VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,154 CVE recordsPage 623 of 1344 · EPSS data 2026.08.14
ReviewHigh
CVE-2026-54415

Azuriom Azuriom CMS

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49502

Dell PowerFlex, powerflex manager

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Unauthorized access.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-47103

fgmacedo python-statemachine, python statemachine

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a call chain ending in Python's built-in eval() without sandboxing, enabling arbitrary code execution in the context of the hosting process.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-42530

F5 NGINX Open Source, Red Hat Hardened Images, Red Hat Enterprise Linux 10

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS)...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-42055

F5 NGINX Open Source, NGINX Plus, Red Hat Enterprise Linux 10

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a res...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35067

Dell PowerFlex, powerflex manager

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35066

Dell PowerFlex, powerflex manager

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35065

Dell PowerFlex, powerflex manager

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-32804

Dell PowerFlex, powerflex manager

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22283

Dell PowerFlex, powerflex manager

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11311

F5 NGINX Gateway Fabric, nginx gateway fabric

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration d...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55738

rxi microtar

A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54819

Webilia Inc. Listdom

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54818

VeronaLabs Slimstat Analytics

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54816

Monetizemore Advanced Ads

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

The CVSS severity warrants an early asset and exposure review.