VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 477 of 1316 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-20191

Cisco Cisco Catalyst Center

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-58127

Hyland PACSgear MediaWriter, pacsgear

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs a...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-58126

Hyland PACSgear PACS Scan, pacsgear

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57517

Control Web Panel

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24270

NVIDIA AIStore framework

NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24260

NVIDIA Container Toolkit, GPU Operator

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24251

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24250

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24249

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24248

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24247

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24246

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24245

NVIDIA Megatron-Bridge, nemo megatron bridge, linux kernel

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.