VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,946 CVE recordsPage 288 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-56454

HCL Software DFXAnalytics, dfxanalytics

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-56453

HCL Software DFXAnalytics, dfxanalytics

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35142

HCL Software DFXAnalytics, dfxanalytics

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35140

HCL Software DFXAnalytics, dfxanalytics

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63306

stoatchat

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63305

WWBN AVideo

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS commands as the web-server user.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63304

WWBN AVideo

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted codeToExec payload can break out of the single-quoted grep context and execute arbitrary OS commands as the web-server user.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11386

Canonical ubuntu-pro-client (ubuntu-advantage-tools), Ubuntu 26.04 LTS, Ubuntu 24.04 LTS

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the directives.suites[] and directives.aptURL fields. Because the client utilizes Python's str.format() to write these files without performing escaping, validation, or newline character filtering, a malicious or tampered contract response containing embedded newline (\n) characters can success...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-71388

stoatchat

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can send arbitrary messages to the channel, bypassing channel permissions and impersonating a bot or webhook. Fixed in 20250210-1 (0.8.2).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-71377

stoatchat

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35149

HCL Software DFXServer, dfx server

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35147

HCL Software DFXServer, dfx server

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-49900

X-Rite MA-T6

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-49899

X-Rite MA-T6

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22752

Spring Security Spring Authorization Server

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

The CVSS severity warrants an early asset and exposure review.