VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
20,154 CVE recordsPage 627 of 1344 · EPSS data 2026.08.13
ReviewHigh
CVE-2025-66391

the affected product

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-60236

EMV Creatify

Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-60231

EMV The Hospital

Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-60230

Themeton The Barber Shop

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-60229

Themeton Lagom

Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-59554

Advanced Ads GmbH Advanced Ads – Tracking

CVE-2025-59554 affects Advanced Ads GmbH Advanced Ads – Tracking. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9570

Taskbuilder

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-8089

weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5667

Mitsubishi Electric Corporation Room Air Conditioners (for Japan) MSZ-BKR2223-W, Room Air Conditioners (for Japan) MSZ-BKR2224-W, Room Air Conditioners (for Japan) MSZ-BKR2523-W

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for J...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55706

OpenBSD OpenBSD, openbsd

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54811

Tips and Tricks HQ WP eMember

CVE-2026-54811 affects Tips and Tricks HQ WP eMember. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54807

ThemeGrill Registration Form for WooCommerce

CVE-2026-54807 affects ThemeGrill Registration Form for WooCommerce. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-54806

Melapress WP Activity Log

CVE-2026-54806 affects Melapress WP Activity Log. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54805

sbouey Falang multilanguage

CVE-2026-54805 affects sbouey Falang multilanguage. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.