VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 204 of 1202 · EPSS data 2026.08.08
ReviewCritical
CVE-2025-66390

the affected product

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header). NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavio...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16445

Red Hat Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 10

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16412

Mozilla Firefox, Thunderbird, firefox

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16411

Mozilla Firefox, Thunderbird, firefox

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16405

Mozilla Firefox, Thunderbird, firefox

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.