VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,563 CVE recordsPage 731 of 1305 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-39552

Code Supply Co. Blueprint

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-10621

Collibra Collibra Platform (SaaS), Collibra Platform (on-prem)

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-10611

misp

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated session established during the application beforeFilter phase before the normal login flow enforces the OTP challenge. As a result, an attacker with valid primary authentication credentials could bypass the required OTP step by authenticating through the plugin-backed login flow and then directl...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-69369

Axiomthemes Racquet

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-68886

androThemes Cookiteer

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-58897

Axiomthemes Fermentio

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. This issue affects Fermentio: from n/a through 1.5.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-58707

Axiomthemes Spin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2019-25719

Dräger Infinity Acute Care System, Standalone Infinity M540 patient monitor

Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow network-adjacent attackers to spoof or tamper with data and cause denial-of-service conditions. Attackers with access to an enabled Infinity network port or physical proximity to a wireless access point can modify device settings such as alarm states or alarm limits, and overwhelm the system with incoming data causing the device to reboot and lose network functionality.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42685

Ahmad WP Job Portal

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-42684

Ahmad WP Job Portal

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42669

EventPrime

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39551

Elated-Themes Töbel

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39550

Elated-Themes Aperitif

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

The CVSS severity warrants an early asset and exposure review.