VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,695 CVE recordsPage 466 of 1313 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-27425

Themesuite Automotive Listings

CVE-2026-27425 affects Themesuite Automotive Listings. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-27419

Zozothemes Zegen

CVE-2026-27419 affects Zozothemes Zegen. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27414

Fuelthemes Werkstatt

CVE-2026-27414 affects Fuelthemes Werkstatt. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27408

imithemes NativeChurch

CVE-2026-27408 affects imithemes NativeChurch. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27404

Designthemes LMS

CVE-2026-27404 affects Designthemes LMS. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27060

Repute Infosystems ARMember Premium

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium: from n/a before 7.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11946

open62541 project / o6 Automation GmbH open62541

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4,...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-69153

designthemes Trendy Travel

CVE-2025-69153 affects designthemes Trendy Travel. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.