VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 710 of 1316 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-11239

Google Chrome, chrome, macos

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-10586

wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42824

Microsoft Microsoft 365 Copilot, copilot

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2026-20245

Cisco Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, catalyst sd-wan manager

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks o...

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2026-11237

Google Chrome, chrome

Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11236

Google Chrome, chrome, macos

Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11235

Google Chrome, chrome, macos

Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11231

Google Chrome, chrome, macos

Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11230

Google Chrome, chrome, macos

Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11224

Google Chrome, chrome, linux kernel

Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-11213

Google Chrome, chrome, macos

Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

The CVSS severity warrants an early asset and exposure review.