4224 | Human Error (Credential Theft via Smishing) | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 4225 | Reused credentials from older data breaches | critical | 8.5 | 1 | Data Breach |
| 4226 | CVE-2026-3063 (Improper implementation in DevTools) | critical | 8.5 | 1 | Vulnerability Patch |
| 4227 | Click2Gov Payment System | critical | 8.5 | 1 | Data Breach |
| 4228 | Inadequate Data Redaction | critical | 8.5 | 1 | Data Breach |
| 4229 | User Email Accounts | critical | 8.5 | 1 | Data Breach |
| 4230 | improper access controls / misconfigured portal | critical | 8.5 | 1 | data breach |
| 4231 | Transaction Front-running | critical | 8.5 | 1 | Security Breach |
| 4232 | CVE-2026-34621 (Prototype pollution vulnerability) | critical | 8.5 | 1 | Zero-day Exploitation |
| 4233 | Weak encryption configurations (e.g., BitLocker), cached authentication tokens, lack of hardware-rooted security | critical | 8.5 | 1 | Device Theft / Data Breach |
| 4234 | CVE-2026-25921 (CWE-345: Insufficient Verification of Data Authenticity) | critical | 8.5 | 1 | Supply-Chain Attack |
| 4235 | Stolen authentication tokens | critical | 8.5 | 1 | Data Breach |
| 4236 | CVE-2026-21385 | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 4237 | Timing Attack via Rendering Pipeline | critical | 8.5 | 1 | Data Theft |
| 4238 | Sensor false data injection | critical | 8.5 | 1 | Firmware-level attack |
| 4239 | CVE-2025-4123 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4240 | Expired email domain allowing credential reset | critical | 8.5 | 1 | Supply Chain Attack |
| 4241 | Weak authentication measures in Fast Pair protocol | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4242 | Reused passwords from data leaks | critical | 8.5 | 1 | Fraud/Scam |
| 4243 | CVE-2014-6271 (Shellshock) | critical | 8.5 | 1 | Exploit Trends |
| 4244 | Human Error (Employee Mistake) | critical | 8.5 | 1 | Data Breach |
| 4245 | Theft of banking credentials and sensitive financial data | critical | 8.5 | 1 | Malware |
| 4246 | Insufficient MFA | critical | 8.5 | 1 | Phishing |
| 4247 | CVE-2023-6895 | critical | 8.5 | 1 | Espionage |
| 4248 | Over-permissioned OAuth scopes | critical | 8.5 | 1 | Data Breach |
| 4249 | Login and Sign-up Service | critical | 8.5 | 1 | Data Breach |
| 4250 | Computer Virus | critical | 8.5 | 1 | Data Breach |
| 4251 | Improper data handling via third-party tracking tools (e.g., Google Analytics, Meta Pixel) | critical | 8.5 | 1 | Data Privacy Breach |
| 4252 | Weak KYC processes, Fast account opening, SEPA transfer infrastructure | critical | 8.5 | 1 | Fraud, Money Laundering |
| 4253 | Lack of robust identity verification during hiring process | critical | 8.5 | 1 | Data Breach (Insider Threat / Identity Misuse) |
| 4254 | Absence of defensible deletion policies | critical | 8.5 | 1 | Data Breach |
| 4255 | MOVEit Transfer Zero-Day (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 4256 | Lack of AI-Specific Security Controls | critical | 8.5 | 1 | Supply Chain Attack |
| 4257 | Lack of Input Sanitization for Hidden Commands | critical | 8.5 | 1 | Data Breach |
| 4258 | human trust in AI-generated content | critical | 8.5 | 1 | fraud |
| 4259 | Now-patched vulnerability in Instructure’s systems | critical | 8.5 | 1 | Data Breach |
| 4260 | Access control failures | critical | 8.5 | 1 | Data Breach |
| 4261 | CVE-2024-13496 | critical | 8.5 | 1 | SQL Injection |
| 4262 | FortiGate Misconfiguration | critical | 8.5 | 1 | Zero-day Exploitation |
| 4263 | Fingerprinting | critical | 8.5 | 1 | Phishing |
| 4264 | Predictable passwords (e.g., team names with numbers or capital letters) | critical | 8.5 | 1 | Data Breach |
| 4265 | CVE-2026-1602 | critical | 8.5 | 1 | Authentication Bypass |
| 4266 | CVE-2026-1340 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4267 | CVE-2025-54135 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4268 | Inconsistent DLP Policy Application | critical | 8.5 | 1 | Data Breach |
| 4269 | Stolen web cookies (session IDs, personal data) | critical | 8.5 | 1 | Data Exposure |
| 4270 | Argument injection in MicrositeURL and CloudPages | critical | 8.5 | 1 | Data Breach |
| 4271 | Insufficient Mass Email Controls | critical | 8.5 | 1 | Data Breach |
| 4272 | High-severity flaws | critical | 8.5 | 1 | Zero-day exploitation |
| 4273 | Two-Factor Authentication (2FA) Bypass | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 4274 | Access Control Weakness | critical | 8.5 | 1 | Data Exposure |
| 4275 | Unauthorized internal access to law enforcement databases | critical | 8.5 | 1 | Data Breach |
| 4276 | Open WebUI flaws | critical | 8.5 | 1 | ransomware |
| 4277 | misconfigured cloud environments | critical | 8.5 | 1 | ransomware |
| 4278 | Software misconfiguration exposing files to the internet | critical | 8.5 | 1 | Data Breach |
| 4279 | Shadow AI usage | critical | 8.5 | 1 | AI-related identity breach |
| 4280 | improper decommissioning of legacy cloud storage | critical | 8.5 | 1 | data breach |
| 4281 | CVE-2026-XXXX (not explicitly mentioned, but implied as a critical vulnerability) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4282 | CVE-2025-32711 (CVSS 9.3) | critical | 8.5 | 1 | AI Command Injection |
| 4283 | Security hole in MOVEit Transfer software | critical | 8.5 | 1 | Ransomware |
| 4284 | Illicit tactics to bypass digital rights management (DRM) | critical | 8.5 | 1 | Data Breach |
| 4285 | Inadequate security on WordPress-hosted infrastructure | critical | 8.5 | 1 | Data Breach |
| 4286 | Ease of onboarding and business-grade tools in fintech platforms, hybrid account functionality | critical | 8.5 | 1 | Financial Fraud, Money Laundering, Phishing |
| 4287 | CVE-2025-47813 (CWE-209) | critical | 8.5 | 1 | Information Disclosure |
| 4288 | Internal Authentication API bug | critical | 8.5 | 1 | Authentication Vulnerability |
| 4289 | CVE-2025-54910 (Office RCE) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4290 | CVE-2025-12807 (SQL Injection) | critical | 8.5 | 1 | Denial-of-Service |
| 4291 | Software Misconfiguration in Online Grant System | critical | 8.5 | 1 | Data Breach |
| 4292 | Weak encryption | critical | 8.5 | 1 | Data Breach |
| 4293 | Hard-coded API Key | critical | 8.5 | 1 | Data Breach |
| 4294 | Time-of-Check to Time-of-Use vulnerability in Alpitronic HYC50 EV charger | critical | 8.5 | 1 | Zero-Day Vulnerabilities |
| 4295 | Over-collection of sensitive PII (e.g., full ID scans vs. minimal verification) | critical | 8.5 | 1 | Data Breach Risk |
| 4296 | Outdated PHP versions (e.g., PHP 7.4 and earlier) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4297 | CVE-not-yet-assigned (as of description) – RCE via `new Function()` in `expr-eval` < 2.0.2 | critical | 8.5 | 1 | Vulnerability |
| 4298 | Lack of default sandboxing, Ineffective filtering of untrusted content, Plaintext storage of API keys and session tokens, Reliance on language models for critical security decisions, Execution of tool calls without explicit user approval | critical | 8.5 | 1 | Malware Distribution, Data Exfiltration, Prompt Injection, Backdoor Installation |
| 4299 | Legitimate Telegram API authentication mechanisms | critical | 8.5 | 1 | Phishing |
| 4300 | CVE-2025-7776 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4301 | Impersonation of legitimate Go module (*golang.org/x/crypto*) | critical | 8.5 | 1 | Supply-Chain Attack |
| 4302 | Employee deception, potential weak passwords or third-party vulnerabilities (Okta identity management service) | critical | 8.5 | 1 | Data Breach |
| 4303 | Lack of regulatory compliance and proper data handling procedures | critical | 8.5 | 1 | Data Breach |
| 4304 | Unmonitored Data Exfiltration via AI Prompts | critical | 8.5 | 1 | Data Leakage |
| 4305 | npm run dev execution | critical | 8.5 | 1 | Supply Chain Attack |
| 4306 | CWE-319: Cleartext Transmission of Sensitive Information (weak AES encryption) | critical | 8.5 | 1 | Data Breach |
| 4307 | faiblesse des mots de passe utilisateurs | critical | 8.5 | 1 | cyberattaque |
| 4308 | Multi-factor Authentication (MFA) Bypass, Credential Theft | critical | 8.5 | 1 | Vishing (Voice Phishing) |
| 4309 | Security flaw | critical | 8.5 | 1 | Data Breach |
| 4310 | CVE-2026-20817 (CWE-280: Improper Handling of Insufficient Permissions) | critical | 8.5 | 1 | Privilege Escalation |
| 4311 | Weak identity verification | critical | 8.5 | 1 | Identity Theft |
| 4312 | Third-Party Integrations | critical | 8.5 | 1 | Credential Exposure |
| 4313 | Abuse of trusted cloud platforms (GitHub Pages, SheetBest), lack of multi-factor authentication, social engineering | critical | 8.5 | 1 | Phishing |
| 4314 | Legitimate remote access tool abuse (ScreenConnect) | critical | 8.5 | 1 | Malware Campaign |
| 4315 | No Technical Vulnerability (Human Factor) | critical | 8.5 | 1 | Trade Secret Theft |
| 4316 | Employee interaction with fraudulent link | critical | 8.5 | 1 | Data Breach |
| 4317 | Insider access, malware backdoor | critical | 8.5 | 1 | Cyber-enabled drug trafficking |
| 4318 | Symbolic link following (CWE-61), UI misrepresentation (CWE-451) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4319 | Human Error (Tricked Call Center Worker) | critical | 8.5 | 1 | Data Breach |
| 4320 | CVE-2025-59367 (Authentication Bypass in DSL-series routers) | critical | 8.5 | 1 | Vulnerability |
| 4321 | Mistake that exposed personal and financial information | critical | 8.5 | 1 | Data Breach |
| 4322 | Insufficient input sanitization and double-parsing bug in 'Dispatch Search' feature | critical | 8.5 | 1 | Data Breach |
| 4323 | gaps in business associate oversight | critical | 8.5 | 1 | ransomware |
| 4324 | System misconfiguration reactivating disabled feature | critical | 8.5 | 1 | Data Breach |
| 4325 | AVrecon Malware | critical | 8.5 | 1 | Zero-day Exploitation |
| 4326 | Lack of encryption and intrusion detection systems | critical | 8.5 | 1 | Data Breach |
| 4327 | Unauthorized Access to Customer Account Information | critical | 8.5 | 1 | Data Exposure |
| 4328 | Limited-access function in internal support portal (proxy access to customer accounts) | critical | 8.5 | 1 | Cyberattack |
| 4329 | Lack of password encryption | critical | 8.5 | 1 | Unauthorized Access |
| 4330 | CVE-2026-1237 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4331 | unpatched vulnerabilities in enterprise software | critical | 8.5 | 1 | ransomware |
| 4332 | PTC Windchill and FlexPLM flaw | critical | 8.5 | 1 | data_breach |
| 4333 | CVE-2025-20352 (SNMP RCE in Cisco IOS/IOS XE) | critical | 8.5 | 1 | unauthorized access |
| 4334 | AcroForms, FlateDecode (PDF features), abuse of legitimate cloud services (Vercel Blob storage) | critical | 8.5 | 1 | Phishing |
| 4335 | CVE-2026-40361 (Use-after-free bug in Outlook’s email rendering engine) | critical | 8.5 | 1 | Zero-Click Remote Code Execution (RCE) |
| 4336 | CVE-2024-40766 (SonicWall Improper Access Control) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4337 | Abuse of High-Reputation Domains (sites.google.com, docs.google.com) | critical | 8.5 | 1 | Phishing |
| 4338 | AMPScript/SSJS template injection | critical | 8.5 | 1 | Data Breach |
| 4339 | CVE-2026-27022 (Query Injection) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4340 | Social engineering (impersonation of Signal Support) | critical | 8.5 | 1 | Phishing |
| 4341 | CVE-2025-53770 (Microsoft SharePoint 'ToolShell') | critical | 8.5 | 1 | Ransomware |
| 4342 | Improper CSV processing allowing unauthenticated file reads | critical | 8.5 | 1 | SQL Injection |
| 4343 | Unauthenticated Access to TRT Tool (Employee Data) | critical | 8.5 | 1 | Data Exposure |
| 4344 | CVE-2025-55177 (WhatsApp Zero-Click) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4345 | Unsecured Amazon cloud storage without password protection | critical | 8.5 | 1 | Data Breach |
| 4346 | CVE-2026-33829 | critical | 8.5 | 1 | Information Disclosure |
| 4347 | Unprotected GPRS gateway | critical | 8.5 | 1 | Data Breach |
| 4348 | Disabled Workspace Trust in Cursor (VS Code fork) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4349 | Failure to Enforce 'Minimum Necessary' HIPAA Requirements | critical | 8.5 | 1 | Data Breach |
| 4350 | abuse of LaunchAgents for persistence | critical | 8.5 | 1 | malware |
| 4351 | WebSocket auth bypass (CVE-2025-52882, CVSS: 8.8) | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4352 | Improper handling of ACME HTTP-01 challenge paths in Cloudflare WAF | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 4353 | Lack of dedicated cybersecurity personnel | critical | 8.5 | 1 | Data exfiltration |
| 4354 | Misuse of legitimate access credentials post-employment | critical | 8.5 | 1 | Data Breach |
| 4355 | CVE-2026-0958 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4356 | Abandoned email domains of financial administrators | critical | 8.5 | 1 | Data Breach |
| 4357 | Undisclosed flaws (Smallstep step-ca) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4358 | Improper Authentication (MongoDB instance left unsecured) | critical | 8.5 | 1 | Data Leak |
| 4359 | Unpatched VPN endpoint | critical | 8.5 | 1 | Ransomware Attack |
| 4360 | Incremental features and customizations accumulating risk, lack of proper access controls | critical | 8.5 | 1 | Misconfiguration |
| 4361 | Unauthorized access to Salesforce | critical | 8.5 | 1 | Data Breach |
| 4362 | Static XOR encryption key | critical | 8.5 | 1 | Data Breach |
| 4363 | Unauthorized access to business email account | critical | 8.5 | 1 | Data Breach |
| 4364 | Outdated or poorly secured API interfaces | critical | 8.5 | 1 | Data Breach |
| 4365 | WinRAR vulnerability | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4366 | WP File Manager (WordPress) | critical | 8.5 | 1 | Webshell Attack |
| 4367 | Weak Authentication Mechanisms (e.g., no 2FA) | critical | 8.5 | 1 | Privacy Violation |
| 4368 | CVE-2025-37899 (Use-After-Free in ksmbd SMB2 LOGOFF handler) | critical | 8.5 | 1 | Zero-Day Vulnerability |
| 4369 | Human error, lack of centralized IT control, decentralized IT departments | critical | 8.5 | 1 | Data Breach |
| 4370 | VPN appliances | critical | 8.5 | 1 | Credential Theft |
| 4371 | Simple File List (WordPress) | critical | 8.5 | 1 | Webshell Attack |
| 4372 | Vulnerability in e-commerce portal | critical | 8.5 | 1 | Data Breach |
| 4373 | Salesforce environment access | critical | 8.5 | 1 | Data Breach |
| 4374 | Credentials exploitation | critical | 8.5 | 1 | Data Breach |
| 4375 | Poor credential management | critical | 8.5 | 1 | Unauthorized Access |
| 4376 | Social Engineering (ClickFix technique) | critical | 8.5 | 1 | Malware Campaign |
| 4377 | Phase-locked loops (PLLs) compromise | critical | 8.5 | 1 | Firmware-level attack |
| 4378 | Progress Software's MOVEit File Transfer solution | critical | 8.5 | 1 | Data Breach |
| 4379 | Inadequate audit logging | critical | 8.5 | 1 | Data Breach |
| 4380 | Exploitation of accessibility permissions, fake overlays | critical | 8.5 | 1 | Trojan |
| 4381 | Microsoft’s legitimate device code authentication flow | critical | 8.5 | 1 | Phishing |
| 4382 | CVE pending (related to 'node-forge' cryptographic signature verification flaw) | critical | 8.5 | 1 | Vulnerability |
| 4383 | Publicly Available Code Repository | critical | 8.5 | 1 | Data Breach |
| 4384 | Lack of Data Encryption in University Advancement Database | critical | 8.5 | 1 | Data Breach |
| 4385 | Unapplied security patches to its software | critical | 8.5 | 1 | Data Breach |
| 4386 | One-click IP leak via MTProxy | critical | 8.5 | 1 | Data Leak |
| 4387 | CWE-862 (Missing Authorization) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4388 | Social engineering, lack of multi-factor authentication | critical | 8.5 | 1 | Phishing Campaign |
| 4389 | Improper Privilege Management (CWE-269) | critical | 8.5 | 1 | Privilege Escalation |
| 4390 | Absence of web application firewall (WAF) | critical | 8.5 | 1 | Data Security Audit |
| 4391 | Plaintext Password Transmission (Design Hub) | critical | 8.5 | 1 | Data Exposure |
| 4392 | CVE-2025-33206 (Improper Input Validation - CWE-78) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4393 | Publicly accessible profile information | critical | 8.5 | 1 | Data Scraping |
| 4394 | Website Setup Error | critical | 8.5 | 1 | Credential Leak |
| 4395 | Static code scanners' inability to detect runtime malicious behavior | critical | 8.5 | 1 | Supply-Chain Compromise |
| 4396 | Unauthorized data collection via embedded tracking tool | critical | 8.5 | 1 | Data Harvesting |
