VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 144 of 1202 · EPSS data 2026.08.07
ReviewHigh
CVE-2026-65015

n8n-io n8n

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization verification.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-61391

Hikvision DS-2CD Series, DS-2DE Series

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-61390

Hikvision DS-2CD Series, DS-2DE Series

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4773

Magarsus Consulting Ltd. Co. IDM-MFA

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44190

Red Hat Red Hat Ansible Automation Platform 2

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44189

Red Hat Red Hat Ansible Automation Platform 2

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14551

servereye GmbH servereye Windows Agent (Sensorhub)

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions. The service subsequently executes the utility Up...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63047

joomdonation.com Events Booking extension for Joomla

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-3821

SMCI X14DBG-DAP, X14DBI

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12987

Events Manager

The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unauthenticated attacker can read arbitrary database data (e.g. user password hashes, secret keys) when the booking is later loaded.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12968

Product Addons and Product Options With Custom Fields

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15802

Chimpstudio WP Foodbakery

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-56844

Veeam Backup and Replication

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

The CVSS severity warrants an early asset and exposure review.