VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,169 CVE recordsPage 601 of 1345 · EPSS data 2026.08.14
ReviewHigh
CVE-2026-42129

Grafana Grafana OSS, loki datasource

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28381

Grafana Snowflake Datasource, snowflake

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12602

Aruba ArubaSign

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive permissions for the ‘Everyone’ group. This could allow an unprivileged user to replace the main executable and/or its components with a malicious file, thereby enabling the execution of arbitrary code. In the worst-case scenario, if the malicious code is executed with elevated privileges (such as tho...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-10561

IBM Langflow OSS, langflow

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-66389

github copilot

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-56422

misp

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object identifiers) without consistently stripping, pinning, or revalidating them against the server-authorized object. In affected paths, an authenticated user with access to one authorized object could submit crafted REST or form payloads that caused MISP to save data against a different object than the one checked by the authorizat...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11373

JASEI Net::Statsite::Client

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12581

Digiwin EasyFlow .NET

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-4994

SafeLine SafeLine SL6/SL6+

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-45796

Pilz PMI v8xx, PASvisu

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-45795

Pilz PMI v8xx, PASvisu

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44914

Apache Software Foundation Apache NiFi, nifi

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-66336

Apache Software Foundation Apache Doris MCP Server, doris mcp server

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope. Affected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-8157

Vitepos

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-6858

Transbank Webpay

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

The CVSS severity warrants an early asset and exposure review.