| 4397 | Vulnerability in UpdraftPlus plugin | critical | 8.5 | 1 | Supply Chain Attack |
| 4398 | Improper Access Controls (Publicly Accessible Folder) | critical | 8.5 | 1 | Data Breach |
| 4399 | Security misconfiguration in a non-production environment | critical | 8.5 | 1 | Data Leakage |
| 4400 | Phishing-susceptible MFA methods | critical | 8.5 | 1 | Data Breach |
| 4401 | CVE-2026-42530 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4402 | Inadequate AI governance and security oversight | critical | 8.5 | 1 | Data Breach |
| 4403 | Lack of AI Agent Management | critical | 8.5 | 1 | Data Breach |
| 4404 | DLL Sideloading via YY platform's updat.exe | critical | 8.5 | 1 | Malware Campaign |
| 4405 | Social Engineering, Fake Authentication Screens | critical | 8.5 | 1 | Phishing |
| 4406 | Unpatched flaw (addressed in July 2023 update, additional vulnerabilities patched in October 2023) | critical | 8.5 | 1 | Data Breach |
| 4407 | Internal system flaw exposing plain text passwords | critical | 8.5 | 1 | Data Breach |
| 4408 | Improper Access Controls, Undisclosed System Features | critical | 8.5 | 1 | Unauthorized Data Access |
| 4409 | Vulnerable pull request target pattern in GitHub Actions, malicious optionalDependencies in package.json, prepare lifecycle hook execution | critical | 8.5 | 1 | Supply Chain Attack |
| 4410 | Shared Access Protocols with Weak Authentication | critical | 8.5 | 1 | Data Breach |
| 4411 | VMware Vulnerabilities | critical | 8.5 | 1 | Ransomware |
| 4412 | Human error, limited cybersecurity resources | critical | 8.5 | 1 | Data Breach |
| 4413 | Security vulnerability in pre-order process | critical | 8.5 | 1 | Data Breach |
| 4414 | third-party vendor (Salesforce) security flaw | critical | 8.5 | 1 | data breach |
| 4415 | Human Error (Improper Handling of Public Records Request) | critical | 8.5 | 1 | Data Breach (Unintentional Disclosure) |
| 4416 | Morris Worm (1988 - Buffer Overflow in `fingerd`/`sendmail`) | critical | 8.5 | 1 | Memory Corruption |
| 4417 | weak access controls at third-party vendor | critical | 8.5 | 1 | data breach |
| 4418 | Unpatched Smart Contract Bugs | critical | 8.5 | 1 | Privacy Violation |
| 4419 | Incorrect System Settings | critical | 8.5 | 1 | Data Leak |
| 4420 | CVE-2014-0160 (Heartbleed - Out-of-Bounds Read in OpenSSL) | critical | 8.5 | 1 | Memory Corruption |
| 4421 | Publicly accessible production chatbots | critical | 8.5 | 1 | LLMjacking |
| 4422 | Endpoint Detection and Response (EDR) Services | critical | 8.5 | 1 | Ransomware Attack |
| 4423 | lack of monitoring | critical | 8.5 | 1 | data breach |
| 4424 | lack of security risk analysis | critical | 8.5 | 1 | ransomware |
| 4425 | lack of phishing-resistant authentication | critical | 8.5 | 1 | phishing |
| 4426 | Remote Code Execution Vulnerability in DS-2105 Pro DVRs | critical | 8.5 | 1 | Botnet |
| 4427 | CVE-2026-48710 (BadHost) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4428 | Exploitation of health information exchange systems, fake NPI numbers, and shell companies | critical | 8.5 | 1 | Data Breach |
| 4429 | CVE-2025-43529 | critical | 8.5 | 1 | Exploit Kit |
| 4430 | untested incident response plans | critical | 8.5 | 1 | ransomware |
| 4431 | Human Error (Employee fell for phishing scam) | critical | 8.5 | 1 | Data Breach |
| 4432 | Insufficient access controls and monitoring | critical | 8.5 | 1 | Insider Threat |
| 4433 | Memory address mapping manipulation via DDR4 interposer | critical | 8.5 | 1 | Supply Chain Attack |
| 4434 | Authentication bypass in Passwordstate Emergency Access (CVE pending) | critical | 8.5 | 1 | Authentication Bypass Vulnerability |
| 4435 | CVE-2026-29191 | critical | 8.5 | 1 | Cross-Site Scripting (XSS) |
| 4436 | potential Oracle E-Business Suite vulnerability | critical | 8.5 | 1 | data breach |
| 4437 | Weak BYOD Policies | critical | 8.5 | 1 | Insider Threat |
| 4438 | CVE-2026-24308 | critical | 8.5 | 1 | Data Exposure |
| 4439 | CVE-2025-54820 (Stack-based buffer overflow, CWE-121) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4440 | Poor Cybersecurity Practices | critical | 8.5 | 1 | Data Breach |
| 4441 | CVE-2021-39935 | critical | 8.5 | 1 | Server-Side Request Forgery (SSRF) |
| 4442 | CVE-2026-45659 (Improper deserialization of untrusted data) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4443 | Privilege Escalation Flaw in FIA Driver Categorisation Website | critical | 8.5 | 1 | Data Breach |
| 4444 | CVE-2025-55227 (SQL Server Privilege Escalation) | critical | 8.5 | 1 | Malware (Infostealer) |
| 4445 | CVE-2025-33231 | critical | 8.5 | 1 | Vulnerability |
| 4446 | Click2Gov online payment system | critical | 8.5 | 1 | Data Breach |
| 4447 | Inadequate IT security measures | critical | 8.5 | 1 | Data Breach |
| 4448 | Misconfigured Salesforce Experience Cloud guest user access controls | critical | 8.5 | 1 | Data Breach |
| 4449 | CVE-2026-1357 | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4450 | Prolonged Email Retention (6+ years) | critical | 8.5 | 1 | Data Breach |
| 4451 | Missing Reporting Mechanisms for Objectionable Content | critical | 8.5 | 1 | Data Breach |
| 4452 | Excessive OAuth permissions (Mail.Read, offline_access, profile/openid) | critical | 8.5 | 1 | OAuth Abuse |
| 4453 | Improper use of tracking technologies on authenticated pages (patient portals) without HIPAA-compliant authorizations or business associate agreements | critical | 8.5 | 1 | Data Breach |
| 4454 | misconfigured data visualization tool | critical | 8.5 | 1 | data exposure |
| 4455 | human trust in search engine ads | critical | 8.5 | 1 | phishing |
| 4456 | Zero-day vulnerabilities in Microsoft Exchange Server | critical | 8.5 | 1 | Cyberespionage |
| 4457 | Remote Work Vulnerabilities (COVID-19 Exploitation) | critical | 8.5 | 1 | Data Breach |
| 4458 | Misconfigured access control, lack of IP whitelisting | critical | 8.5 | 1 | Data Leak |
| 4459 | Insufficient sanitization in the `serialize` function (CVE-2026-0969) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4460 | eCompli application vulnerability | critical | 8.5 | 1 | Data Breach |
| 4461 | Weak/Reused Passwords (from third-party sources) | critical | 8.5 | 1 | Account Takeover |
| 4462 | Password reset flaw via AI chatbot instructions | critical | 8.5 | 1 | Data Breach |
| 4463 | Email Misdirection | critical | 8.5 | 1 | Data Breach |
| 4464 | Abuse of Microsoft Phone Link synchronization feature, living-off-the-land binaries (LOLBins) | critical | 8.5 | 1 | Cyberespionage, Malware Attack |
| 4465 | User trust in online platforms | critical | 8.5 | 1 | Phishing |
| 4466 | Unauthorized Software Installation | critical | 8.5 | 1 | Data Breach |
| 4467 | CVE-2026-21262 (Improper Access Control - CWE-284) | critical | 8.5 | 1 | Privilege Escalation |
| 4468 | MOVEit Transfer zero-day vulnerability (CVE-2023-34362) | critical | 8.5 | 1 | Data Breach |
| 4469 | CVE-2026-21519 | critical | 8.5 | 1 | Privilege Escalation |
| 4470 | inadequate cloud security measures | critical | 8.5 | 1 | data breach |
| 4471 | Lack of visibility into employee AI tool usage | critical | 8.5 | 1 | Data Leakage |
| 4472 | CVE-2026-1592 | critical | 8.5 | 1 | Supply Chain Attack |
| 4473 | Security access codes obtained through deception | critical | 8.5 | 1 | Hacking, Identity Theft, Data Breach, Cyberstalking |
| 4474 | Insider Threat / Unauthorized Access | critical | 8.5 | 1 | Data Breach |
| 4475 | Lack of audit and oversight of third-party SDK configurations | critical | 8.5 | 1 | Data Exposure |
| 4476 | OpenAI-compatible APIs (port 8000) | critical | 8.5 | 1 | LLMjacking |
| 4477 | Docker container escape | critical | 8.5 | 1 | Supply Chain Attack |
| 4478 | Insecure Data Storage | critical | 8.5 | 1 | Data Collection |
| 4479 | Client-Side Reward Points Validation (Mobile App) | critical | 8.5 | 1 | Data Exposure |
| 4480 | Unpatched CMS vulnerability | critical | 8.5 | 1 | Supply-Chain Attack |
| 4481 | Unauthorized access to Salesforce instance | critical | 8.5 | 1 | Data Breach |
| 4482 | CWE-287: Improper Authentication (Authentication Bypass) | critical | 8.5 | 1 | Data Breach |
| 4483 | AI Agents Bypassing Human Oversight | critical | 8.5 | 1 | Data Breach |
| 4484 | Ability to self-apply for admin privileges on the FIA Driver Categorisation portal | critical | 8.5 | 1 | data breach |
| 4485 | Third-party tracking and data sharing | critical | 8.5 | 1 | Data Breach |
| 4486 | Lack of Multi-Layered Authentication for Integrations | critical | 8.5 | 1 | Data Breach |
| 4487 | Prompt Injection Vulnerabilities | critical | 8.5 | 1 | AI Security Vulnerabilities |
| 4488 | Poor security practices, shared credentials or third-party tool managing access | critical | 8.5 | 1 | Account Takeover |
| 4489 | zero-day_vulnerabilities | critical | 8.5 | 1 | data_breach |
| 4490 | Insufficient data encryption | critical | 8.5 | 1 | Data Breach |
| 4491 | eForms System Vulnerability | critical | 8.5 | 1 | Data Breach |
| 4492 | Health Information Exchange (HIE) platform misconfiguration | critical | 8.5 | 1 | Data Breach |
| 4493 | Compromised company account on GitHub | critical | 8.5 | 1 | Data Breach |
| 4494 | Implicit trust in AI-generated summaries, unchecked trust in retrieved data by AI tools | critical | 8.5 | 1 | Phishing |
| 4495 | Unspecified vulnerability in Salesloft Drift's OAuth token management | critical | 8.5 | 1 | Supply Chain Attack |
| 4496 | Lack of Data Minimization in Blockchain Transactions | critical | 8.5 | 1 | Privacy Violation |
| 4497 | CVE-2026-11374 | critical | 8.5 | 1 | Account Takeover |
| 4498 | Reused passwords across multiple accounts | critical | 8.5 | 1 | Credential Stuffing |
| 4499 | Data security lapse | critical | 8.5 | 1 | Data Breach |
| 4500 | Compromised financial advisors' devices | critical | 8.5 | 1 | Cybersecurity Breach |
| 4501 | Human error, Social engineering, Internal leaks | critical | 8.5 | 1 | Data Breach |
| 4502 | CVE-2026-20040 | critical | 8.5 | 1 | Privilege Escalation |
| 4503 | AI_GENERATE_EMBEDDINGS (covert C2 channels) | critical | 8.5 | 1 | Data Exfiltration |
| 4504 | CVE-2026-26268 (CVSS 8.1) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4505 | Blender’s 'Auto Run Python Scripts' feature | critical | 8.5 | 1 | malware |
| 4506 | Weak authentication in verification APIs | critical | 8.5 | 1 | Data Breach Risk |
| 4507 | Weak IT Help Desk Authentication Protocols | critical | 8.5 | 1 | Data Breach |
| 4508 | Patched security vulnerability | critical | 8.5 | 1 | Data Breach |
| 4509 | Lack of Second-Layer Security Checks in API Configurations | critical | 8.5 | 1 | Data Breach |
| 4510 | Web vulnerabilities in Subaru's Starlink service | critical | 8.5 | 1 | Web Vulnerabilities |
| 4511 | Legitimate API traffic for command-and-control (C2) communications | critical | 8.5 | 1 | Cyber Espionage |
| 4512 | passkey storage in password managers | critical | 8.5 | 1 | phishing |
| 4513 | Vulnerable drivers (8 distinct drivers), FortiGate misconfigurations | critical | 8.5 | 1 | Ransomware |
| 4514 | Human access points, Infected endpoints | critical | 8.5 | 1 | Data Breach, Financial Theft, Ransomware (Suspected) |
| 4515 | Salesforce integration flaw (Drift-Salesloft) | critical | 8.5 | 1 | data breach |
| 4516 | Improper Handling of Sensitive Data | critical | 8.5 | 1 | Data Breach |
| 4517 | Storage and transmission of device-specific data (e.g., precise geolocation, browsing history, search queries) | critical | 8.5 | 1 | Data Exposure |
| 4518 | Obscured opt-out tools, 'no index' instructions, and dark patterns | critical | 8.5 | 1 | Data Breach |
| 4519 | Undisclosed vulnerabilities | critical | 8.5 | 1 | Zero-day exploitation |
| 4520 | CVE-2026-32202 (Windows Shell Protection Mechanism Failure - CWE-693) | critical | 8.5 | 1 | Zero-Day Vulnerability Exploitation |
| 4521 | TNEF decoder infinite loop | critical | 8.5 | 1 | Zero-Click XSS, DoS, SSRF, Session Injection |
| 4522 | Website Bug | critical | 8.5 | 1 | Data Exposure |
| 4523 | Impersonation Feature in Employee Portals | critical | 8.5 | 1 | Data Exposure |
| 4524 | Human Error (Failure to Redact Sensitive Data) | critical | 8.5 | 1 | Data Breach (Unintentional Disclosure) |
| 4525 | Weak verification processes for new user accounts on online gambling platforms | critical | 8.5 | 1 | Fraud Scheme |
| 4526 | Insecure Age-Verification System | critical | 8.5 | 1 | Surveillance |
| 4527 | Insufficient Agent Permission Controls | critical | 8.5 | 1 | AI Security Vulnerabilities |
| 4528 | Employee targeted via vishing | critical | 8.5 | 1 | Data Breach |
| 4529 | Inadequate User Data Protection | critical | 8.5 | 1 | Data Breach |
| 4530 | Overprivileged OAuth Tokens | critical | 8.5 | 1 | Data Breach (OAuth Token Compromise) |
| 4531 | Authentication vulnerabilities in Coupang's servers | critical | 8.5 | 1 | Data Breach |
| 4532 | CVE-2026-41613 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4533 | Lack of Access Controls / Unencrypted Data Storage | critical | 8.5 | 1 | Data Exposure |
| 4534 | Insufficient DLP and behavioral analytics | critical | 8.5 | 1 | Data Breach |
| 4535 | CVE-2025-0520 (CVSS 9.4) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4536 | CVE-2026-50507 (CWE-306: Missing Authentication for Critical Function) | critical | 8.5 | 1 | Security Feature Bypass |
| 4537 | CVE-2026-1281 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4538 | Lack of centralized oversight, inadequate vendor vetting, uncoordinated technology adoption | critical | 8.5 | 1 | Data Breach |
| 4539 | CVE-2026-44930 | critical | 8.5 | 1 | LDAP Injection |
| 4540 | Over-Permissive Third-Party App Access (Gmail, Google Drive, Dropbox) | critical | 8.5 | 1 | Data Breach |
| 4541 | Third-party shopping cart software | critical | 8.5 | 1 | Data Breach |
| 4542 | Compromised maintainer account (atiertant) | critical | 8.5 | 1 | Supply Chain Attack |
| 4543 | policy gaps | critical | 8.5 | 1 | data breach |
| 4544 | Overly permissive guest user settings in Salesforce Experience Cloud | critical | 8.5 | 1 | Data Harvesting |
| 4545 | Over-privileged access, improper offboarding, lack of monitoring | critical | 8.5 | 1 | Insider Threat |
| 4546 | CVE-2026-3338 | critical | 8.5 | 1 | Cryptographic Vulnerability |
| 4547 | Use-after-free in DRM GEM core ioctl (DRM_IOCTL_GEM_CHANGE_HANDLE) | critical | 8.5 | 1 | Privilege Escalation |
| 4548 | CVE-2024-3177 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4549 | Publicly exposed RPC endpoint lacking authentication, rate limiting, or permission checks | critical | 8.5 | 1 | Supply Chain Attack |
| 4550 | Leaked Passwords | critical | 8.5 | 1 | Data Breach |
| 4551 | Vertex AI Agent Engine Service Agent Hijacking | critical | 8.5 | 1 | Privilege Escalation |
| 4552 | Vulnerability in Accellion FTA system | critical | 8.5 | 1 | Data Breach |
| 4553 | CVE-2026-23818 (Open Redirect in GUI Login Workflow) | critical | 8.5 | 1 | Phishing-Style Exploit |
| 4554 | Reused usernames, weak security questions, password reuse | critical | 8.5 | 1 | Data Breach |
| 4555 | Unique Identification Number Guessing | critical | 8.5 | 1 | Data Breach |
| 4556 | Vulnerability with technology vendor | critical | 8.5 | 1 | Data Breach |
| 4557 | Improper sanitization of authorization URLs in n8n | critical | 8.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 4558 | MOVEit file transfer platform vulnerability | critical | 8.5 | 1 | Data Breach |
| 4559 | Third-party platforms used for marketing and operations | critical | 8.5 | 1 | Data Breach |
| 4560 | ClawJacked (CVE not specified) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4561 | CVE-2026-21514 (CWE-807 - Improper security decision-making based on untrusted inputs) | critical | 8.5 | 1 | Zero-Day Vulnerability Exploitation |
| 4562 | Chrome’s App-Bound Encryption | critical | 8.5 | 1 | Malware |
| 4563 | weak MFA implementations | critical | 8.5 | 1 | phishing |
| 4564 | Exposed Personal Data | critical | 8.5 | 1 | Data Breach |
| 4565 | Improper data handling and lack of safeguards | critical | 8.5 | 1 | Data Breach |
| 4566 | Vulnerability in GoAnywhere file transfer platform | critical | 8.5 | 1 | Data Breach |
| 4567 | CVE-2026-9560 (OS Command Injection - CWE-78) | critical | 8.5 | 1 | Privilege Escalation |
| 4568 | 46 vulnerabilities in inverters from Sungrow, Growatt, and SMA | critical | 8.5 | 1 | Firmware-level attack |
| 4569 | Improper handling of sensitive credentials in web assets | critical | 8.5 | 1 | Data Exposure |
| 4570 | human error (employee tricked into clicking malicious link) | critical | 8.5 | 1 | phishing |
