VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,695 CVE recordsPage 462 of 1313 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-12168

Little Orbit GameFirst Anti-Cheat

An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12167

Little Orbit GameFirst Anti-Cheat

The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that lacks appropriate access restrictions.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-4767

TR7 Cyber ​​Defense Inc. WAF-ASP

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-5524

Divi Engine Divi Form Builder

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-base...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58652

openwrt luci-app-travelmate, travelmate

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads the raw UCI 'script' and 'script_args' values and executes the configured path when the captive-portal auto-login branch (f_check() in travelmate-functions.sh) is reached. An attacker with delegated...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57765

Levelfourdevelopment WP EasyCart

CVE-2026-57765 affects Levelfourdevelopment WP EasyCart. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57761

BlueAstralThemes SEOWP

CVE-2026-57761 affects BlueAstralThemes SEOWP. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57759

Metagauss ProfileGrid

CVE-2026-57759 affects Metagauss ProfileGrid. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57756

友人a丶 nicen-localize-image

CVE-2026-57756 affects 友人a丶 nicen-localize-image. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.