VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,165 CVE recordsPage 573 of 1345 · EPSS data 2026.08.13
ReviewHigh
CVE-2026-53950

TryGhost Ghost

@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-53943

TryGhost Ghost

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same page, allowing cache poisoning of request-specific preview output. When running Ghost's frontend and admin panel on the same domain this could be used to take over staff user accounts. When ru...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-49980

rclone rclone, Cryostat 4, OpenShift API for Data Protection

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49247

jellyfin

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields and uses them unsanitized as components of the on-disk filename when persisting client-uploaded log documents. As a result, any authenticated non-admin user can include ../ sequences in the Client field to cause Jellyfin to write attacker-controlled content to arbitrary paths reachable by the Jellyfin service user, with a forced .log suffix. This vulnerability is fixed in 10.11.10.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48793

jellyfin

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. SubtitleEncoder.ConvertTextSubtitleToSrtInternal (SubtitleEncoder.cs, line 382) interpolates the subtitle file path into FFmpeg command-line arguments without calling EncodingUtils.NormalizePath(). On Linux, filenames can contain double-quote characters, which break the argument quoting and allow injection of arbitrary FFmpeg arguments. The vulnerability is reachable without authentication via SubtitleController.GetSubtitle,...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13038

Google Chrome, chrome, windows

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13037

Google Chrome, chrome, android

Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13036

Google Chrome, chrome, macos

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13035

Google Chrome, chrome, macos

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13033

Google Chrome, chrome, macos

Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13032

Google Chrome, chrome, android

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13031

Google Chrome, chrome, macos

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13029

Google Chrome, chrome, macos

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13028

Google Chrome, chrome, android

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13027

Google Chrome, chrome, macos

Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.