| 4571 | Unconstrained CI/CD Service Accounts | critical | 8.5 | 1 | Identity Compromise |
| 4572 | Design flaw in metadata handling for public pages | critical | 8.5 | 1 | Privacy Leak |
| 4573 | Weak Authentication Credentials / Use of Non-Corporate Devices | critical | 8.5 | 1 | Data Breach / Unauthorized Access |
| 4574 | Compromised LiteLLM AI API tool versions | critical | 8.5 | 1 | Data Breach |
| 4575 | inadequate contractor oversight | critical | 8.5 | 1 | data breach |
| 4576 | Insider Knowledge (Ethan Lipnik's Willingness to Share) | critical | 8.5 | 1 | Trade Secret Theft |
| 4577 | Weaknesses in Almaviva’s infrastructure | critical | 8.5 | 1 | Data Breach |
| 4578 | Weak encryption (unsalted MD5 password hashes) | critical | 8.5 | 1 | Data Breach |
| 4579 | User account compromise | critical | 8.5 | 1 | Data Breach |
| 4580 | Missing role checks during user onboarding | critical | 8.5 | 1 | Autonomous AI-driven cyber attack |
| 4581 | CVE-2026-39987 (CVSS 9.3) | critical | 8.5 | 1 | Remote Code Execution (RCE) |
| 4582 | failure to deactivate former employee accounts | critical | 8.5 | 1 | data breach |
| 4583 | Improper Access by Employee | critical | 8.5 | 1 | Data Breach |
| 4584 | Improper IAM Policies | critical | 8.5 | 1 | Cloud Security Breach |
| 4585 | CVE (not specified) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4586 | Lack of multimodal review in AI code reviewers, exclusion of image files from analysis | critical | 8.5 | 1 | Data Exfiltration |
| 4587 | Improper Token Management (Unrotated API Tokens) | critical | 8.5 | 1 | Data Breach |
| 4588 | OAuth 2.0 protocol behavior (RFC 6749/9700) | critical | 8.5 | 1 | Phishing |
| 4589 | Malicious npm packages impersonating legitimate libraries | critical | 8.5 | 1 | Supply Chain Attack |
| 4590 | Unauthorized access to third-party system storing customer data | critical | 8.5 | 1 | Data Breach |
| 4591 | CVE-2026-24155 (Code Injection) | critical | 8.5 | 1 | Vulnerability Disclosure |
| 4592 | Failure to remediate known vulnerabilities | critical | 8.5 | 1 | Data Breach |
| 4593 | CVE-2026-3062 (Out-of-bounds read/write in Tint shader engine) | critical | 8.5 | 1 | Vulnerability Patch |
| 4594 | CVE-2017-7921 | critical | 8.5 | 1 | Espionage |
| 4595 | Improper third-party access to confidential records | critical | 8.5 | 1 | Data Breach |
| 4596 | CVE-2025-61882 (CVSS 9.8 - Remote Code Execution in BI Publisher Integration/Concurrent Processing) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4597 | CVE-2026-9614 (CWE-284: Improper Access Control) | critical | 8.5 | 1 | Privilege Escalation |
| 4598 | Auto-execution of `runOptions.runOn: 'folderOpen'` in tasks | critical | 8.5 | 1 | Arbitrary Code Execution |
| 4599 | CVE-2025-23120 | critical | 8.5 | 1 | Vulnerability |
| 4600 | Logic error in NextAuth JWT callback (GHSA-7hg4-x4pr-3hrg) | critical | 8.5 | 1 | Authentication Bypass |
| 4601 | Lack of disclosure and user consent for data collection | critical | 8.5 | 1 | Data Exfiltration |
| 4602 | CWE-20: Improper Input Validation (lack of server-side checks) | critical | 8.5 | 1 | Data Breach |
| 4603 | Publicly Accessible .env Files | critical | 8.5 | 1 | Data Exposure |
| 4604 | CVE-2025-4366 | critical | 8.5 | 1 | HTTP Request Smuggling |
| 4605 | Unsecured third-party server | critical | 8.5 | 1 | Data Breach |
| 4606 | Lack of encryption/authentication in SunSpec Modbus | critical | 8.5 | 1 | Firmware-level attack |
| 4607 | Inadequate acceptable use policies for AI | critical | 8.5 | 1 | Data Leakage |
| 4608 | COM-elevation technique | critical | 8.5 | 1 | Malware (RAT) |
| 4609 | Improper Access Control (Publicly Exposed Sensitive Data) | critical | 8.5 | 1 | Data Breach |
| 4610 | Lack of Input Validation | critical | 8.5 | 1 | Data Breach |
| 4611 | Lack of Secure Document Destruction Procedures | critical | 8.5 | 1 | Data Breach (Improper Disposal / Physical Security Failure) |
| 4612 | Unauthorized access to shared network drive | critical | 8.5 | 1 | Data Breach |
| 4613 | Insufficient user identification and authentication (UIA) controls | critical | 8.5 | 1 | Data Security Audit |
| 4614 | CVE-2025-7659 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4615 | Known system vulnerability | critical | 8.5 | 1 | Data Breach |
| 4616 | Unsecured database, malware infection via phishing emails/malicious websites/cracked software | critical | 8.5 | 1 | Data Exposure |
| 4617 | Compromised remote access credentials from third-party service providers | critical | 8.5 | 1 | Data Breach |
| 4618 | CVE-2025-XXXX (WebKit Zero-Day 2) | critical | 8.5 | 1 | Zero-Day Exploit |
| 4619 | CVE-2025-33228 | critical | 8.5 | 1 | Vulnerability |
| 4620 | Login Page Bug | critical | 8.5 | 1 | Data Breach |
| 4621 | Poor security practices for remote logins | critical | 8.5 | 1 | Data Breach |
| 4622 | Misconfigured database lacking proper authentication controls | critical | 8.5 | 1 | Data Breach |
| 4623 | Unsecured APIs, shared keys | critical | 8.5 | 1 | Data Breach |
| 4624 | CVE-2025-10547 (Uninitialized Stack Value Leading to Arbitrary Free) | critical | 8.5 | 1 | Vulnerability |
| 4625 | Session token hijacking | critical | 8.5 | 1 | Phishing-as-a-Service (PhaaS) |
| 4626 | CVE-2025-0520 (ShowDoc) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4627 | Malware deployment on third-party vendor employee device | critical | 8.5 | 1 | Data Breach |
| 4628 | CVE-2026-7201 (CVSS 8.8) | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4629 | CVE-2026-9080 | critical | 8.5 | 1 | Vulnerability Exploitation |
| 4630 | Default remote user account, no-password accounts, unsecured 'superuser' account | critical | 8.5 | 1 | Misconfiguration |
| 4631 | Inadequate safeguards | critical | 8.5 | 1 | Data Breach |
| 4632 | Human Resources Information Access | critical | 8.0 | 1 | Data Breach |
| 4633 | Compromised Administrative Staff Account | critical | 8.0 | 1 | Data Breach |
| 4634 | Misconfiguration in computer system | critical | 8.0 | 1 | Data Breach |
| 4635 | Software Update | critical | 8.0 | 1 | Data Breach |
| 4636 | Accellion’s FTA | critical | 8.0 | 1 | Data Breach |
| 4637 | Application Vulnerability | critical | 8.0 | 1 | Data Breach |
| 4638 | Sequential User ID Bug | critical | 8.0 | 1 | Data Breach |
| 4639 | CWE Exposure of Resource to Wrong Sphere | critical | 8.0 | 1 | Vulnerability |
| 4640 | Physical Loss of Device | critical | 8.0 | 1 | Data Breach |
| 4641 | Various vulnerabilities scanned by the Angler exploit kit | critical | 8.0 | 1 | Malvertising |
| 4642 | Improper Data Redaction | critical | 8.0 | 1 | Data Breach |
| 4643 | Impersonation of law enforcement officials | critical | 8.0 | 1 | Data Leak |
| 4644 | Database Access | critical | 8.0 | 1 | Data Breach |
| 4645 | Unsecured Data Storage Device | critical | 8.0 | 1 | Data Breach |
| 4646 | Insufficient security protections in cloud-based storage container | critical | 8.0 | 1 | Data Breach |
| 4647 | System Bug | critical | 8.0 | 1 | Data Disclosure |
| 4648 | Keyboard Software Bug | critical | 8.0 | 1 | Software Vulnerability |
| 4649 | Radio Communications Disruption | critical | 8.0 | 1 | Vulnerability Exploitation |
| 4650 | Employee Sharing Sensitive Information | critical | 8.0 | 1 | Data Breach |
| 4651 | Authentication process for My Account login details | critical | 8.0 | 1 | Data Breach |
| 4652 | Unauthorized Access by Insider | critical | 8.0 | 1 | Data Breach |
| 4653 | Lack of security safeguards in the contract | critical | 8.0 | 1 | Data Breach |
| 4654 | Security flaw in the patient portal | critical | 8.0 | 1 | Data Breach |
| 4655 | Misconfigured Server | critical | 8.0 | 1 | Data Breach |
| 4656 | RCE vulnerability in Dynamicweb software | critical | 8.0 | 1 | Remote Code Execution (RCE) |
| 4657 | Third-party Vendor Access | critical | 8.0 | 1 | Data Breach |
| 4658 | Points of Sale | critical | 8.0 | 1 | Data Breach |
| 4659 | Accellion file-sharing system | critical | 8.0 | 1 | Data Breach |
| 4660 | Misconfigured GitHub repository | critical | 8.0 | 1 | Data Leak |
| 4661 | Stack space exhaustion in user code with async_hooks enabled | high | 7.5 | 1 | Denial-of-Service (DoS) |
| 4662 | Lack of multi-factor authentication (MFA) on domain accounts | high | 7.5 | 1 | Ransomware Attempt |
| 4663 | Zero-day vulnerability in third-party software (Oracle E-Business Suite) | high | 7.5 | 1 | Data Breach |
| 4664 | CVE-2025-61884 (potential, not yet confirmed as exploited) | high | 7.5 | 1 | ransomware |
| 4665 | Review Process Bypass | high | 7.5 | 1 | Ransomware |
| 4666 | Obfuscated Code in Extensions | high | 7.5 | 1 | Malicious Software |
| 4667 | Internet-accessible flaws | high | 7.5 | 1 | Ransomware |
| 4668 | Firewall Vulnerability | high | 7.5 | 1 | Ransomware Attack |
| 4669 | Vulnerabilities in global digital infrastructure | high | 7.5 | 1 | Ransomware |
| 4670 | POS Systems | high | 7.5 | 1 | Data Breach |
| 4671 | Fragmented security tools, insufficient email security coverage | high | 7.5 | 1 | Ransomware |
| 4672 | outdated software, overworked staff, limited holiday response times | high | 7.5 | 1 | phishing |
| 4673 | Improper handling of sensitive information | high | 7.5 | 1 | Data Breach |
| 4674 | CVE-2025-61884 | high | 7.5 | 1 | Cyberattack |
| 4675 | IT System Glitch | high | 7.5 | 1 | Data Breach |
| 4676 | Payment system vulnerability | high | 7.5 | 1 | Data Breach |
| 4677 | Employee login credentials | high | 7.5 | 1 | Ransomware Attack |
| 4678 | Compromised Update Server | high | 7.5 | 1 | Malware Distribution |
| 4679 | Oracle E-Business Suite Zero-Day (Unauthenticated, Low Complexity) | high | 7.5 | 1 | Cyberattack |
| 4680 | CVE-2023-34362 (MOVEit) | high | 7.5 | 1 | ransomware |
| 4681 | legacy perimeter firewall | high | 7.5 | 1 | Ransomware |
| 4682 | security systems vulnerability | high | 7.5 | 1 | data breach |
| 4683 | Weak Password Policy | high | 6.5 | 1 | Hacking Incident |
| 4684 | User Trust in Legitimate Software Repositories | high | 6.0 | 1 | Malware Distribution |
| 4685 | Lack of Cross-Border Data Transfer Compliance | high | 6.0 | 1 | Data Breach |
| 4686 | CVE-2026-21525 (NULL pointer dereference, CWE-476) | high | 6.0 | 1 | Zero-Day Vulnerability |
| 4687 | Human Error (Unauthorized Information Disclosure) | high | 6.0 | 1 | Data Breach |
| 4688 | Lack of Real-Time Verification for High-Risk Transactions | high | 6.0 | 1 | Social Engineering |
| 4689 | developer reliance on third-party dependencies | high | 6.0 | 1 | supply chain attack |
| 4690 | Misconfiguration in talent management software | high | 6.0 | 1 | Data Breach |
| 4691 | Lack of robust security measures | high | 6.0 | 1 | Hacking |
| 4692 | Social Engineering (Trust Exploitation, Urgency Tactics) | high | 6.0 | 1 | Phishing |
| 4693 | Mandatory login gate on social media platform | high | 6.0 | 1 | Notification System Failure |
| 4694 | CVE-2025-33206 (CWE-78: Improper Neutralization of Special Elements in OS Commands) | high | 6.0 | 1 | Vulnerability |
| 4695 | Human (Insider Trust) | high | 6.0 | 1 | Unauthorized Disclosure |
| 4696 | CMS vulnerability | high | 6.0 | 1 | Data Breach |
| 4697 | Payment card processing system | high | 6.0 | 1 | Data Breach |
| 4698 | Misplaced Thumb Drive | high | 6.0 | 1 | Data Breach |
| 4699 | Unauthorized Access due to Program Glitch | high | 6.0 | 1 | Data Breach |
| 4700 | Unencrypted CouchDB installation | high | 6.0 | 1 | Data Leak |
| 4701 | Loss of Physical Hard Drives | high | 6.0 | 1 | Data Breach |
| 4702 | CVE-2025-32432 (Craft CMS) | high | 6.0 | 1 | cyberattack |
| 4703 | Disconnected Security Tools | high | 6.0 | 1 | DDoS Attack |
| 4704 | Email Account Security | high | 6.0 | 1 | Email Hijacking |
| 4705 | trust in automated AI-driven code analysis | high | 6.0 | 1 | supply chain attack |
| 4706 | Insufficient verification protocols for payment changes | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 4707 | Lack of vetting for third-party game demos (Valve/Steam) | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 4708 | DNS misconfiguration (abandoned domains with improper nameserver delegation) | high | 6.0 | 1 | DNS Misconfiguration Exploitation |
| 4709 | Insecure Direct Object Reference (IDOR) in media access endpoints (/media/{ID}) | high | 6.0 | 1 | Data Breach |
| 4710 | Unspecified software vulnerability in 2Keys MFA system | high | 6.0 | 1 | Data Breach |
| 4711 | PCI DSS 4.0.1 Non-Compliance (Unmanaged Scripts on Payment Pages) | high | 6.0 | 1 | Data Breach |
| 4712 | CVE-2026-0231 (CWE-497) | high | 6.0 | 1 | Vulnerability |
| 4713 | Default Configurations in Security Tools | high | 6.0 | 1 | Operational Risk |
| 4714 | CVE-2024-36347 | high | 6.0 | 1 | Vulnerability |
| 4715 | Bug in open-source library | high | 6.0 | 1 | Data Leak |
| 4716 | security risk analysis violations | high | 6.0 | 1 | regulatory_enforcement |
| 4717 | Lack of Email Gateway HTML Attachment Blocking | high | 6.0 | 1 | Phishing |
| 4718 | Regulatory Filing Systems (e.g., EDGAR, PACER) | high | 6.0 | 1 | Market Manipulation |
| 4719 | Insufficient Staff Training | high | 6.0 | 1 | Data Breach |
| 4720 | Lack of Automated Secrets Rotation | high | 6.0 | 1 | Credential Theft |
| 4721 | Unpatched/Outdated Systems (Windows Server 2003) | high | 6.0 | 1 | Physical Theft |
| 4722 | weaknesses in social media platform moderation | high | 6.0 | 1 | fraud |
| 4723 | Weak authentication mechanism (Phone Number/PIN model) | high | 6.0 | 1 | Unauthorized Access |
| 4724 | Use of Personal Device for Corporate Access | high | 6.0 | 1 | Data Breach |
| 4725 | Excessive OAuth Token Scopes | high | 6.0 | 1 | Unauthorized Access |
| 4726 | Flaw in the online application | high | 6.0 | 1 | Data Breach |
| 4727 | Donation Page | high | 6.0 | 1 | Data Breach |
| 4728 | CVE-2025-2848 | high | 6.0 | 1 | Vulnerability Exploitation |
| 4729 | Lack of Continuous Credential Monitoring | high | 6.0 | 1 | Credential Theft |
| 4730 | user typographical errors | high | 6.0 | 1 | phishing |
| 4731 | Human (phishing) | high | 6.0 | 1 | Phishing |
| 4732 | Online Store Vulnerability | high | 6.0 | 1 | Data Breach |
| 4733 | Insufficient oversight of contractor personnel with privileged access | high | 6.0 | 1 | Insider Threat |
| 4734 | Unsecured Personal Laptop | high | 6.0 | 1 | Data Breach |
| 4735 | Lack of Data Governance Policies | high | 6.0 | 1 | Data Leakage |
| 4736 | Authentication protocol vulnerabilities | high | 6.0 | 1 | Cyberattack |
| 4737 | CVE-2025-27610 | high | 6.0 | 1 | Vulnerability Exploitation |
| 4738 | Employee's Microsoft 365 Account | high | 6.0 | 1 | Data Breach |
| 4739 | Offline functionality of Cellebrite UFED tools | high | 6.0 | 1 | Unauthorized Data Extraction |
| 4740 | ARC processor flaws | high | 6.0 | 1 | DDoS Attack |
| 4741 | Unencrypted USB Flash Drive | high | 6.0 | 1 | Data Breach |
| 4742 | Legacy X-Frame-Options Ineffectiveness | high | 6.0 | 1 | Data Breach |
| 4743 | Incorrectly Configured AWS Bucket | high | 6.0 | 1 | Data Exposure |
| 4744 | Test server misconfiguration | high | 6.0 | 1 | Data Breach |
| 4745 | Unpatched external web servers (Nintendo) | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 4746 | misconfigured slot machine software | high | 6.0 | 1 | fraud |
| 4747 | Compromised e-mail account | high | 6.0 | 1 | Data Breach |
| 4748 | Security Setting Error | high | 6.0 | 1 | Data Breach |
| 4749 | Over-reliance on Limited Public Nodes (Centralization Risk) | high | 6.0 | 1 | Blockchain Security Breach |
| 4750 | Obfuscated Fake Context Alignment | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 4751 | Unencrypted Device | high | 6.0 | 1 | Data Breach |
| 4752 | TotoLink router firmware update server | high | 6.0 | 1 | DDoS Attack |
| 4753 | Sabre Hospitality Solutions' system | high | 6.0 | 1 | Data Breach |
| 4754 | Citrix Remote Desktop Software Vulnerability | high | 6.0 | 1 | Unauthorized Access |
| 4755 | Third-party AI tools | high | 6.0 | 1 | DDoS |
| 4756 | Delayed Tool Invocation | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 4757 | Unsecured Zoom Classroom | high | 6.0 | 1 | Cyber Attack |
| 4758 | Compromised Emails | high | 6.0 | 1 | Cyber Fraud |
| 4759 | Absence of Passkey Support | high | 6.0 | 1 | Phishing |
| 4760 | Fortinet VPN vulnerability | high | 6.0 | 1 | Data Breach |
| 4761 | Lack of API-Centric Threat Intelligence Sharing | high | 6.0 | 1 | Operational Risk |
| 4762 | Insertion of malicious script | high | 6.0 | 1 | Data Breach |
| 4763 | Unguarded Physical Access Points | high | 6.0 | 1 | Physical Theft |
| 4764 | exploitation of job application platforms | high | 6.0 | 1 | social engineering |
