VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,982 CVE recordsPage 536 of 1333 · EPSS data 2026.08.13
ReviewCritical
CVE-2026-54820

Crocoblock. Jetimpex Inc. JetBooking

CVE-2026-54820 affects Crocoblock. Jetimpex Inc. JetBooking. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45257

FreeBSD FreeBSD, freebsd

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the sender transmits such data over a loopback connection without enabling KTLS on the transmit side, the file-backed mbufs reach the receiver's decryption path unchanged. Decrypting a record in place then overwrites the backing file's page cache instead of a private copy of the...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-30041

the affected product

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-68064

Everthemess Goya Core

CVE-2025-68064 affects Everthemess Goya Core. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57923

JetBrains YouTrack, youtrack

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57921

JetBrains YouTrack, youtrack

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-53914

JetBrains Kotlin, kotlin

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57920

Peplink InControl, intcontrol 2

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40711

Dell Container Storage Modules

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-64152

Apache Software Foundation Apache IoTDB

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-55017

Apache Software Foundation Apache IoTDB

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.