VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 34 of 1178 · EPSS data 2026.08.04
ReviewHigh
CVE-2026-54365

Gladinet CentreStack

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with attacker-controlled credentials and create arbitrary directories on the server file...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54363

Gladinet CentreStack

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Attackers can use the hardcoded key to craft valid x-glad-auth headers and call privileged API endpoints such as acquiretenantbackuptoken to obtain a domain administrator IdentityTicket, enabling a complete unauthenticated remote code execution chain.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-47876

VMware Cloud Foundation, vSphere Foundation, ESX

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41703

VMware Cloud Foundation, vSphere Foundation, ESX

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18381

Red Hat Cost Management Metrics Operator

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18378

Red Hat Cost Management Metrics Operator

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17544

PHP Group PHP

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17543

PHP Group PHP

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15397

wpswings Subscriptions for WooCommerce

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22622

Eaton PADM

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22621

Eaton PADM

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22620

Eaton PADM

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18363

Enhancesoft LLC osTicket

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able to obtain a valid password reset token could reuse it to perform an unauthorised password reset...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18361

dfir-iris iris-web

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18360

dfir-iris iris-web

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

The CVSS severity warrants an early asset and exposure review.