| 4765 | Exposed ADB ports on internet-facing devices | high | 6.0 | 1 | DDoS-for-hire |
| 4766 | publicly available personal data (for voice cloning) | high | 6.0 | 1 | phishing |
| 4767 | Weak Cloud Security (Nintendo) | high | 6.0 | 1 | DDoS Attack |
| 4768 | Human Error / Lack of Authentication Protocols | high | 6.0 | 1 | Data Breach |
| 4769 | Clipboard hijacking | high | 6.0 | 1 | Malware (Browser Extension) |
| 4770 | Insufficient User Awareness Training | high | 6.0 | 1 | Phishing |
| 4771 | Paycor's MOVEit Transfer software | high | 6.0 | 1 | Data Breach |
| 4772 | Lack of user awareness, trust in government services, and reusable phishing infrastructure | high | 6.0 | 1 | Phishing |
| 4773 | Vulnerability in TinyPulse employee survey platform | high | 6.0 | 1 | Data Breach |
| 4774 | Browsealoud Plugin | high | 6.0 | 1 | Cryptojacking |
| 4775 | NFC Protocol Abuse (Legitimate Traffic Relay) | high | 6.0 | 1 | Financial Fraud |
| 4776 | Gaps in cybersecurity | high | 6.0 | 1 | Cyberattack (Hacking) |
| 4777 | Website Payment Page | high | 6.0 | 1 | Data Breach |
| 4778 | Lack of U2F/Physical Security Key Enforcement | high | 6.0 | 1 | Financial Fraud |
| 4779 | Password Reset Token Leak | high | 6.0 | 1 | Account Hijacking |
| 4780 | lack of package registry enforcement | high | 6.0 | 1 | supply chain attack |
| 4781 | Weak passwords (e.g., 'LOUVRE', 'THALES') | high | 6.0 | 1 | Security Audit Findings |
| 4782 | Unsecured Deleted Cloud Storage Buckets | high | 6.0 | 1 | Data Breach |
| 4783 | weak monitoring of east-west traffic | high | 6.0 | 1 | phishing |
| 4784 | Publicly accessible Elasticsearch instance | high | 6.0 | 1 | Data Breach |
| 4785 | Apache HTTP server vulnerability | high | 6.0 | 1 | Cyber Espionage |
| 4786 | insufficient security protections | high | 6.0 | 1 | cyber intrusion |
| 4787 | Context Poisoning | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 4788 | Fault in the code of EOSBet's smart contracts | high | 6.0 | 1 | Cryptocurrency Theft |
| 4789 | CVE-2025-12779 | high | 6.0 | 1 | Vulnerability |
| 4790 | Database vulnerability | high | 6.0 | 1 | Data Breach |
| 4791 | Employee Mistake | high | 6.0 | 1 | Data Breach |
| 4792 | Base64 Obfuscation Bypass | high | 6.0 | 1 | Prompt Injection |
| 4793 | Lack of Access Controls (No Password Protection) | high | 6.0 | 1 | Data Breach (Unintentional Exposure) |
| 4794 | Generic Compliance Policies | high | 6.0 | 1 | Data Breach |
| 4795 | Human error (opening malicious attachment) | high | 6.0 | 1 | Phishing |
| 4796 | Data Collection Practices | high | 6.0 | 1 | Data Privacy Issue |
| 4797 | Package look-up capabilities | high | 6.0 | 1 | Data Breach |
| 4798 | Changes introduced in the 2026 roadmap update, including sharding and execution environment enhancements | high | 6.0 | 1 | Security Breach |
| 4799 | npm package distribution, Dynamic script loading from external sources | high | 6.0 | 1 | Supply Chain Attack, DDoS Attack |
| 4800 | Default password ('1234') on wireless crosswalk buttons | high | 6.0 | 1 | Hacking |
| 4801 | Payment .php file vulnerability | high | 6.0 | 1 | Data Breach |
| 4802 | lack of verification by job seekers | high | 6.0 | 1 | social engineering |
| 4803 | Inadequate Coordination of Security Escort | high | 6.0 | 1 | Physical Security Breach |
| 4804 | Browser-Stored Credentials | high | 6.0 | 1 | Credential Theft |
| 4805 | Automated attack tools | high | 6.0 | 1 | DDoS |
| 4806 | Human factor (phishing) | high | 6.0 | 1 | Phishing |
| 4807 | unprotected storage | high | 6.0 | 1 | data exposure |
| 4808 | SSRF | high | 6.0 | 1 | SSRF Vulnerability |
| 4809 | Weak Security Questions | high | 6.0 | 1 | Data Breach |
| 4810 | Data breach via third-party vendor | high | 6.0 | 1 | Phishing |
| 4811 | Weak Password Policy (Password: 'Louvre', 'Thales') | high | 6.0 | 1 | Physical Theft |
| 4812 | ADT Pulse Software Vulnerabilities | high | 6.0 | 1 | Unauthorized Access |
| 4813 | Outdated Antivirus/Anti-Malware Tools | high | 6.0 | 1 | Data Breach Risk |
| 4814 | Psychological manipulation (urgency, authority impersonation) | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 4815 | Inadequate Multi-Factor Authentication (MFA) | high | 6.0 | 1 | Human Error |
| 4816 | Weak DDoS mitigation (gaming platforms) | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 4817 | Human Carelessness | high | 6.0 | 1 | Human Error |
| 4818 | Location tracking vulnerabilities | high | 6.0 | 1 | Data Collection Incident |
| 4819 | Realtek chips | high | 6.0 | 1 | DDoS Attack |
| 4820 | Misconfigured third-party service | high | 6.0 | 1 | Data Exposure |
| 4821 | Permission Misconfiguration | high | 6.0 | 1 | Data Exposure |
| 4822 | Unauthorized access from outside of Europe | high | 6.0 | 1 | DDoS Attack |
| 4823 | psychological manipulation (e.g., fear of missing out on high returns) | high | 6.0 | 1 | fraud |
| 4824 | Drift’s OAuth integration flow vulnerability | high | 6.0 | 1 | Data Breach |
| 4825 | lack of real-time maritime tracking safeguards | high | 6.0 | 1 | physical cyber convergence |
| 4826 | Email Access | high | 6.0 | 1 | Business Email Compromise |
| 4827 | Unpatched Endpoints | high | 6.0 | 1 | Credential Theft |
| 4828 | unsecured QR code access | high | 6.0 | 1 | fraud |
| 4829 | Click2Gov | high | 6.0 | 1 | Data Breach |
| 4830 | Improperly secured MongoDB database | high | 6.0 | 1 | Data Breach |
| 4831 | Default/weak credentials | high | 6.0 | 1 | Botnet, DDoS |
| 4832 | CVE-2025-37735 (Improper Preservation of Permissions) | high | 6.0 | 1 | Vulnerability / Privilege Escalation |
| 4833 | JavaScript File Modification | high | 6.0 | 1 | Malware |
| 4834 | User Trust in Discounted/Rare Item Offers | high | 6.0 | 1 | DDoS Attack |
| 4835 | Human Error (IT Support Tricked) | high | 6.0 | 1 | Data Breach |
| 4836 | Android system permissions bypass | high | 6.0 | 1 | Vulnerability |
| 4837 | CVE-2025-59789 (Uncontrolled Recursion / Stack Overflow in json2pb component) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 4838 | Lack of Physical Security Measures at ATM | high | 6.0 | 1 | Data Breach (Card Skimming) |
| 4839 | Absence of Endpoint Monitoring | high | 6.0 | 1 | Data Breach Risk |
| 4840 | CVE-2024-38197 (CVSS 6.5: Medium) | high | 6.0 | 1 | Spoofing |
| 4841 | Muted Fake Context Alignment | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 4842 | Inadequate Firewalls | high | 6.0 | 1 | Data Breach |
| 4843 | Computer Infection | high | 6.0 | 1 | Financial Theft |
| 4844 | Unauthorized access to QuickBooks Online account | high | 6.0 | 1 | Data Breach |
| 4845 | Improper access to email account | high | 6.0 | 1 | Data Breach |
| 4846 | Legacy Credential | high | 6.0 | 1 | Supply Chain Attack |
| 4847 | Hardcoded GitHub Token | high | 6.0 | 1 | Supply Chain Attack |
| 4848 | Weak Administrator Password | high | 6.0 | 1 | Data Breach |
| 4849 | Backup Payment Card Readers | high | 6.0 | 1 | Data Breach |
| 4850 | Human Error/Employee Misconduct | high | 6.0 | 1 | Unauthorized Access and Data Breach |
| 4851 | Configuration Mistake | high | 6.0 | 1 | Data Leak |
| 4852 | Unsecured installation page, lack of session validation, exposed administrative endpoints | high | 6.0 | 1 | Malware Distribution |
| 4853 | Publicly Available Environment Files | high | 6.0 | 1 | Data Exposure |
| 4854 | improper use of email fields (To/CC instead of BCC) | high | 6.0 | 1 | data breach |
| 4855 | Player trust in unofficial marketplaces | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 4856 | Lack of Visibility in Rapid Development Cycles | high | 6.0 | 1 | DDoS Attack |
| 4857 | Human Trust in Branded Communications / Lack of Multi-Channel Verification | high | 6.0 | 1 | Phishing / Social Engineering |
| 4858 | Medium and high severity vulnerabilities in Ivanti EPMM software | high | 6.0 | 1 | Cyber Attack |
| 4859 | Unauthorized access due to call center employee negligence | high | 6.0 | 1 | Data Breach |
| 4860 | Payment Card Network | high | 6.0 | 1 | Data Breach |
| 4861 | Exploitation of GitHub's Discussions feature and perceived trustworthiness of security advisories | high | 6.0 | 1 | Phishing |
| 4862 | Unsecured Wi-Fi network | high | 6.0 | 1 | Malware |
| 4863 | Website platform configuration error (password-protected documents made publicly accessible via search) | high | 6.0 | 1 | data breach |
| 4864 | Weak Cybersecurity Standards in Financial and E-Commerce Sectors | high | 6.0 | 1 | Cybercrime Network Dismantling |
| 4865 | Lack of data-sharing protocols in pilot programs | high | 6.0 | 1 | Data Breach / Unauthorized Data Sharing |
| 4866 | Human (Social Engineering) | high | 6.0 | 1 | Phishing |
| 4867 | Lack of verification protocols for financial requests, unauthorized executable file execution | high | 6.0 | 1 | CEO Impersonation Fraud (Boss Scam) |
| 4868 | Critical Infrastructure Vulnerabilities (e.g., Power Grid Exploitation) | high | 6.0 | 1 | Cybercrime Network Dismantling |
| 4869 | Unsecured Collaborative Tools | high | 6.0 | 1 | Data Breach Risk |
| 4870 | Public exposure of environment configuration file | high | 6.0 | 1 | Data Breach |
| 4871 | Lax privacy settings | high | 6.0 | 1 | Data Breach |
| 4872 | URL Spoofing | high | 6.0 | 1 | Phishing |
| 4873 | Weak URL validation in RecursiveUrlLoader (String.startsWith() check) and lack of private IP range validation | high | 6.0 | 1 | Server-Side Request Forgery (SSRF) |
| 4874 | Hardcoded Secrets in Code Repositories | high | 6.0 | 1 | Credential Theft |
| 4875 | Insufficiently Secure Settings | high | 6.0 | 1 | Data Breach |
| 4876 | Human Trust in Branded Communications | high | 6.0 | 1 | Phishing |
| 4877 | Lack of Token Rotation | high | 6.0 | 1 | Unauthorized Access |
| 4878 | Website Configuration Error | high | 6.0 | 1 | Data Breach |
| 4879 | TOCTOU Vulnerability | high | 6.0 | 1 | Vulnerability Exploitation |
| 4880 | Software Update Issue | high | 6.0 | 1 | Data Breach |
| 4881 | Unauthorized access to sensitive employee records | high | 6.0 | 1 | Data Breach |
| 4882 | Fake CAPTCHA prompts, social engineering | high | 6.0 | 1 | Malware Attack |
| 4883 | Cached Credentials | high | 6.0 | 1 | Data Security Incident |
| 4884 | Internal Employee Access | high | 6.0 | 1 | Data Breach |
| 4885 | Business Continuity Dependencies | high | 6.0 | 1 | Third-Party Risk |
| 4886 | Overly Permissive Sandbox Attributes (allow-same-origin + allow-scripts) | high | 6.0 | 1 | Data Breach |
| 4887 | Insufficient network segmentation between office and operational systems | high | 6.0 | 1 | Cyber Intrusion |
| 4888 | Backend Update Bug | high | 6.0 | 1 | Bug/Exploit |
| 4889 | Insufficient Monitoring of Third-Party Integrations | high | 6.0 | 1 | Unauthorized Access |
| 4890 | unsecured email systems | high | 6.0 | 1 | phishing |
| 4891 | Weak Internal Controls (Prior Embezzlement) | high | 6.0 | 1 | Fraud |
| 4892 | Lack of Geofencing for Transaction Validation | high | 6.0 | 1 | Financial Fraud |
| 4893 | WhatsApp screen-sharing feature (misuse) | high | 6.0 | 1 | social engineering |
| 4894 | insufficient monitoring of collaboration platforms | high | 6.0 | 1 | data breach |
| 4895 | Weak Login Verification | high | 6.0 | 1 | Data Breach |
| 4896 | Lack of Regulatory Oversight in Cryptocurrency Operations | high | 6.0 | 1 | Cybercrime Network Dismantling |
| 4897 | Weak Authentication for OAuth Tokens | high | 6.0 | 1 | Data Breach |
| 4898 | Non-secure data storage location | high | 6.0 | 1 | Data Breach |
| 4899 | Backup Device Misconfiguration | high | 6.0 | 1 | Data Breach |
| 4900 | Legacy IT systems and outdated infrastructure | high | 6.0 | 1 | Cybersecurity Awareness and Infrastructure Vulnerability |
| 4901 | unrestricted access to student email accounts | high | 6.0 | 1 | election fraud |
| 4902 | Abuse of trusted cloud services (Firebase, Google Translate) | high | 6.0 | 1 | Phishing |
| 4903 | Security weaknesses in NHS websites | high | 6.0 | 1 | Cyberattack |
| 4904 | Unspecified vulnerability | high | 6.0 | 1 | Cyber Attack |
| 4905 | Retired Internet Application | high | 6.0 | 1 | Data Breach |
| 4906 | Accela Software Error | high | 6.0 | 1 | Data Breach |
| 4907 | Unpatched firmware and default credentials in IoT devices | high | 6.0 | 1 | DDoS-for-hire |
| 4908 | Lack of endpoint security for attendee devices | high | 6.0 | 1 | Malware |
| 4909 | MOVEit Transfer platform vulnerability (likely CVE-2023-34362) | high | 6.0 | 1 | Data Breach |
| 4910 | Vulnerable version of Trust Wallet browser extension (v2.68) | high | 6.0 | 1 | Supply Chain Attack |
| 4911 | Static Filtering in SEGs | high | 6.0 | 1 | Operational Risk |
| 4912 | Abuse of trusted .arpa domain for reverse DNS lookups | high | 6.0 | 1 | Phishing |
| 4913 | No Device Encryption | high | 6.0 | 1 | Data Breach Risk |
| 4914 | Delay introduction via VPN | high | 6.0 | 1 | Cheating via VPN |
| 4915 | AI-related blind spots | high | 6.0 | 1 | Data Breach |
| 4916 | Data processing error | high | 6.0 | 1 | Data Breach |
| 4917 | Misconfigured database backup access | high | 6.0 | 1 | Data Breach |
| 4918 | Privacy Controls | high | 6.0 | 1 | Data Breach |
| 4919 | Weak password ('solarwinds123') | high | 6.0 | 1 | Cyberattack |
| 4920 | Human error (email misdelivery) | high | 6.0 | 1 | Data Breach (Human Error / Misdelivery) |
| 4921 | Poor Data Protection Practices | high | 6.0 | 1 | Insider Threat |
| 4922 | Fortra GoAnywhere secure file transfer platform | high | 6.0 | 1 | Data Breach |
| 4923 | CVE-2025-57714 (Unquoted Search Path in NetBak Replicator 4.5.x) | high | 6.0 | 1 | Vulnerability |
| 4924 | Family Member Trust Exploitation | high | 6.0 | 1 | Fraud |
| 4925 | CVE-2026-26127 (Out-of-bounds read, CWE-125) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 4926 | Internal Access Controls | high | 6.0 | 1 | Data Breach |
| 4927 | Vulnerable Laravel version or misconfiguration | high | 6.0 | 1 | Data Exposure |
| 4928 | Physical ATM Security | high | 6.0 | 1 | Data Breach |
| 4929 | Security vulnerabilities in IP cameras | high | 6.0 | 1 | DDoS Attack |
| 4930 | Legacy banking systems | high | 6.0 | 1 | AI-generated exploits |
| 4931 | Use of Non-Official Communication Channels | high | 6.0 | 1 | Phishing |
| 4932 | misconfigured database | high | 6.0 | 1 | data exposure |
| 4933 | Error in resetting network settings | high | 6.0 | 1 | Data Breach |
| 4934 | weakness in AIS tampering detection | high | 6.0 | 1 | physical cyber convergence |
| 4935 | NEXTEP self-service kiosks | high | 6.0 | 1 | Data Breach |
| 4936 | Lack of Device Encryption/Tracking | high | 6.0 | 1 | Data Security Incident |
| 4937 | Routers from T-Mobile, Zyxel, D-Link, Linksys | high | 6.0 | 1 | DDoS Attack |
| 4938 | Third-party software (TanStack) | high | 6.0 | 1 | AI-generated exploits |
| 4939 | Abuse of Legitimate Services | high | 6.0 | 1 | Phishing |
| 4940 | Third-Party CRM Integration Vulnerabilities | high | 6.0 | 1 | Data Breach |
| 4941 | Software vulnerability at vendor Infosys McCamish Systems LLC | high | 6.0 | 1 | Data Breach |
| 4942 | Email Privacy Misconfigurations | high | 6.0 | 1 | Data Breach |
| 4943 | Weak Authentication (SMS-based 2FA) | high | 6.0 | 1 | Social Engineering |
| 4944 | Exposure of Customer Data | high | 6.0 | 1 | Data Exposure |
| 4945 | DNS misconfiguration | high | 6.0 | 1 | DNS Hijacking |
| 4946 | Poor password hygiene (weak, reused, or easily guessable passwords) | high | 6.0 | 1 | data breach |
| 4947 | Social Engineering of Mobile Carriers | high | 6.0 | 1 | Account Takeover |
| 4948 | Unquoted Search Path Weakness in Plantronics Hub | high | 6.0 | 1 | Privilege Escalation |
| 4949 | Unpatched flaw in a commercial MDM system | high | 6.0 | 1 | Data Breach |
| 4950 | Compromised user credentials | high | 6.0 | 1 | Data Breach |
| 4951 | Human Trust in Authority Figures | high | 6.0 | 1 | Social Engineering |
| 4952 | IT vendor vulnerability confirmed by the Ministry of Health | high | 6.0 | 1 | Data Breach |
| 4953 | URL Parameter Manipulation (collection) | high | 6.0 | 1 | Prompt Injection |
| 4954 | Employee Credentials and Laptop | high | 6.0 | 1 | Data Breach |
| 4955 | Vendor Misconfiguration | high | 6.0 | 1 | Data Breach |
| 4956 | Human Error (Fatigue/Jetlag) | high | 6.0 | 1 | Phishing |
| 4957 | Neglected to fix vulnerabilities | high | 6.0 | 1 | Data Breach |
| 4958 | Human Error / Policy Violation (Email Mismanagement) | high | 6.0 | 1 | Data Breach / Unauthorized Disclosure |
| 4959 | Mistaken Disclosure | high | 6.0 | 1 | Data Breach |
| 4960 | Unsecured Employee Roster | high | 6.0 | 1 | Data Breach |
