VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 352 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-15701

Totolink NR1800X

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15428

TP-Link Systems Inc. Archer VX1800v v1, archer vx1800v firmware, archer vx1800v

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15427

TP-Link Systems Inc. Archer VX1800v v1, archer vx1800v firmware, archer vx1800v

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9636

Rockwell Automation ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, 1756-EN4TR

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9292

Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9128

Rockwell Automation Studio 5000 Logix Designer

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9127

Rockwell Automation Studio 5000 Logix Designer

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-62644

Roundcube Webmail, webmail

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-62643

Roundcube Webmail, webmail

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-60082

HMBRAND DBI

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-60081

HMBRAND DBI::ProfileData

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59841

Fortinet FortiSIEMWindowsAgent, fortisiem, windows

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-59836

Fortinet FortiClientEMS, forticlientems

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

The CVSS severity warrants an early asset and exposure review.