🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
Search: Time Range:
Sources: Clear All Filters
378,232+
CVEs Tracked
378,232
Exploit Intel
358,051
EPSS Scored
5,202
CISA KEV
2,698
Metasploit Modules
30,385
ExploitDB Entries
61
MITRE ATT&CK Maps
0
Actively Exploited
0
CISA KEV
1
PoC Available
0
Zero-Days
0
Recent Discoveries
0
Most Mentioned

CVE Severity Distribution (Last 30 Days)

Found 1 CVEs in the last 30 days.

CVE-2026-9586 CRITICAL CVSS: 9.8 EPSS: 11.8% VulnCheck KEV PoC Available CWE-89 T1190
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Published: 2026-07-17
Mentioned in 4 article(s):
Sangoma Switchvox Vulnerabilities Exploited in the Wild
SecurityWeek
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
BleepingComputer
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
The Hacker News
CVE-2026-9586 - Sangoma Switchvox SQL Injection Vulnerability
Recent KEV Entries