| 4961 | Lack of multi-factor authentication (MFA) in some cases | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 4962 | Same password for multiple accounts | high | 6.0 | 1 | Cyber Attack |
| 4963 | GitHub Credentials | high | 6.0 | 1 | Data Breach |
| 4964 | gaps in visibility | high | 6.0 | 1 | phishing |
| 4965 | lack of bulk email security measures | high | 6.0 | 1 | data breach |
| 4966 | Unprotected RSYNC Server | high | 6.0 | 1 | Data Leak |
| 4967 | Third-party application vulnerability | high | 6.0 | 1 | Data Breach |
| 4968 | Inadequate User Consent Mechanisms | high | 6.0 | 1 | Data Breach |
| 4969 | Backdoor in the system | high | 6.0 | 1 | Fraud |
| 4970 | CVE-2026-20188 (Uncontrolled Resource Consumption - CWE-400) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 4971 | Folio/IIN Integration Flaws | high | 6.0 | 1 | Data Breach |
| 4972 | Inadvertent public exposure of live surveillance feeds | high | 6.0 | 1 | Data Leak |
| 4973 | human trust in authoritative messages (e.g., toll agencies) | high | 6.0 | 1 | phishing |
| 4974 | Unpatched Public-Facing Servers | high | 6.0 | 1 | DDoS Attack |
| 4975 | Weak Authentication Controls | high | 6.0 | 1 | Data Breach |
| 4976 | Lack of proactive domain monitoring and registration of brand variations | high | 6.0 | 1 | Cybersquatting, Phishing, Malware Distribution, Fraud |
| 4977 | Exposure of Install Action Tokens | high | 6.0 | 1 | Data Breach |
| 4978 | Incorrect Address Usage | high | 6.0 | 1 | Data Breach |
| 4979 | Accellion's File Transfer Appliance software | high | 6.0 | 1 | Data Breach |
| 4980 | Accès non autorisé aux données clients | high | 6.0 | 1 | Cyberattaque |
| 4981 | Lack of user awareness, perceived trustworthiness of FaceTime, screen-sharing access | high | 6.0 | 1 | Social Engineering / Phishing Scam |
| 4982 | System Vulnerability | high | 6.0 | 1 | Data Breach |
| 4983 | CVE-2025-66168 | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 4984 | human trust in FIFA branding | high | 6.0 | 1 | phishing |
| 4985 | CVE-2025-43300 (Apple OS-level zero-day) | high | 6.0 | 1 | Zero-day exploit |
| 4986 | Unsecured Audio Files | high | 6.0 | 1 | Data Exposure |
| 4987 | Insecure use of pull_request_target in GitHub Actions workflows | high | 6.0 | 1 | Supply Chain Attack |
| 4988 | Third-party file sharing product | high | 6.0 | 1 | Data Breach |
| 4989 | Server vulnerability of a former IT service provider | high | 6.0 | 1 | Data Breach |
| 4990 | Credential theft, Stolen payment tokens | high | 6.0 | 1 | Fraud |
| 4991 | End-of-life (EOL) software (Apache/2.4.52, Apache/2.4.6 with OpenSSL/1.0.2k-fips, etc.) | high | 6.0 | 1 | Phishing |
| 4992 | Stolen Laptop | high | 6.0 | 1 | Data Breach |
| 4993 | Unauthorized access to an employee email account | high | 6.0 | 1 | Data Breach |
| 4994 | CVE-2025-53770 (SharePoint Server, 'ToolShell') | high | 6.0 | 1 | Data Breach |
| 4995 | Employee Account | high | 6.0 | 1 | Data Breach |
| 4996 | Human error leading to unauthorized access | high | 6.0 | 1 | Phishing |
| 4997 | Unattended Property | high | 6.0 | 1 | Data Theft |
| 4998 | lack of verification for online investments | high | 6.0 | 1 | fraud |
| 4999 | Fragmented Security Tool Integration | high | 6.0 | 1 | Operational Risk |
| 5000 | improper authentication | high | 6.0 | 1 | unauthorized access |
| 5001 | Weak Authentication (Slack Cookies) | high | 6.0 | 1 | Data Breach |
| 5002 | CVE-2025-61882, Oracle E-Business Suite (EBS) security flaws | high | 6.0 | 1 | Data Breach |
| 5003 | Malicious Software Installation | high | 6.0 | 1 | Data Breach |
| 5004 | Lack of Public Awareness | high | 6.0 | 1 | Phishing |
| 5005 | System Malfunction | high | 6.0 | 1 | Data Leak |
| 5006 | Human Trust in Official-Looking Communications | high | 6.0 | 1 | Phishing |
| 5007 | Hardcoded Credentials in Internal Portals | high | 6.0 | 1 | Data Breach |
| 5008 | Unencrypted and Unprotected Data Storage | high | 6.0 | 1 | Data Breach |
| 5009 | Improper storage of personal information | high | 6.0 | 1 | Data Breach |
| 5010 | Failure to Protect Sensitive Location Data | high | 6.0 | 1 | Physical Security Breach |
| 5011 | Human factor - employees providing login credentials | high | 6.0 | 1 | Data Breach |
| 5012 | Human Error (Falling for Spoofed Email) | high | 6.0 | 1 | Data Breach |
| 5013 | Stolen authentication cookie | high | 6.0 | 1 | Cyber Espionage |
| 5014 | Lack of authentication on Kubernetes console | high | 6.0 | 1 | Cloud Security Breach |
| 5015 | Business Email Compromise | high | 6.0 | 1 | Data Breach |
| 5016 | Installation management process in Mobile VPN with IPSec client for Windows | high | 6.0 | 1 | Privilege Escalation |
| 5017 | Same-Origin Policy Gaps (postMessage Wildcards, CORS Misconfigurations) | high | 6.0 | 1 | Data Breach |
| 5018 | Employee System Credentials | high | 6.0 | 1 | Data Breach |
| 5019 | Unsecured MongoDB Server | high | 6.0 | 1 | Data Exposure |
| 5020 | lack of authentication for mobile device pairing | high | 6.0 | 1 | fraud |
| 5021 | Lack of Email Encryption / Employee Negligence | high | 6.0 | 1 | Data Breach |
| 5022 | Basic Security Vulnerability | high | 6.0 | 1 | Data Breach |
| 5023 | GoAnywhere MFT zero-day vulnerability | high | 6.0 | 1 | Data Breach |
| 5024 | Faiblesse dans les procédures de vérification d'identité | high | 6.0 | 1 | Cyberattaque |
| 5025 | Inadequate Vetting Procedures | high | 6.0 | 1 | Data Exposure |
| 5026 | External Access to Validator Keys | high | 6.0 | 1 | Blockchain Security Breach |
| 5027 | Weak PIN reset security questions | high | 6.0 | 1 | Data Breach |
| 5028 | Unencrypted Storage Devices | high | 6.0 | 1 | Data Breach |
| 5029 | Expanded digital identities, permissions, and access points due to AI adoption | high | 6.0 | 1 | Data Breach |
| 5030 | Lack of Data Wiping and Encryption | high | 6.0 | 1 | Data Breach |
| 5031 | unauthorized data access/exfiltration by terminated employee | high | 6.0 | 1 | data breach |
| 5032 | Web-based payroll program | high | 6.0 | 1 | Data Breach |
| 5033 | CVE-2025-0128 | high | 6.0 | 1 | Denial of Service (DoS) |
| 5034 | Fake Context Alignment | high | 6.0 | 1 | Indirect Prompt Injection (IPI) Attack |
| 5035 | CVE-2025-24071 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5036 | Credential Stuffing | high | 6.0 | 1 | Authentication Security Improvement |
| 5037 | Inadequate credential monitoring and reliance on unmanaged devices for SaaS access | high | 6.0 | 1 | Credential Theft |
| 5038 | Automatic processing of iCalendar files, Trust in calendar notifications, Device code phishing (ConsentFix) | high | 6.0 | 1 | Phishing |
| 5039 | Public Access to Amazon S3 Bucket | high | 6.0 | 1 | Data Exposure |
| 5040 | potential weaknesses in email system security | high | 6.0 | 1 | phishing |
| 5041 | Public fear | high | 6.0 | 1 | Phishing |
| 5042 | weak governance | high | 6.0 | 1 | phishing |
| 5043 | API security flaw in Kiln’s infrastructure (used for Solana staking operations) | high | 6.0 | 1 | cyberattack |
| 5044 | weak identity verification for wallet transfers | high | 6.0 | 1 | cyber theft |
| 5045 | Unsecured Email Account | high | 6.0 | 1 | Data Breach |
| 5046 | CVE-2025-24061 | high | 6.0 | 1 | Vulnerability Disclosure |
| 5047 | System-generated error | high | 6.0 | 1 | Data Breach |
| 5048 | Unsecured Remote Work Environments | high | 6.0 | 1 | Human Error |
| 5049 | Unvalidated PostMessage Origins | high | 6.0 | 1 | Data Breach |
| 5050 | Data server configuration error | high | 6.0 | 1 | Data Breach |
| 5051 | Human Error (Improper Data Handling) | high | 6.0 | 1 | Data Breach (Accidental Disclosure) |
| 5052 | Rapid development cycles outpacing security reviews | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5053 | low cybersecurity awareness | high | 6.0 | 1 | phishing |
| 5054 | Email login credentials | high | 6.0 | 1 | Data Breach |
| 5055 | Post-termination access to company passwords | high | 6.0 | 1 | Unauthorized Access |
| 5056 | Weak Data Access Controls | high | 6.0 | 1 | Data Exposure |
| 5057 | Unpatched systems in video surveillance and access control | high | 6.0 | 1 | Security Audit Findings |
| 5058 | Loss of Physical Control (Stolen Laptop) | high | 6.0 | 1 | Data Breach (Theft of Device) |
| 5059 | Lack of Secure Document Disposal Procedures | high | 6.0 | 1 | Data Breach (Physical) |
| 5060 | Inadvertent Permissions | high | 6.0 | 1 | Cyber Attack |
| 5061 | Skill Gaps in Workforce | high | 6.0 | 1 | Data Breach |
| 5062 | Standard employee account credentials | high | 6.0 | 1 | Cyberattack |
| 5063 | inadequate contractor monitoring | high | 6.0 | 1 | insider threat |
| 5064 | Bypass of Time-Limited MFA Windows | high | 6.0 | 1 | Financial Fraud |
| 5065 | MIME type and filename extension mismatches | high | 6.0 | 1 | Vulnerability Exploit |
| 5066 | Phishing/Malware | high | 6.0 | 1 | Data Breach |
| 5067 | Malware installation via phishing | high | 6.0 | 1 | Data Breach |
| 5068 | Unencrypted Email | high | 6.0 | 1 | Data Breach |
| 5069 | Administrative Error | high | 6.0 | 1 | Data Breach |
| 5070 | lack of anomaly detection for screenshot activities | high | 6.0 | 1 | insider threat |
| 5071 | Stolen Google Gemini API Keys | high | 6.0 | 1 | Fraud |
| 5072 | Trust in unsolicited communications | high | 6.0 | 1 | Scam |
| 5073 | Over-Permissive Ticket Transfer Features | high | 6.0 | 1 | Account Takeover (ATO) |
| 5074 | Human vulnerability (phishing) | high | 6.0 | 1 | Phishing |
| 5075 | MOVEit zero-day vulnerability | high | 6.0 | 1 | Data Breach |
| 5076 | Weak Authentication in Mobile Wallet Onboarding | high | 6.0 | 1 | Financial Fraud |
| 5077 | Inadequate Internal Controls and Oversight | high | 6.0 | 1 | Insider Threat |
| 5078 | Weak PIN reset security | high | 6.0 | 1 | Data Breach |
| 5079 | Business Email Accounts | high | 6.0 | 1 | Data Breach |
| 5080 | Compromised Employee Mailbox | high | 6.0 | 1 | Data Breach |
| 5081 | Undisclosed Data Breaches | high | 6.0 | 1 | Market Manipulation |
| 5082 | Fortra's GoAnywhere MFT platform's zero-day vulnerability | high | 6.0 | 1 | Data Breach |
| 5083 | Weak password hashing (SHA-256) | high | 6.0 | 1 | Data Breach |
| 5084 | DeFi Vulnerabilities | high | 6.0 | 1 | Market Manipulation |
| 5085 | Google Business Profile verification loophole | high | 6.0 | 1 | defacement |
| 5086 | Shadow IT | high | 6.0 | 1 | Security Control Bypass |
| 5087 | Human error (successful phishing attack) | high | 6.0 | 1 | Data Breach |
| 5088 | Human Error (Inadvertent Disclosure in Public Documents) | high | 6.0 | 1 | Data Breach |
| 5089 | Lax controls | high | 6.0 | 1 | Insider Threat |
| 5090 | Unsecured IoT Devices (DVRs, WiFi Routers) | high | 6.0 | 1 | DDoS Attack |
| 5091 | Loneliness | high | 6.0 | 1 | Scam |
| 5092 | Weakness in GPS Navigation System Authentication/Encryption | high | 6.0 | 1 | GPS Spoofing / Maritime Cyber Incident |
| 5093 | Default/Lack of Credentials | high | 6.0 | 1 | DDoS Attack |
| 5094 | Human Error (Incorrect Address Usage) | high | 6.0 | 1 | Data Breach |
| 5095 | Abuse of legitimate platform features (email parsing, merchant workflows, or input validation gaps) | high | 6.0 | 1 | Phishing / Social Engineering |
| 5096 | Security Misconfiguration | high | 6.0 | 1 | Data Leak |
| 5097 | shared/default credentials | high | 6.0 | 1 | election fraud |
| 5098 | Exposed Private Data | high | 6.0 | 1 | Data Leak |
| 5099 | Suspicious WordPress plugin | high | 6.0 | 1 | Cyberattack |
| 5100 | Point-of-sale terminals | high | 6.0 | 1 | Data Breach |
| 5101 | Unspecified vulnerability in 2Keys MFA system (Interac-owned) | high | 6.0 | 1 | Data Breach |
| 5102 | Delayed Detection of Coordinated Trading Patterns | high | 6.0 | 1 | Financial Fraud |
| 5103 | Lack of insider threat detection and prevention measures | high | 6.0 | 1 | Insider Threat |
| 5104 | Low-and-slow request rate evasion of rate-limiting defenses | high | 6.0 | 1 | DDoS |
| 5105 | Legal Access via Emergency Order | high | 6.0 | 1 | Data Breach |
| 5106 | Password Manager Bypass | high | 6.0 | 1 | Phishing |
| 5107 | Outdated Technology Infrastructure | high | 6.0 | 1 | Data Leakage |
| 5108 | Weak Password/Credential Management | high | 6.0 | 1 | Data Breach |
| 5109 | Reused passwords across multiple services | high | 6.0 | 1 | Credential Stuffing |
| 5110 | human trust/urgency bias | high | 6.0 | 1 | social engineering |
| 5111 | lapses in cybersecurity measures | high | 6.0 | 1 | cyber intrusion |
| 5112 | Zero-Day Vulnerability in ESG Equipment | high | 6.0 | 1 | Data Theft |
| 5113 | Phishable OTP Tokens for Mobile Wallet Provisioning | high | 6.0 | 1 | Financial Fraud |
| 5114 | Inadvertent transfer of control of the account to a malicious actor | high | 6.0 | 1 | Hacking |
| 5115 | Improper data storage | high | 6.0 | 1 | Data Breach |
| 5116 | AI Platform Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5117 | Unsecured Endpoints | high | 6.0 | 1 | Data Security Incident |
| 5118 | Improper Data Handling / Public-Facing Website Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5119 | Insufficient Email Security Protocols | high | 6.0 | 1 | Phishing |
| 5120 | Legacy Access Controls, Identity Vulnerabilities | high | 6.0 | 1 | Data Breach |
| 5121 | Unmanaged Secrets in CI/CD Pipelines | high | 6.0 | 1 | Credential Theft |
| 5122 | Compromise at a third party vendor's file servers | high | 6.0 | 1 | Data Breach |
| 5123 | Human vulnerability through social engineering | high | 6.0 | 1 | Social Engineering Attack |
| 5124 | Employee Mailboxes | high | 6.0 | 1 | Data Breach |
| 5125 | CVE-2025-53770 (Microsoft SharePoint, CVSS 9.8) | high | 6.0 | 1 | Data Breach |
| 5126 | Suspicious code on online payment portal | high | 6.0 | 1 | Data Breach |
| 5127 | Browser hijacking via malicious script | high | 6.0 | 1 | DDoS Attack, Content Tampering, Malicious JavaScript Injection |
| 5128 | Internal SharePoint Site | high | 6.0 | 1 | Data Breach |
| 5129 | Inadequate Training Programs | high | 6.0 | 1 | Data Breach |
| 5130 | Employee email account credentials | high | 6.0 | 1 | Data Breach |
| 5131 | Open Elastic Search Instances | high | 6.0 | 1 | Data Exposure |
| 5132 | Unauthorized Change to Website | high | 6.0 | 1 | Data Breach |
| 5133 | Compromised software via phishing | high | 6.0 | 1 | Phishing Attack |
| 5134 | Misconfigured AWS S3 storage | high | 6.0 | 1 | Data Leak |
| 5135 | Human Error (Misplaced Trust in Email Communication) | high | 6.0 | 1 | Business Email Compromise (BEC) |
| 5136 | Over-reliance on email/text-based communication without secondary validation | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 5137 | Potential compromise of routers by Chinese state-sponsored hackers | high | 6.0 | 1 | Security Concerns and Investigations |
| 5138 | Unauthorized access to payment card data | high | 6.0 | 1 | Data Breach |
| 5139 | Security flaw in Progress' MOVEit data transfer programme | high | 6.0 | 1 | Data Breach |
| 5140 | misconfigured public-facing storage/exposure of sensitive backup file | high | 6.0 | 1 | data exposure |
| 5141 | Logic error in temporary file access and download request handling | high | 6.0 | 1 | Logic Flaw / Guardrail Bypass |
| 5142 | Weak or compromised email account security | high | 6.0 | 1 | Data Breach |
| 5143 | Employee Self Service system | high | 6.0 | 1 | Data Breach |
| 5144 | alleged exploitation of parking permit system to gain unauthorized access | high | 6.0 | 1 | phishing |
| 5145 | Lack of Real-Time Email Authentication | high | 6.0 | 1 | Phishing |
| 5146 | Unsupported OS (Windows 2000, XP, Server 2003) | high | 6.0 | 1 | Security Audit Findings |
| 5147 | Unauthorized access to an employee's email account | high | 6.0 | 1 | Data Breach |
| 5148 | Inherited extension reputation, Unicode spoofing, remote phishing page | high | 6.0 | 1 | Phishing |
| 5149 | poor email filtering | high | 6.0 | 1 | phishing |
| 5150 | Employee Misconfiguration | high | 6.0 | 1 | Data Breach |
| 5151 | Email Encryption | high | 6.0 | 1 | Data Breach |
| 5152 | human error (successful phishing) | high | 6.0 | 1 | data breach |
| 5153 | Weak Password Hashing (MD5 without salt) | high | 6.0 | 1 | Data Breach |
| 5154 | Outdated Website | high | 6.0 | 1 | Data Breach |
| 5155 | Lack of Data Redaction/Validation in FOI Process | high | 6.0 | 1 | Data Breach (Unintentional Disclosure) |
| 5156 | Software used by a third-party service provider | high | 6.0 | 1 | Data Breach |
| 5157 | Unauthorized access to Microsoft 365 account | high | 6.0 | 1 | Data Breach |
| 5158 | Microsoft Exchange email servers | high | 6.0 | 1 | Data Breach |
