VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 218 of 1202 · EPSS data 2026.08.08
ReviewHigh
CVE-2026-63746

surrealdb

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63740

surrealdb

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-level permissions should deny by exploiting incorrect index handling during permission filtering.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63739

surrealdb

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63737

surrealdb

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack overflow during query processing and aborting the entire process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63735

surrealdb

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in other tenants by specifying the target scope in the URL path, reading sensitive data or triggering unintended operations.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16247

Bizerba SE & Co. KG _connect.BRAIN

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. Starting with _connect.BRAIN 5.06, the setup no longer executes this tool.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16246

Bizerba SE & Co. KG BRAIN2

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. Starting with BRAIN2 3.09, the setup no longer executes this tool. However, the optional component Bizerba ScriptService still executes it. Bizerba ScriptService is being deprecated and will no longer be included starting with BRAIN2 version 3.11.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14448

MB connect line mbCONNECT24, mymbCONNECT24, myREX24V2

An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in an OS command. This can result in a total loss of confidentiality, availability and integrity.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16242

Red Hat multicluster engine for Kubernetes 2.1, multicluster engine for Kubernetes 2.11.0, multicluster engine for Kubernetes 2.17

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13577

CROMEDOME Dancer2

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9833

Tag Groups is the Advanced Way to Display Your Taxonomy Terms

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into following a crafted link.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-6656

DRSTEVE Crypt::Password

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16235

DRSTEVE Crypt::Password

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13147

Kirki

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13142

Social Login, Passkeys, Magic Link & Email OTP

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

The CVSS severity warrants an early asset and exposure review.