VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,154 CVE recordsPage 558 of 1344 · EPSS data 2026.08.04
ReviewHigh
CVE-2026-54838

Rymera Web Co WC Vendors Marketplace

CVE-2026-54838 affects Rymera Web Co WC Vendors Marketplace. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54836

YMC YMC Filter

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54829

Jacob N. Breetvelt WP Photo Album Plus

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54828

StylemixThemes Motors

CVE-2026-54828 affects StylemixThemes Motors. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54823

MarketingFire Widget Options

CVE-2026-54823 affects MarketingFire Widget Options. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54822

SALESmanago SALESmanago & Leadoo

CVE-2026-54822 affects SALESmanago SALESmanago & Leadoo. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54821

Bootstrapped Ventures Visual Link Preview

CVE-2026-54821 affects Bootstrapped Ventures Visual Link Preview. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4526

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49506

Dell Wyse Management Suite, wyse management suite

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47154

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Simple Metering cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47153

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47152

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47151

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47150

Silicon Labs EmberZNet, emberznet

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may be impacted.

The CVSS severity warrants an early asset and exposure review.