| 5159 | Improper folder permissions on file servers | high | 6.0 | 1 | Data Breach |
| 5160 | AI-assisted coding error (unauthenticated open web directory) | high | 6.0 | 1 | Data Breach |
| 5161 | Improper handling of sensitive documents | high | 6.0 | 1 | Data Breach |
| 5162 | Lack of end-to-end encryption in standard email protocols, Absence of proper email authentication mechanisms | high | 6.0 | 1 | Business Email Compromise (BEC) |
| 5163 | File Decompression in Kernel | high | 6.0 | 1 | Vulnerability Exploit |
| 5164 | Policy workarounds | high | 6.0 | 1 | Insider Threat |
| 5165 | Weak Third-Party Compliance Standards | high | 6.0 | 1 | Data Leakage |
| 5166 | ThinkPHP, Jenkins, Hadoop YARN vulnerabilities | high | 6.0 | 1 | Botnet, DDoS |
| 5167 | Misconfiguration of AWS Application Load Balancer Authentication | high | 6.0 | 1 | Misconfiguration |
| 5168 | Data mismatch error in system logic | high | 6.0 | 1 | Data Breach (Unauthorized Access/Disclosure) |
| 5169 | Fake pop-up window | high | 6.0 | 1 | Data Breach |
| 5170 | Human trust in authentic-looking communications | high | 6.0 | 1 | Phishing (AI-enhanced) |
| 5171 | Unauthorized access to Workday payroll accounts | high | 6.0 | 1 | Data Breach |
| 5172 | Email Account and Tax Preparation Software | high | 6.0 | 1 | Data Breach |
| 5173 | Lack of oversight/guidance for opioid settlement fund allocation; flexible spending rules | high | 6.0 | 1 | Financial Misappropriation / Regulatory Non-Compliance |
| 5174 | Three additional undisclosed vulnerabilities (details not specified) | high | 6.0 | 1 | Spoofing |
| 5175 | Reused/Weak Passwords | high | 6.0 | 1 | Data Breach |
| 5176 | Human error, Credential harvesting | high | 6.0 | 1 | Data Breach |
| 5177 | Dangerous React Patterns (dangerouslySetInnerHTML near iframes) | high | 6.0 | 1 | Data Breach |
| 5178 | Unpatched flaws in TVT, Ruijie, TP-Link, ZTE devices | high | 6.0 | 1 | Botnet, DDoS |
| 5179 | Lack of rate-limiting or size restrictions on contact list uploads, enabling mass verification of phone numbers associated with WhatsApp accounts. | high | 6.0 | 1 | Privacy Vulnerability |
| 5180 | Unrelated software bugs in vendor’s trading software | high | 6.0 | 1 | Hacking, Software Bug |
| 5181 | Improper Access Controls on AWS EC2 | high | 6.0 | 1 | DDoS Attack |
| 5182 | Social engineering, lack of verification for financial transactions | high | 6.0 | 1 | Fraud |
| 5183 | multilingual social engineering gaps | high | 6.0 | 1 | phishing |
| 5184 | Insecure IoT devices | high | 6.0 | 1 | DDoS |
| 5185 | Lack of cybersecurity awareness | high | 6.0 | 1 | Scam |
| 5186 | AI Agent Memory Access | high | 6.0 | 1 | Prompt Injection |
| 5187 | Bypass of macOS Gatekeeper via direct Terminal input | high | 6.0 | 1 | Social Engineering, Malware |
| 5188 | Absence of Technical Safeguards (Encryption/De-identification) | high | 6.0 | 1 | Data Breach |
| 5189 | Compromised Office 365 Account | high | 6.0 | 1 | Data Breach |
| 5190 | Four zero-day vulnerabilities in IBM Data Risk Manager | high | 6.0 | 1 | Zero-Day Exploit |
| 5191 | Unmonitored DOM Changes (Lack of MutationObserver) | high | 6.0 | 1 | Data Breach |
| 5192 | Human Trust in Email Communication | high | 6.0 | 1 | Phishing |
| 5193 | Poor Data Handling Protocols | high | 6.0 | 1 | Data Breach |
| 5194 | Weak credential security (IT vendor account compromise) | high | 6.0 | 1 | unauthorized access |
| 5195 | Student Access to Staff Devices | high | 6.0 | 1 | Insider Threat |
| 5196 | Human trust in fake USPS parcel delivery messages | high | 6.0 | 1 | Smishing Campaign |
| 5197 | Weak SMS-based Multi-Factor Authentication (MFA) | high | 6.0 | 1 | Financial Fraud |
| 5198 | Flaw in Ivanti Endpoint Manager Mobile (EPMM) | high | 6.0 | 1 | Data Breach |
| 5199 | Improper Client Segregation | high | 6.0 | 1 | Data Breach |
| 5200 | CSP frame-src Bypass (Compromised Allowed Domains) | high | 6.0 | 1 | Data Breach |
| 5201 | Employee Malpractice | high | 6.0 | 1 | Data Breach |
| 5202 | Unencrypted device with sensitive data (despite password protection) | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5203 | Unsecured Physical Device (Password-protected laptop) | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5204 | lack of multi-factor verification | high | 6.0 | 1 | phishing |
| 5205 | Complexity in visibility and control | high | 6.0 | 1 | Data Breach |
| 5206 | Human Trust in IT Support Impersonation | high | 6.0 | 1 | Data Breach |
| 5207 | Lack of Strict Marketplace Vetting | high | 6.0 | 1 | Malware Distribution |
| 5208 | Developer oversight leading to token exposure in public repositories | high | 6.0 | 1 | credential compromise |
| 5209 | Payment gateway manipulation | high | 6.0 | 1 | Payment System Exploitation |
| 5210 | privileged access controls | high | 6.0 | 1 | insider threat |
| 5211 | Weak Access Controls in Citrix Systems | high | 6.0 | 1 | Data Breach |
| 5212 | Human Trust and Urgency | high | 6.0 | 1 | Social Engineering Scam |
| 5213 | Vulnerabilities in ticketing and access control systems | high | 6.0 | 1 | Cyberattack |
| 5214 | holiday distraction | high | 6.0 | 1 | phishing |
| 5215 | Malicious activity in open-source code repository | high | 6.0 | 1 | Supply Chain Attack |
| 5216 | Third-Party Integration (Drift Email/Salesloft) | high | 6.0 | 1 | Data Breach |
| 5217 | Absence of Document Automation/Redaction Tools | high | 6.0 | 1 | Data Leakage |
| 5218 | Unauthorized Disclosure of Surveillance Footage | high | 6.0 | 1 | Physical Security Breach |
| 5219 | Inadequate Remote Work Policies | high | 6.0 | 1 | Data Leak |
| 5220 | Poor Employee Training | high | 6.0 | 1 | Data Leak |
| 5221 | lack of multi-factor authentication (MFA) on crypto accounts | high | 6.0 | 1 | cyber theft |
| 5222 | Unauthorized access to WiFi management system | high | 6.0 | 1 | Cyber Attack |
| 5223 | Human (Email Compromise) | high | 6.0 | 1 | Data Breach |
| 5224 | Unsecured Active Directory | high | 6.0 | 1 | Data Breach |
| 5225 | Lack of Security Clearance Enforcement | high | 6.0 | 1 | Data Exposure |
| 5226 | Human Trust in Known Contacts | high | 6.0 | 1 | Phishing |
| 5227 | E-Verify's inability to verify the authenticity of presented documents | high | 6.0 | 1 | Identity Theft |
| 5228 | Trust in official app marketplaces, deceptive email outreach | high | 6.0 | 1 | Phishing |
| 5229 | Programming Update Error | high | 6.0 | 1 | Data Breach |
| 5230 | Improper backup file storage | high | 6.0 | 1 | Data Breach |
| 5231 | Zero-Day Vulnerability in Fortran GoAnywhere MFT | high | 6.0 | 1 | Data Breach |
| 5232 | Lack of Physical Security / Unencrypted Laptops | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5233 | Automated Attack | high | 6.0 | 1 | Security Breach |
| 5234 | Public Visibility of Venmo Transactions and Contacts | high | 6.0 | 1 | Data Leak |
| 5235 | Unauthorized tools | high | 6.0 | 1 | Insider Threat |
| 5236 | Compromised official Belgian Grand Prix email account | high | 6.0 | 1 | Multi-vector attack |
| 5237 | Exposed Google API key | high | 6.0 | 1 | Data Exposure |
| 5238 | Weak password encryption (unsalted MD5 and SHA-1) | high | 6.0 | 1 | Data Breach |
| 5239 | Jailbroken AI (Google Gemini) | high | 6.0 | 1 | Fraud |
| 5240 | Surveillance software | high | 6.0 | 1 | Surveillance |
| 5241 | Generic Design of Legitimate Settlement Sites | high | 6.0 | 1 | Phishing |
| 5242 | Weak Multi-Factor Authentication (MFA) on Twitter Employee Accounts | high | 6.0 | 1 | Account Takeover |
| 5243 | Physical Sensor Feeds | high | 6.0 | 1 | Market Manipulation |
| 5244 | Potentially CVE-2025-53779 (Windows Kerberos) | high | 6.0 | 1 | Data Breach |
| 5245 | Accidental Exposure | high | 6.0 | 1 | Data Breach |
| 5246 | Insufficient Contextual Risk Awareness | high | 6.0 | 1 | Social Engineering |
| 5247 | Insufficient Access Controls for High-Risk Secrets | high | 6.0 | 1 | Credential Theft |
| 5248 | Brokerage Platforms Allowing MFA via Text/Call | high | 6.0 | 1 | Financial Fraud |
| 5249 | Coding techniques to enter the Naviance student site | high | 6.0 | 1 | Data Breach |
| 5250 | Human Vulnerability (Blackmail) | high | 6.0 | 1 | Extortion, Insider Threat, Retail Theft |
| 5251 | Exploitation of Apple’s account creation process (excessive character acceptance in name fields) and security alert email system | high | 6.0 | 1 | Phishing (Callback Phishing) |
| 5252 | Data Privacy Policy | high | 6.0 | 1 | Data Disclosure |
| 5253 | Decentralized Voting/Oracle Mechanisms | high | 6.0 | 1 | Market Manipulation |
| 5254 | CVE-2026-55407 (Unbounded heap allocation in `decode_unknown_field` function) | high | 6.0 | 1 | Denial-of-Service (DoS) |
| 5255 | Potential SharePoint vulnerability (unconfirmed) | high | 6.0 | 1 | Cyberattack |
| 5256 | human error (lack of training) | high | 6.0 | 1 | phishing |
| 5257 | Weak front-end identity verification, outdated workflow designs, lack of real-time identity checks | high | 6.0 | 1 | Identity Fraud, Automated Bot Attack |
| 5258 | External System Breach (Hacking) | high | 6.0 | 1 | Data Breach |
| 5259 | Improper Access | high | 6.0 | 1 | Data Breach |
| 5260 | Unknown Zero-Day Exploit (mentioned in Telegram chats) | high | 6.0 | 1 | Distributed Denial-of-Service (DDoS) Attack |
| 5261 | Phishing/Email Compromise | high | 6.0 | 1 | Cyber Attack |
| 5262 | MOVEit file transfer program | high | 6.0 | 1 | Data Breach |
| 5263 | Discord’s expired vanity URL reuse policy | high | 6.0 | 1 | Distributed Denial of Service (DDoS) |
| 5264 | Sitting Ducks (DNS misconfiguration) | high | 6.0 | 1 | Scam / Fraudulent Push Notifications |
| 5265 | Lack of secondary verification in AI-driven DeFi systems, Insufficient security filters for obfuscated commands | high | 6.0 | 1 | AI Exploitation, Prompt Injection, Unauthorized Token Transfer |
| 5266 | User trust in brand communications; exploitation of psychological urgency and fear tactics. No technical vulnerabilities in LastPass, Bitwarden, or 1Password systems were exploited. | high | 6.0 | 1 | Phishing |
| 5267 | lack of domain registration oversight | high | 6.0 | 1 | phishing |
| 5268 | Misconfigured Docker Daemon (Exposed to Internet) | high | 6.0 | 1 | DDoS Attack |
| 5269 | Human Trust in Legitimate Breach Alerts | high | 6.0 | 1 | Phishing / Social Engineering |
| 5270 | Default Weak Passwords | high | 6.0 | 1 | Unauthorized Access |
| 5271 | Compromised Email Credentials | high | 6.0 | 1 | Data Breach |
| 5272 | DVRs/NVRs | high | 6.0 | 1 | DDoS Attack |
| 5273 | CitrixBleed | high | 6.0 | 1 | Data Breach |
| 5274 | Outdated website and aging IT infrastructure | high | 6.0 | 1 | Cybersecurity Breach |
| 5275 | Alert System Failure | high | 6.0 | 1 | Data Breach |
| 5276 | Browser and plugin vulnerabilities | high | 6.0 | 1 | Malvertising |
| 5277 | Insider Tool Abuse | high | 6.0 | 1 | Account Takeover |
| 5278 | Weak/Leaked Credentials | high | 6.0 | 1 | Data Breach |
| 5279 | Weak WordPress Administrator Credentials | high | 6.0 | 1 | Fraud |
| 5280 | Reused/Weak Passwords (Phishing) | high | 6.0 | 1 | DDoS Attack |
| 5281 | Setup Configuration | high | 6.0 | 1 | Data Leak |
| 5282 | Improper data management practices | high | 6.0 | 1 | Data Leak |
| 5283 | Exploitable Gaps in Contactless Payment Tokenization | high | 6.0 | 1 | Financial Fraud |
| 5284 | Zero-day exploit (2FA bypass) | high | 6.0 | 1 | AI-generated exploits |
| 5285 | Rapid Response to Urgent Requests from Seniors | high | 6.0 | 1 | Social Engineering |
| 5286 | Internal Employee Privileges | high | 6.0 | 1 | Data Breach |
| 5287 | Unsecured PHI on Laptop | high | 6.0 | 1 | Data Breach (Theft of Physical Device) |
| 5288 | Lack of Oversight/Enforcement of Access Controls | high | 6.0 | 1 | Data Breach |
| 5289 | Employee Portal Accounts | high | 6.0 | 1 | Data Breach |
| 5290 | AI-generated content | high | 6.0 | 1 | Phishing |
| 5291 | Weak ATM Security | high | 6.0 | 1 | Financial Fraud |
| 5292 | Lack of Device Encryption | high | 6.0 | 1 | Data Breach (Physical Theft) |
| 5293 | Abuse of Google Tag Manager (GTM) | high | 6.0 | 1 | Credit Card Skimming |
| 5294 | Public Venmo Account | high | 6.0 | 1 | Data Exposure |
| 5295 | Social engineering, user trust exploitation | high | 6.0 | 1 | Malware Campaign |
| 5296 | Unspecified vulnerability in a development server | high | 6.0 | 1 | Data Breach |
| 5297 | Gmail accounts | high | 6.0 | 1 | Data Breach |
| 5298 | Exposed Data on Website | high | 6.0 | 1 | Data Leak |
| 5299 | Unknown Oracle E-Business System Vulnerability | high | 6.0 | 1 | Cyber Attack |
| 5300 | Microsoft OAuth 2.0 Device Authorization Flow | high | 6.0 | 1 | Credential Theft |
| 5301 | On-board ports containing vehicle data | high | 6.0 | 1 | Vehicle Theft |
| 5302 | Inadvertent Technical Error | high | 6.0 | 1 | Data Breach |
| 5303 | Lack of verification for payment changes (e.g., routing/banking number updates) | high | 6.0 | 1 | Fraud/Scam |
| 5304 | Compromised email account credentials | high | 6.0 | 1 | Phishing |
| 5305 | Cloud Storage System | high | 6.0 | 1 | Data Breach |
| 5306 | Session Cookie Theft | medium | 5.0 | 1 | Security Breach |
| 5307 | CVE-2025-59489 (Unity Engine Arbitrary Code Execution) | medium | 5.0 | 1 | Vulnerability Disclosure |
| 5308 | Archived website hosted by a now-former third-party vendor | medium | 5.0 | 1 | Data Breach |
| 5309 | Reused Usernames and Passwords | medium | 5.0 | 1 | Account Compromise |
| 5310 | Browser Cache Storage | medium | 5.0 | 1 | Data Breach |
| 5311 | CVE-2025-11001 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5312 | Third-party contractor’s laptop | medium | 5.0 | 1 | Data Breach |
| 5313 | Insufficient access controls and monitoring in office suites | medium | 5.0 | 1 | Physical Security Breach, Theft |
| 5314 | Open database without authentication | medium | 5.0 | 1 | Data Breach |
| 5315 | Compromised Python SDK versions (4.87.1, 4.87.2) | medium | 5.0 | 1 | Supply Chain Attack |
| 5316 | CVE-2024-41710 | medium | 5.0 | 1 | DDoS Botnet |
| 5317 | Bug | medium | 5.0 | 1 | Data Leak |
| 5318 | Online quote system | medium | 5.0 | 1 | Data Breach |
| 5319 | Point-of-Sale (POS) Systems | medium | 5.0 | 1 | Data Breach |
| 5320 | CVE-2025-46176 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5321 | Improper Account Use | medium | 5.0 | 1 | Data Breach |
| 5322 | Inconsistent data retention policy enforcement | medium | 5.0 | 1 | Data Breach |
| 5323 | Web Page Configuration | medium | 5.0 | 1 | Data Breach |
| 5324 | Human Factor (Insider Access Abuse) | medium | 5.0 | 1 | Insider Threat |
| 5325 | Data Handling Error | medium | 5.0 | 1 | Data Breach |
| 5326 | Third-Party Vendor Security Gaps | medium | 5.0 | 1 | Data Breach |
| 5327 | Insufficient input validation | medium | 5.0 | 1 | Cross-Site Scripting (XSS) |
| 5328 | Data Mishandling | medium | 5.0 | 1 | Data Breach |
| 5329 | Mistakenly attached sensitive information to email | medium | 5.0 | 1 | Data Breach |
| 5330 | Unauthorized access to secrets during pull request process | medium | 5.0 | 1 | Unauthorized Access |
| 5331 | Insufficient Email Client-Side Sanitization | medium | 5.0 | 1 | Email Spoofing |
| 5332 | Bug in the GMX platform | medium | 5.0 | 1 | Cryptocurrency Theft |
| 5333 | CVE-2025-27915 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5334 | Ignoring Robots Exclusion Protocol | medium | 5.0 | 1 | Data Scraping |
| 5335 | Outdated Windows software (including video surveillance systems) | medium | 5.0 | 1 | Physical Burglary |
| 5336 | Typosquatting (Visual Deception) | medium | 5.0 | 1 | Phishing |
| 5337 | CVE-2026-5707 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 5338 | Unsecured Public Trello Boards | medium | 5.0 | 1 | Data Leak |
| 5339 | Supply-chain attack via npm ecosystem | medium | 5.0 | 1 | Infostealer |
| 5340 | Compromised npm maintainer account | medium | 5.0 | 1 | Supply Chain Attack |
| 5341 | OAuth Tokens | medium | 5.0 | 1 | Data Breach |
| 5342 | Progress Software's MOVEit software vulnerability | medium | 5.0 | 1 | Data Breach |
| 5343 | Misconfigured security protocols or automated password reset systems | medium | 5.0 | 1 | Potential Data Exposure |
| 5344 | Lateral Movement via Stolen Credentials | medium | 5.0 | 1 | Supply Chain Attack |
| 5345 | Instant Quote Platform | medium | 5.0 | 1 | Data Breach |
| 5346 | Open Server | medium | 5.0 | 1 | Data Exposure |
| 5347 | Service request lookup tool flaw allowing unauthorized access via bot | medium | 5.0 | 1 | Data Breach |
| 5348 | Microsoft Power Apps portal configuration error | medium | 5.0 | 1 | Data Breach |
| 5349 | Older servers | medium | 5.0 | 1 | Data Breach |
