VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,982 CVE recordsPage 547 of 1333 · EPSS data 2026.08.04
ReviewCritical
CVE-2026-54823

MarketingFire Widget Options

CVE-2026-54823 affects MarketingFire Widget Options. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54822

SALESmanago SALESmanago & Leadoo

CVE-2026-54822 affects SALESmanago SALESmanago & Leadoo. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54821

Bootstrapped Ventures Visual Link Preview

CVE-2026-54821 affects Bootstrapped Ventures Visual Link Preview. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4526

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49506

Dell Wyse Management Suite, wyse management suite

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47154

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Simple Metering cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47153

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47152

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47151

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47150

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47149

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47148

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Groups cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47147

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices supporting the OTA Server cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47146

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47145

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.