VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 12 of 1178
ReviewHigh
CVE-2026-9593

Endress+Hauser FDI Package library

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4793

Synology Synology Assistant

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18589

Wavlink WL-NU516U1

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18588

Wavlink WL-NU516U1

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16572

LogMyTrip

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16539

sm page duplicator

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16534

Import and export users and customers

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16532

Link Library

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

The CVSS severity warrants an early asset and exposure review.