| 5350 | CVE-2025-48989 (HTTP/2 'Made You Reset' Memory Exhaustion) | medium | 5.0 | 1 | Vulnerability |
| 5351 | GiveWP WordPress Plugin Flaw | medium | 5.0 | 1 | Data Breach |
| 5352 | Progress Software's MOVEit Transfer | medium | 5.0 | 1 | Data Breach |
| 5353 | Compromised email login credentials | medium | 5.0 | 1 | Data Breach |
| 5354 | CVE-2025-13223 (V8 JavaScript engine flaw) | medium | 5.0 | 1 | Zero-day vulnerability |
| 5355 | CVE-2025-22243: Stored XSS Vulnerability in NSX Manager UI | medium | 5.0 | 1 | Vulnerability |
| 5356 | CVE-2025-22245: Stored XSS in Router Port Configurations | medium | 5.0 | 1 | Vulnerability |
| 5357 | User Account | medium | 5.0 | 1 | Data Breach |
| 5358 | Inadequate data security program | medium | 5.0 | 1 | Data Breach |
| 5359 | Remote Code Execution (RCE) in misconfigured Jenkins servers | medium | 5.0 | 1 | DDoS Botnet |
| 5360 | Out-of-Bounds Write (CWE-787) | medium | 5.0 | 1 | Denial-of-Service (DoS) |
| 5361 | Improper third-party data sharing | medium | 5.0 | 1 | Data Breach |
| 5362 | Metadata Harvesting in Salesforce | medium | 5.0 | 1 | Data Breach |
| 5363 | Improper configuration of the website | medium | 5.0 | 1 | Data Breach |
| 5364 | Unsecured Paper Files | medium | 5.0 | 1 | Data Breach |
| 5365 | Byte Pair Encoding (BPE) or WordPiece tokenization weaknesses in LLMs | medium | 5.0 | 1 | AI/ML Vulnerability Exploitation |
| 5366 | Website Programming Change | medium | 5.0 | 1 | Data Breach |
| 5367 | Weak IAM credential security, lack of multifactor authentication (MFA) | medium | 5.0 | 1 | Cryptocurrency Mining |
| 5368 | Open Database Platform | medium | 5.0 | 1 | Data Exposure |
| 5369 | CVE-2023-2533 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5370 | Inadequate data erasure protocols | medium | 5.0 | 1 | Data Handling Incident |
| 5371 | Weak SaaS Integration Controls | medium | 5.0 | 1 | Data Breach |
| 5372 | Bug in Vine | medium | 5.0 | 1 | Data Breach |
| 5373 | Trust in Urgent Requests | medium | 5.0 | 1 | Awareness Campaign |
| 5374 | Customer service software misconfiguration | medium | 5.0 | 1 | Data Breach |
| 5375 | Improper Access Control (Publicly Accessible File) | medium | 5.0 | 1 | Data Exposure / Unauthorized Access |
| 5376 | Click2Gov System | medium | 5.0 | 1 | Data Breach, Fraud |
| 5377 | Email Security | medium | 5.0 | 1 | Data Breach |
| 5378 | Internal Logging Mechanism | medium | 5.0 | 1 | Data Exposure |
| 5379 | Human error (misconfigured download link) | medium | 5.0 | 1 | Extortion |
| 5380 | CVE-2026-5709 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 5381 | Slack's link-rendering logic flaw (misinterpreting text as domains when missing spaces after punctuation) | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5382 | Design flaw in chat feature | medium | 5.0 | 1 | Data Exposure |
| 5383 | Third-party software library vulnerability | medium | 5.0 | 1 | Data Breach |
| 5384 | Trust in AI-assisted development tools | medium | 5.0 | 1 | Supply Chain Attack |
| 5385 | Software Glitch | medium | 5.0 | 1 | Data Breach |
| 5386 | Insecure Transport | medium | 5.0 | 1 | Data Leak |
| 5387 | Computer Error | medium | 5.0 | 1 | Data Breach |
| 5388 | Weak Username and Password Combinations | medium | 5.0 | 1 | Data Breach |
| 5389 | Lack of verification of driver credentials and shipping paperwork | medium | 5.0 | 1 | Cyber Cargo Theft (Fictitious Pickup) |
| 5390 | Physical Loss of Storage Device | medium | 5.0 | 1 | Data Breach |
| 5391 | Information Sharing Program | medium | 5.0 | 1 | Data Breach |
| 5392 | Privileged credentials | medium | 5.0 | 1 | Data Breach |
| 5393 | Exposed backup firewall preference files in MySonicWall cloud service | medium | 5.0 | 1 | Data Exposure |
| 5394 | Unprotected Excel Spreadsheet | medium | 5.0 | 1 | Data Breach |
| 5395 | Flaw in proxy link handling | medium | 5.0 | 1 | Information Disclosure |
| 5396 | Indirect prompt injection (IPI) | medium | 5.0 | 1 | Vulnerability Exploit |
| 5397 | Unchecked third-party access, improper configurations, over-permissioned tools | medium | 5.0 | 1 | Data Exposure |
| 5398 | Progress Software's MOVEit file transfer software | medium | 5.0 | 1 | Data Breach |
| 5399 | CVE-2025-45080 | medium | 5.0 | 1 | Vulnerability |
| 5400 | Improper Handling of Physical Records | medium | 5.0 | 1 | Data Breach |
| 5401 | CVE-2025-61882 (critical zero-day in Oracle E-Business Suite allowing remote system control without authentication) | medium | 5.0 | 1 | ransomware |
| 5402 | CVE-2025-52891 | medium | 5.0 | 1 | Denial-of-Service |
| 5403 | initramfs debug shell access during boot failures | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5404 | Typeform Vulnerability | medium | 5.0 | 1 | Data Breach |
| 5405 | Lack of Output Encoding in Email Templates | medium | 5.0 | 1 | Email Spoofing |
| 5406 | Incorrect Privacy Settings | medium | 5.0 | 1 | Data Breach |
| 5407 | Home internet connection access via VPN | medium | 5.0 | 1 | Security Breach |
| 5408 | Improper output encoding | medium | 5.0 | 1 | Cross-Site Scripting (XSS) |
| 5409 | Data Entry Error | medium | 5.0 | 1 | Data Breach |
| 5410 | CVE-2025-9242 (Out-of-bounds Write in 'iked' process) | medium | 5.0 | 1 | Vulnerability |
| 5411 | Misconfigured or unpatched hosting infrastructure | medium | 5.0 | 1 | Data Breach |
| 5412 | Poor access controls | medium | 5.0 | 1 | Data Breach |
| 5413 | CVE-2025-11002 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5414 | Database Misconfiguration | medium | 5.0 | 1 | Data Breach |
| 5415 | Incorrect fax number | medium | 5.0 | 1 | Data Breach |
| 5416 | Stored HTML Injection via Budget Name Input Field | medium | 5.0 | 1 | Email Spoofing |
| 5417 | URL Redirection | medium | 5.0 | 1 | Vulnerability Exploit |
| 5418 | CVE-2025-0520 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 5419 | Unknown Third Party Credential Leak | medium | 5.0 | 1 | Credential Stuffing |
| 5420 | Improper Access Restrictions | medium | 5.0 | 1 | Data Breach |
| 5421 | Technical Setting in Tracking Technology | medium | 5.0 | 1 | Data Breach |
| 5422 | CVE-2024-6914 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5423 | Poor physical installation of hardware | medium | 5.0 | 1 | Hardware Security Oversight |
| 5424 | Policy Violation | medium | 5.0 | 1 | Data Breach |
| 5425 | Microsoft 365 Email Account | medium | 5.0 | 1 | Data Breach |
| 5426 | User Credentials from an Unrelated Site | medium | 5.0 | 1 | Data Breach |
| 5427 | Improper truncation of payment card information on receipts | medium | 5.0 | 1 | Data Exposure |
| 5428 | Improper Data Disposal | medium | 5.0 | 1 | Data Breach |
| 5429 | Accellion file sharing platform | medium | 5.0 | 1 | Data Breach |
| 5430 | Snowflake data warehouse misconfiguration/weakness | medium | 5.0 | 1 | Data Breach |
| 5431 | CVE-2025-48384 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5432 | Failure to redact information properly | medium | 5.0 | 1 | Data Breach |
| 5433 | Accidental Sharing of Data | medium | 5.0 | 1 | Data Breach |
| 5434 | Insufficient Data Protection Measures | medium | 5.0 | 1 | Data Breach |
| 5435 | Firewall bypass | medium | 5.0 | 1 | Penetration Test Exceeding Scope |
| 5436 | Remote Access through Third-Party POS Vendor | medium | 5.0 | 1 | Payment Card Breach |
| 5437 | Weakness in Drift-Salesforce integration security | medium | 5.0 | 1 | data breach |
| 5438 | Unauthorized Biometric Data Collection | medium | 5.0 | 1 | Privacy Breach |
| 5439 | Sorting Error | medium | 5.0 | 1 | Data Breach |
| 5440 | Outdated Routers with Remote Administration Enabled | medium | 5.0 | 1 | Cyber Attack |
| 5441 | Credentials left on GitHub | medium | 5.0 | 1 | Data Breach |
| 5442 | CVE-2019-9621 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5443 | AI Algorithm Inefficiency | medium | 5.0 | 1 | System Malfunction |
| 5444 | CVE-2026-6296 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 5445 | Poor governance, lack of controls in records management, and inadequate note-taking practices | medium | 5.0 | 1 | Data Breach (Unauthorized Disclosure) |
| 5446 | Weak administrator password, lack of Multi-Factor Authentication, exposed remote access | medium | 5.0 | 1 | Ransomware |
| 5447 | Unsecured Browser-Stored Passwords/Cookies | medium | 5.0 | 1 | Data Breach |
| 5448 | Malicious JavaScript injection through API call | medium | 5.0 | 1 | Supply Chain Attack |
| 5449 | Inappropriate email handling | medium | 5.0 | 1 | Data Breach |
| 5450 | CVE-2025-22244: Stored XSS in Gateway Firewall Response Pages | medium | 5.0 | 1 | Vulnerability |
| 5451 | Printing Error | medium | 5.0 | 1 | Data Breach |
| 5452 | Patient Billing System | medium | 5.0 | 1 | Data Breach |
| 5453 | Public Exposure of Sensitive Information | medium | 5.0 | 1 | Data Breach |
| 5454 | Exposed credentials from earlier data breaches | medium | 5.0 | 1 | Credential Stuffing |
| 5455 | CVE-2025-61884 (potential, patched later) | medium | 5.0 | 1 | Data Breach |
| 5456 | Microsoft Exchange vulnerability | medium | 5.0 | 1 | Ransomware |
| 5457 | Vbulletin CMS Flaw | medium | 5.0 | 1 | Data Breach |
| 5458 | Online appointment functionality failure | medium | 5.0 | 1 | Data Leak |
| 5459 | Public-facing website | medium | 5.0 | 1 | Data Breach |
| 5460 | Computer Programming Error | medium | 5.0 | 1 | Data Breach |
| 5461 | Human Error (Inadvertent Disclosure) | medium | 5.0 | 1 | Data Breach |
| 5462 | Unsecured Vehicle | medium | 5.0 | 1 | Physical Theft |
| 5463 | Gmail 'dot trick' combined with unsanitized HTML input in Robinhood's signup flow | medium | 5.0 | 1 | Phishing Attack |
| 5464 | Outdated security measures, vulnerable CMS, weak authentication, inadequate monitoring | medium | 5.0 | 1 | SEO Poisoning |
| 5465 | Lack of access controls, Unauthorized third-party server usage | medium | 5.0 | 1 | Data Misuse, Election Interference, Unauthorized Data Access |
| 5466 | Improper website data handling | medium | 5.0 | 1 | Data Breach (Accidental Disclosure) |
| 5467 | Improper disposal of electronic devices | medium | 5.0 | 1 | Data Breach |
| 5468 | MOVEit file transfer tool vulnerability | medium | 5.0 | 1 | Data Breach |
| 5469 | Weak cybersecurity measures | medium | 5.0 | 1 | Data Breach |
| 5470 | Vulnerability in Drift application’s Salesforce integration | medium | 5.0 | 1 | third-party breach |
| 5471 | Samsung.com | medium | 5.0 | 1 | Data Breach |
| 5472 | Human Error (Mistaken Disclosure) | medium | 5.0 | 1 | Data Breach (Unauthorized Disclosure) |
| 5473 | Shared infrastructure flaw | medium | 5.0 | 1 | Data Breach |
| 5474 | CVE-2026-5708 | medium | 5.0 | 1 | Policy & Defense Initiatives |
| 5475 | Improper Disclosure of Research Funding | medium | 5.0 | 1 | Data Privacy Incident |
| 5476 | WordPress plugins | medium | 5.0 | 1 | Website Defacement |
| 5477 | Security hole in the in-house web application | medium | 5.0 | 1 | Data Breach |
| 5478 | Third-party vendor misconfiguration | medium | 5.0 | 1 | Data Breach |
| 5479 | Human error (password/authentication process manipulation) | medium | 5.0 | 1 | Cyberattack |
| 5480 | Denial of Service (DoS) | medium | 5.0 | 1 | Data Breach, Denial of Service (DoS) |
| 5481 | Email Indexing and Unsubscribe Vulnerability | medium | 5.0 | 1 | Data Exposure |
| 5482 | Improper OAuth Token Security | medium | 5.0 | 1 | Data Breach |
| 5483 | CVE-2026-24489 | medium | 5.0 | 1 | Vulnerability Exploitation |
| 5484 | Insecure transmission of payment card data | medium | 5.0 | 1 | Payment Card Breach |
| 5485 | Exposed MCP servers | low | 2.5 | 1 | Reconnaissance Scanning |
| 5486 | Easily Exploitable Vulnerabilities | low | 2.5 | 1 | Vulnerability Exploitation |
| 5487 | CVE-2025-34141 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5488 | Unencrypted Hard Drive | low | 2.5 | 1 | Data Breach |
| 5489 | Faulty fuel injector | low | 2.5 | 1 | Product Recall |
| 5490 | Exposed phone numbers from data breaches or leaked marketing databases | low | 2.5 | 1 | Phishing (SMS-based) |
| 5491 | CVE-2025-13878 | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 5492 | Missing portable data storage device | low | 2.5 | 1 | Data Breach |
| 5493 | Mobile app API | low | 2.5 | 1 | Data Breach |
| 5494 | Unsecured AWS S3 bucket (lack of password protection and encryption) | low | 2.5 | 1 | Data Breach |
| 5495 | Imperfect Process | low | 2.5 | 1 | Data Breach |
| 5496 | Weak credentials/default passwords in IoT devices | low | 2.5 | 1 | Distributed Denial of Service (DDoS) |
| 5497 | Vulnerability on older game websites | low | 2.5 | 1 | Data Breach |
| 5498 | SSH password capture | low | 2.5 | 1 | Data Breach |
| 5499 | Social Engineering (Legitimate Appearance), Dynamic Payload Updates, Stolen AI Infrastructure | low | 2.5 | 1 | Malicious Package / Data Exfiltration |
| 5500 | Third-party file transfer software | low | 2.5 | 1 | Data Breach |
| 5501 | MOVEit secure file transfer application | low | 2.5 | 1 | Data Breach |
| 5502 | Unprotected IoT Devices | low | 2.5 | 1 | IoT Device Hack |
| 5503 | CVE-2026-45494 | low | 2.5 | 1 | Vulnerability |
| 5504 | Database Configuration Error | low | 2.5 | 1 | Data Breach |
| 5505 | Malicious QR Code | low | 2.5 | 1 | Supply Chain Attack |
| 5506 | Improper Storage of Sensitive Information | low | 2.5 | 1 | Data Breach |
| 5507 | CVE-2026-7323 | low | 2.5 | 1 | Vulnerability Patch |
| 5508 | Weak message validation | low | 2.5 | 1 | Vulnerability Exploitation |
| 5509 | High Volume Access Requests | low | 2.5 | 1 | Misconfiguration |
| 5510 | CVE-2025-48651 | low | 2.5 | 1 | Vulnerability |
| 5511 | Lack of email authentication for Google AppSheet, social engineering (credential harvesting, 2FA bypass) | low | 2.5 | 1 | Phishing |
| 5512 | Unauthorized access to source code repository | low | 2.5 | 1 | Data Breach |
| 5513 | 12 new exploits targeting D-Link, Huawei, NETGEAR, TP-Link, and other devices | low | 2.5 | 1 | DDoS-for-Hire Botnet |
| 5514 | Cloned Phishing Site | low | 2.5 | 1 | Supply Chain Attack |
| 5515 | Automatic execution of tasks.json in VS Code/Cursor, lack of user interaction requirement in Cursor | low | 2.5 | 1 | Phishing, Malware, Credential Theft, Cryptocurrency Theft |
| 5516 | USBAnywhere | low | 2.5 | 1 | Remote Attack Vector |
| 5517 | Realtek routers via port 52869 | low | 2.5 | 1 | DDoS-for-Hire Botnet |
| 5518 | Publicly Accessible S3 Bucket | low | 2.5 | 1 | Data Breach |
| 5519 | Critical Issues | low | 2.5 | 1 | Vulnerability Exploitation |
| 5520 | vBulletin’s reliance on PHP’s Reflection API for its custom Model-View-Controller (MVC) framework and API system | low | 2.5 | 1 | Remote Code Execution (RCE) |
| 5521 | Known loopholes in SonicWall VPN | low | 2.5 | 1 | Exploitation of Vulnerability |
| 5522 | Server setup error | low | 2.5 | 1 | Data Breach |
| 5523 | Third-party software vendor (MOVEit) | low | 2.5 | 1 | Data Breach |
| 5524 | CVE-2025-7723 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5525 | Unauthorized access to historical emails | low | 2.5 | 1 | Data Breach |
| 5526 | CVE-2026-20029 | low | 2.5 | 1 | Information Disclosure |
| 5527 | CVE-2026-48778 | low | 2.5 | 1 | Arbitrary Code Execution |
| 5528 | Serial number extraction | low | 2.5 | 1 | Authentication Bypass |
| 5529 | Path traversal flaw in file download mechanism and guardrail bypass via prompt manipulation | low | 2.5 | 1 | Vulnerability Exploitation |
| 5530 | CVE-2025-13348 | low | 2.5 | 1 | Vulnerability |
| 5531 | Remote access to car's specialized computers | low | 2.5 | 1 | Cyberattack |
| 5532 | Improper fax transmission | low | 2.5 | 1 | Data Breach |
| 5533 | CVE-2025-1234 | low | 2.5 | 1 | DDoS |
| 5534 | CVE-2025-65606 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5535 | CVE-2024-45432 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5536 | CVE-2025-4230 | low | 2.5 | 1 | Command Injection |
| 5537 | CVE-2025-5138 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5538 | Use-after-free flaws | low | 2.5 | 1 | Data Breach |
| 5539 | CVE-2026-7320 (Audio/Video) | low | 2.5 | 1 | Vulnerability Patch |
| 5540 | CVE-2025-53506 | low | 2.5 | 1 | Denial of Service (DoS) |
| 5541 | ConnectWise ScreenConnect (CVE-2024-1709) | low | 2.5 | 1 | Ransomware |
| 5542 | Public-facing website misconfiguration | low | 2.5 | 1 | Data Breach |
| 5543 | Trust in employment process | low | 2.5 | 1 | Insider Threat |
| 5544 | Flaw in HTML sanitizer (rcube_washtml) failing to block <feImage> SVG element | low | 2.5 | 1 | Privacy Bypass |
| 5545 | OS command injection | low | 2.5 | 1 | vulnerability_exploitation |
| 5546 | GeminiJack | low | 2.5 | 1 | Zero-Click Exploit |
