VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 494 of 1316 · EPSS data 2026.08.12
ReviewHigh
CVE-2025-71349

picklescan

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using trace.Trace.run in the reduce method to achieve arbitrary code execution when pickle.load processes the file.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-58449

neuml txtai

txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no TOKEN configured (authentication is opt-in, so all endpoints are unauthenticated) and the index is configured writable, a remote attacker can set function to an arbitrary callable such as subprocess.getoutput, achieving remote code execution as the server process during reindexing. Exploitation requires those deployment...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58448

YunaiV yudao-cloud

yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the @PreAuthorize annotation. Attackers can query any process-instance identifier through the unguarded GET endpoint to read sensitive workflow data including submitted form variables, approver identities, approval and rejection comments, and process BPMN XML without ownership or tenant party verification.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58447

iv-org Invidious

Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the playlist endpoint. Attackers can obtain per-video index values from the public playlist JSON API and submit them to the playlist video deletion endpoint without ownership validation, permanently removing videos from playlists they do not own.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57585

msgpack msgpack-python, messagepack

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-52868

OFFIS DICOM DCMTK Toolkit

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-52196

the affected product

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416f28 component

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-50254

OFFIS DICOM DCMTK Toolkit

An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-50003

OFFIS DICOM DCMTK Toolkit

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-37106

the affected product

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self-registration being enabled without the administrators knowledge.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35505

OFFIS DICOM DCMTK Toolkit

An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44628

OFFIS DICOM DCMTK Toolkit

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13207

Frangoteam FUXA SCADA/HMI

FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticated requests to access protected endpoints by prefixing paths with dot-segments such as /api/./users, /api/./roles, and /api/project/../users. These requests bypass authentication checks and return sensitive user and role data without credentials.

The CVSS severity warrants an early asset and exposure review.