VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 135 of 1202 · EPSS data 2026.08.07
ReviewHigh
CVE-2026-64611

Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16745

Red Hat Red Hat OpenShift AI (RHOAI)

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65758

tassos.gr Convert Forms extension for Joomla

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65757

regularlabs.com Modules Anywhere extension for Joomla

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65755

regularlabs.com Articles Anywhere extension for Joomla, Users Anywhere extension for Joomla

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-65431

regularlabs.com GeoIP extension for Joomla

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-64876

regularlabs.com GeoIP extension for Joomla

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-64799

regularlabs.com Articles Anywhere Pro extension for Joomla, Users Anywhere Pro extension for Joomla

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15017

mdjm MDJM Event Management

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_e...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-15015

cascadiawebservices MountDev AI MCP Connector for WordPress

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full administrator-equivalent access to the plugin's MCP tool surface and all exposed WordPress content, users, and options. This is exploitable by combining the publicly accessible Dynamic Client Registratio...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-15011

emarket-design Customer Support Ticket System & Helpdesk

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated attackers to invoke arbitrary parameterless PHP functions, which can be used to disrupt site functionality or expose sensitive information. The required nonce is publicly emitted via wp_localize_script whenever the plugin's [emd_form] shortcode is rendered on any public-facing...

The CVSS severity warrants an early asset and exposure review.