| 5547 | CVE-2025-55188 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5548 | CVE-2026-33825 (Insufficient access-control granularity - CWE-1220) | low | 2.5 | 1 | Privilege Escalation |
| 5549 | CVE-2025-34142 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5550 | AI assistant configuration files | low | 2.5 | 1 | Reconnaissance Scanning |
| 5551 | CVE-2025-20701 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5552 | CVE-2025-46789 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5553 | Misprinting of personal information | low | 2.5 | 1 | Data Breach |
| 5554 | Vulnerability in third-party firewall software | low | 2.5 | 1 | Data Breach |
| 5555 | Debug code in production builds causing routing failure | low | 2.5 | 1 | Vulnerability |
| 5556 | Compromised developer account, abuse of npm publishing mechanism | low | 2.5 | 1 | Supply-Chain Attack |
| 5557 | Out-of-bounds reads | low | 2.5 | 1 | Data Breach |
| 5558 | Hiring Process | low | 2.5 | 1 | State-Sponsored Hacker Infiltration |
| 5559 | Software Error | low | 2.5 | 1 | Data Breach |
| 5560 | Logic error in handling Authorization objects in ACME service, allowing improper reuse of domain validation data | low | 2.5 | 1 | Certificate Misissuance |
| 5561 | CVE-2026-2636 (Improper flag validation in CLFS.sys) | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 5562 | CVE-2026-3483 (CWE-749 - Exposed Dangerous Method) | low | 2.5 | 1 | Privilege Escalation |
| 5563 | MOVEit file transfer program vulnerability | low | 2.5 | 1 | Data Breach |
| 5564 | CVE-2026-20803 | low | 2.5 | 1 | Elevation of Privilege |
| 5565 | CVE-2026-7322 | low | 2.5 | 1 | Vulnerability Patch |
| 5566 | CVE-Unassigned (ASLR Bypass via NSKeyedArchiver Serialization Pointer Leak) | low | 2.5 | 1 | Vulnerability Disclosure |
| 5567 | Critical Telnet vulnerability allowing unauthorized access | low | 2.5 | 1 | Vulnerability Exploitation |
| 5568 | Phishing Susceptibility | low | 2.5 | 1 | Security Awareness |
| 5569 | Improper link resolution in Windows Update Stack (CVE-2025-21204) | low | 2.5 | 1 | Privilege Escalation |
| 5570 | Psychological manipulation (urgency, stress, perceived authority) | low | 2.5 | 1 | Phishing/Scam |
| 5571 | Lack of Backup Procedure | low | 2.5 | 1 | Data Loss |
| 5572 | CVE-2025-3699 | low | 2.5 | 1 | Vulnerability |
| 5573 | CVE-2026-20841 (CWE-77: Command Injection) | low | 2.5 | 1 | Remote Code Execution (RCE) |
| 5574 | CVE-2026-20805 | low | 2.5 | 1 | Information Disclosure |
| 5575 | Cloud Storage Misconfiguration | low | 2.5 | 1 | Misconfiguration |
| 5576 | Vulnerability in data storage system | low | 2.5 | 1 | Data Breach |
| 5577 | CVE-2025-34140 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5578 | Exposed RDP server | low | 2.5 | 1 | Ransomware |
| 5579 | CVE-2026-8927 | low | 2.5 | 1 | Vulnerability Disclosure |
| 5580 | Shared File Location | low | 2.5 | 1 | Data Breach |
| 5581 | External control of file paths | low | 2.5 | 1 | Data Breach |
| 5582 | Printing Software Vulnerability | low | 2.5 | 1 | Data Breach |
| 5583 | Stack-based buffer overflow | low | 2.5 | 1 | Vulnerability Exploitation |
| 5584 | Data Security Vulnerabilities | low | 2.5 | 1 | Data Security Vulnerability |
| 5585 | Previously undetected vulnerability in the Productivity Commission's website | low | 2.5 | 1 | Email Spoofing |
| 5586 | CVE-2025-59718 | low | 2.5 | 1 | Authentication Bypass |
| 5587 | Weak cybersecurity defenses and high AI-driven automation in attacks | low | 2.5 | 1 | botnets |
| 5588 | Stored XSS in Zimbra Classic Web Client | low | 2.5 | 1 | Stored Cross-Site Scripting (XSS) |
| 5589 | CVE-2026-32185 | low | 2.5 | 1 | Spoofing |
| 5590 | CVE-2025-24091 | low | 2.5 | 1 | Denial of Service (DoS) |
| 5591 | DMARC authentication bypass, trusted infrastructure abuse | low | 2.5 | 1 | Phishing |
| 5592 | human_error | low | 2.5 | 1 | data_breach |
| 5593 | Accidental Disclosure | low | 2.5 | 1 | Data Breach |
| 5594 | Bug introduced during an update of the email system | low | 2.5 | 1 | Data Leak |
| 5595 | Vendor Service (Accellion) | low | 2.5 | 1 | Data Breach |
| 5596 | CVE-2026-20824 | low | 2.5 | 1 | Security Feature Bypass |
| 5597 | XSS in *Software Acquisition Guide: Supplier Response Web Tool* | low | 2.5 | 1 | Vulnerability |
| 5598 | CVE-2026-3008 (String injection in FindInFiles functionality) | low | 2.5 | 1 | Vulnerability |
| 5599 | Unspecified | low | 2.5 | 1 | Phishing |
| 5600 | CVE-2026-23869 (Deserialization of untrusted data - CWE-502, Uncontrolled resource consumption - CWE-400) | low | 2.5 | 1 | Denial of Service (DoS) |
| 5601 | CVE-2024-22774 (Uncontrolled search path element) | low | 2.5 | 1 | Privilege Escalation |
| 5602 | Obsolete servers exposed to the internet | low | 2.5 | 1 | Cyberattack |
| 5603 | Hard-coded secret values | low | 2.5 | 1 | Vulnerability Exploitation |
| 5604 | CVE-2025-7724 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5605 | Misconfigured PAM (pam_exec module) | low | 2.5 | 1 | Backdoor |
| 5606 | Memory leak in embedded JavaScript engine | low | 2.5 | 1 | Resource Exhaustion |
| 5607 | CVE-2025-5601 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5608 | CVE-2025-34028 | low | 2.5 | 1 | Path Traversal Vulnerability |
| 5609 | CVE-2025-5678 | low | 2.5 | 1 | DDoS |
| 5610 | CWE-400 | low | 2.5 | 1 | Uncontrolled Resource Consumption |
| 5611 | Vulnerability in the outage app | low | 2.5 | 1 | Data Breach |
| 5612 | Mailing Processes | low | 2.5 | 1 | Data Breach |
| 5613 | CVE-2025-4563 | low | 2.5 | 1 | Vulnerability |
| 5614 | Hardcoded trust exception in authentication flow (2FA bypass) | low | 2.5 | 1 | Zero-Day Exploit |
| 5615 | CVE-2026-11586 | low | 2.5 | 1 | Vulnerability Disclosure |
| 5616 | CVE-2026-45492 | low | 2.5 | 1 | Vulnerability |
| 5617 | Improper conversation/message ID verification | low | 2.5 | 1 | Vulnerability Exploitation |
| 5618 | Misconfigured/unsecured server | low | 2.5 | 1 | Phishing (AiTM) |
| 5619 | CVE-2026-0227 | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 5620 | CVE-2025-32756 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5621 | CVE-2025-59719 | low | 2.5 | 1 | Authentication Bypass |
| 5622 | CVE-2025-1087 | low | 2.5 | 1 | Template Injection |
| 5623 | MOVEit Transfer tool vulnerabilities | low | 2.5 | 1 | Data Breach |
| 5624 | CVE-2026-35273 (CVSS 9.8, unauthenticated remote code execution in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62) | low | 2.5 | 1 | Data Breach |
| 5625 | Exploit in Trinity wallet app | low | 2.5 | 1 | Cryptocurrency Wallet Exploit |
| 5626 | unpatched_software | low | 2.5 | 1 | data_breach |
| 5627 | Authentication Flaw in cPanel Login Mechanisms | low | 2.5 | 1 | Authentication Vulnerability |
| 5628 | Website Search Function | low | 2.5 | 1 | Data Breach |
| 5629 | CVE-2025-24016 (Unsafe Deserialization) | low | 2.5 | 1 | Botnet Exploitation |
| 5630 | CVE-2026-45502 | low | 2.5 | 1 | SSRF (Server-Side Request Forgery) |
| 5631 | Secure Email Account | low | 2.5 | 1 | Data Breach |
| 5632 | CVE-2026-7344 (Accessibility) | low | 2.5 | 1 | Vulnerability Patch |
| 5633 | CVE-2026-45586 (Improper Link Resolution - CWE-59) | low | 2.5 | 1 | Privilege Escalation |
| 5634 | Unsecured FTP Server | low | 2.5 | 1 | Data Breach |
| 5635 | CVE-2024-45431 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5636 | MOVEit server vulnerability | low | 2.5 | 1 | Data Breach |
| 5637 | Vendor's Software Flaw | low | 2.5 | 1 | Data Breach |
| 5638 | zero-click vulnerabilities | low | 2.5 | 1 | vulnerability_exploitation |
| 5639 | Improperly secured GitHub secrets (long-lived PyPI tokens stored in workflows) | low | 2.5 | 1 | supply chain attack |
| 5640 | Mailing Label Printing Error | low | 2.5 | 1 | Data Breach |
| 5641 | CVE-2025-2761 | low | 2.5 | 1 | Software Vulnerability |
| 5642 | Insufficient policy enforcement in the WebView tag | low | 2.5 | 1 | Security Bypass |
| 5643 | Improper Access Control in fepblue Mobile App | low | 2.5 | 1 | Data Breach (Unauthorized Access) |
| 5644 | Compromised internal operations wallet | low | 2.5 | 1 | Security Breach |
| 5645 | CVE-2026-23600 | low | 2.5 | 1 | Authentication Bypass |
| 5646 | Misconfigured permissions | low | 2.5 | 1 | Cyber Breach |
| 5647 | CVE-2025-9101 | low | 2.5 | 1 | DDoS |
| 5648 | CVE-2025-50054 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5649 | Vulnerability in a third-party application | low | 2.5 | 1 | Unauthorized Access |
| 5650 | CVE-2026-9079 | low | 2.5 | 1 | Vulnerability Disclosure |
| 5651 | Lack of authentication on C2 panel, weak SSH credentials, exposed services (RDP, SMB, WinRM) | low | 2.5 | 1 | Credential Stuffing |
| 5652 | Insecure remote administration access | low | 2.5 | 1 | Security Breach |
| 5653 | Exposed .env files | low | 2.5 | 1 | Reconnaissance Scanning |
| 5654 | Fake Firmware | low | 2.5 | 1 | Supply Chain Attack |
| 5655 | Identical authentication certificates, prolonged certificate validity (10 years), inadequate network access controls | low | 2.5 | 1 | Data Breach, Unauthorised Transactions, Malware Infection |
| 5656 | Incompatible resource access | low | 2.5 | 1 | Data Breach |
| 5657 | CVE-2026-45495 | low | 2.5 | 1 | Vulnerability |
| 5658 | Unauthorized physical access | low | 2.5 | 1 | Physical and Logical Security Breach |
| 5659 | CVE-2026-40176 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5660 | Fortinet EMS (CVE-2023-48788) | low | 2.5 | 1 | Ransomware |
| 5661 | Stolen GitHub credentials | low | 2.5 | 1 | Source Code Theft |
| 5662 | Unpatched firmware in home routers/cameras | low | 2.5 | 1 | Distributed Denial of Service (DDoS) |
| 5663 | CVE-2026-9545 | low | 2.5 | 1 | Vulnerability Disclosure |
| 5664 | Evasion of rate-limiting defenses via 'low and slow' fragmentation | low | 2.5 | 1 | DDoS |
| 5665 | Arbitrary File Upload (CVE-2025-64374) | low | 2.5 | 1 | Vulnerability Exploitation |
| 5666 | Malformed ZIP archives evading security tools, native Windows unarchiving utility exploitation | low | 2.5 | 1 | Malware Campaign |
| 5667 | CVE-2026-7363 (Canvas) | low | 2.5 | 1 | Vulnerability Patch |
| 5668 | Vulnerabilities in Cleo's platform | low | 2.5 | 1 | Data Breach |
| 5669 | CVE-2025-50165 (Uninitialized function pointer dereference in WindowsCodecs.dll) | low | 2.5 | 1 | Remote Code Execution (RCE) |
| 5670 | Unattended Vehicle | low | 2.5 | 1 | Data Breach |
| 5671 | CVE-2025-54957 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5672 | Rowhammer | low | 2.5 | 1 | Vulnerability Exploitation |
| 5673 | Lack of Awareness (pre-training) | low | 2.5 | 1 | Security Awareness |
| 5674 | Unsecured Computer Server | low | 2.5 | 1 | Data Breach |
| 5675 | CVE-2025-6029 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5676 | Exposed .env file with database credentials | low | 2.5 | 1 | Data Exposure, Potential DoS Attack |
| 5677 | CVE-2026-48770 | low | 2.5 | 1 | Arbitrary Code Execution |
| 5678 | Data Transfer Error | low | 2.5 | 1 | Data Breach |
| 5679 | Lack of phishing controls, Unrestricted RMM tool usage, Insufficient EDR monitoring | low | 2.5 | 1 | Phishing, Social Engineering, RMM Abuse |
| 5680 | Improper error handling | low | 2.5 | 1 | Misconfiguration |
| 5681 | CVE-2025-24813 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5682 | CVE-2025-36537 | low | 2.5 | 1 | Vulnerability |
| 5683 | Unauthorized network access | low | 2.5 | 1 | Physical and Logical Security Breach |
| 5684 | Misconfigured web application firewall in cloud infrastructure | low | 2.5 | 1 | Data Breach |
| 5685 | MOVEit Transfer tool vulnerability | low | 2.5 | 1 | Data Breach |
| 5686 | CVE-2026-11856 | low | 2.5 | 1 | Vulnerability Disclosure |
| 5687 | Damaged mailing | low | 2.5 | 1 | Data Breach |
| 5688 | CVE-2025-2760 | low | 2.5 | 1 | Software Vulnerability |
| 5689 | CVE-2026-7324 | low | 2.5 | 1 | Vulnerability Patch |
| 5690 | Unsecured Storage of Usernames and Passwords | low | 2.5 | 1 | Data Breach |
| 5691 | CVE-2026-48800 | low | 2.5 | 1 | Arbitrary Code Execution |
| 5692 | Unauthenticated LLM endpoints | low | 2.5 | 1 | Reconnaissance Scanning |
| 5693 | Device Tracking Vulnerabilities | low | 2.5 | 1 | Surveillance Investigation |
| 5694 | Reflected cross site scripting (XSS) | low | 2.5 | 1 | Vulnerability Exploitation |
| 5695 | CVE-2025-26147 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5696 | Legacy /sse endpoints | low | 2.5 | 1 | Reconnaissance Scanning |
| 5697 | Programming Code Error | low | 2.5 | 1 | Data Breach |
| 5698 | CVE-2026-2441 (use-after-free in CSS component) | low | 2.5 | 1 | Zero-Day Vulnerability |
| 5699 | CVE-2025-49464 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5700 | Shared authentication systems, privileged access management gaps | low | 2.5 | 1 | Credential Exposure |
| 5701 | CVE-2026-7343 (Views) | low | 2.5 | 1 | Vulnerability Patch |
| 5702 | OAuth consent prompts, user behavior | low | 2.5 | 1 | Phishing |
| 5703 | CVE-2026-7361 (iOS) | low | 2.5 | 1 | Vulnerability Patch |
| 5704 | Social engineering, malware-laced coding assignments | low | 2.5 | 1 | Cryptocurrency Theft |
| 5705 | Unmonitored lateral movement | low | 2.5 | 1 | Cyber Breach |
| 5706 | Unpatched IoT/ARC processor vulnerabilities | low | 2.5 | 1 | DDoS Attack |
| 5707 | Insufficient intrusion detection | low | 2.5 | 1 | Ransomware |
| 5708 | Credentials obtained from another website | low | 2.5 | 1 | Data Breach |
| 5709 | Flaw in ASUS DriverHub | low | 2.5 | 1 | Vulnerability Exploit |
| 5710 | CVE-2026-40261 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5711 | CVE-2025-7206 | low | 2.5 | 1 | Vulnerability |
| 5712 | Zero-day vulnerability in Oracle’s eBusiness Suite | low | 2.5 | 1 | Data Breach |
| 5713 | Barracuda Networks email application vulnerability | low | 2.5 | 1 | Data Breach |
| 5714 | Admin password bypass | low | 2.5 | 1 | Authentication Bypass |
| 5715 | Heap-based buffer overflows | low | 2.5 | 1 | Data Breach |
| 5716 | Writable MFGSTAT.zip file with incorrect permissions | low | 2.5 | 1 | Vulnerability Exploitation |
| 5717 | Low entropy in database metadata retrieval | low | 2.5 | 1 | Privacy Vulnerability |
| 5718 | CVE-2024-11857 | low | 2.5 | 1 | Vulnerability |
| 5719 | Web Server | low | 2.5 | 1 | Data Breach |
| 5720 | Human psychology (trust in job applications), abuse of trusted cloud infrastructure (AWS EC2/S3) | low | 2.5 | 1 | Phishing/Social Engineering, Malware Delivery |
| 5721 | Lack of proper access controls and oversight in AI systems | low | 2.5 | 1 | Data Breach |
| 5722 | Android APK vulnerabilities | low | 2.5 | 1 | DDoS Attack |
| 5723 | Compromised IoT devices (routers, IP cameras, digital video recorders) | low | 2.5 | 1 | DDoS Attack |
| 5724 | CVE-2025-37103 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5725 | Remote Code Execution (RCE) in auto-updater software | low | 2.5 | 1 | Vulnerability Exploitation |
| 5726 | Lack of contextual awareness in AI systems | low | 2.5 | 1 | AI-related data exposure |
| 5727 | X11 clipboard functionality | low | 2.5 | 1 | Malware |
| 5728 | CVE-2025-12420 | low | 2.5 | 1 | Privilege Escalation |
| 5729 | CVE-2025-27387 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5730 | Unmonitored networks | low | 2.5 | 1 | Ransomware |
| 5731 | Insufficient file authentication in the updater mechanism | low | 2.5 | 1 | Software Vulnerability |
| 5732 | Counterfeit Hardware | low | 2.5 | 1 | Supply Chain Attack |
| 5733 | CVE-2025-34143 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5734 | CVE-2024-45434 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5735 | Poor password practices | low | 2.5 | 1 | Ransomware |
| 5736 | Weaknesses in cloud security, insufficient encryption, inadequate identity management, lack of network segmentation | low | 2.5 | 1 | AI System Targeting, Cloud Infrastructure Exploitation |
| 5737 | CVE-2025-49825 | low | 2.5 | 1 | Vulnerability Exploit |
| 5738 | Temporary API code misconfiguration | low | 2.5 | 1 | Data Breach |
| 5739 | PHP Exploit in MyBB Codebase | low | 2.5 | 1 | Infrastructure Disruption |
| 5740 | Unpatched vulnerabilities (31% of breaches) | low | 2.5 | 1 | data_breach |
| 5741 | Unsecured attic access, potential food attractants | low | 2.5 | 1 | Physical Intrusion (Non-Cyber) |
| 5742 | CVE-2024-45433 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5743 | CVE-2025-22234 | low | 2.5 | 1 | Vulnerability Exploitation |
| 5744 | CVE-2026-26127 (Out-of-bounds read weakness, CWE-125) | low | 2.5 | 1 | Denial-of-Service (DoS) |
| 5745 | DNS misconfiguration (lame delegation), browser notification permissions | low | 2.5 | 1 | Push-Notification Scam |