VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,787 CVE recordsPage 665 of 1320 · EPSS data 2026.08.13
ReviewHigh
CVE-2026-11933

MongoDB MongoDB, mongodb

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45173

CyberArk Software, a Palo Alto Networks Company Identity Browser Extensions, idira identity browser extension, chrome

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45172

CyberArk Software, a Palo Alto Networks Company PAM Self-Hosted, Privilege Cloud, idira privileged session manager for ssh

Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45171

CyberArk Software, a Palo Alto Networks Company Privileged Session Manager, Vault, idira privileged session manager

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44890

netty netty, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Data Grid 8.6.2

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44250

netty netty, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Data Grid 8.6.2

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44249

netty netty, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-12027

Google Chrome, chrome, macos

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12018

Google Chrome, chrome, windows

Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12016

Google Chrome, chrome, macos

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12014

Google Chrome, chrome, macos

Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12012

Google Chrome, chrome, macos

Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12008

Google Chrome, chrome, macos

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-49973

nesquena hermes-webui

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an arbitrary password hash, obtain a valid session cookie, and lock out the legitimate operator from their own instance.

The CVSS severity warrants an early asset and exposure review.