VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 24 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-15722

Red Hat Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11770

Red Hat Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-10079

Red Hat Red Hat Advanced Cluster Security 4

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65313

ANDRITZ HIPASE-250, 250 SCALA

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65310

ANDRITZ HIPASE-250, 250 SCALA

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65309

ANDRITZ HIPASE-250, 250 SCALA

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18452

Rich Source DMS+ (Non-Mobile)

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16236

realtyna Realtyna Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15258

Product Feed Manager For WooCommerce

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15048

Geeky Bot

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14930

JS Help Desk

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14919

ShopMonitor.io

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14830

FlxWoo

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14483

realtyna Realtyna Organic IDX plugin + WPL Real Estate

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installations. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The WPL I/O service endpoint is registered on the public...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14333

Demi

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

The CVSS severity warrants an early asset and exposure review.