VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 26 of 1178 · EPSS data 2026.08.04
ReviewHigh
CVE-2026-43832

tbc

Full details and mitigation steps are currently restricted and will be published at a later date.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-43831

tbc

Full details and mitigation steps are currently restricted and will be published at a later date.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-43830

tbc

Full details and mitigation steps are currently restricted and will be published at a later date.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-43829

tbc

Full details and mitigation steps are currently restricted and will be published at a later date.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18157

RedHatInsights yggdrasil-worker-package-manager, Red Hat Enterprise Linux 10

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14541

Google mcp-toolbox

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14540

Google mcp-toolbox

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14537

Google mcp-toolbox

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66720

MZ Automation GmbH libiec61850

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to crash and resulting in a denial-of-service condition.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66421

tugcantopaloglu openclaw-dashboard

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated unsanitized into innerHTML on the default landing page, allowing theft of session tokens and unautho...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66420

Ylianst MeshCentral

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66369

MZ Automation GmbH libiec61850

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66364

MZ Automation GmbH libiec61850

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66360

MZ Automation GmbH libiec61850

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service condition.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65423

o6 Automation open62541

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

The CVSS severity warrants an early asset and exposure review.