VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 405 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-56001

X.Org libXfont2, libxfont

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-56000

X.Org xorg-x11-server, xwayland, x server

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55999

X.Org xorg-server, xwayland, x server

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-9695

Dassault Systèmes DELMIA Apriso

An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12378

Appointment Booking Calendar Plugin and Scheduling Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to achieve remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9700

joe007 Eventer

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57895

Fuji Electric Co., Ltd. Pupsman

Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folder, which results in arbitrary code execution with SYSTEM privilege

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-56437

Fuji Electric Co., Ltd. Pupsman

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.

The CVSS severity warrants an early asset and exposure review.