VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,449 CVE recordsPage 444 of 1297 · EPSS data 2026.07.28
ReviewCritical
CVE-2026-56004

openSUSE buildservice

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55113

Ubiquiti Inc UniFi Talk Application, unifi talk application

A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55112

Ubiquiti Inc Dream Machines, Dream Wall, Dream Routers

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.

The CVSS severity warrants an early asset and exposure review.