VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,384 CVE recordsPage 743 of 1293 · EPSS data 2026.08.12
ReviewCritical
CVE-2025-41273

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-41272

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-41271

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-41270

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-41269

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-41268

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-41267

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-41266

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-41265

Waterfall WF-500, wf-500 firmware, wf-500

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-9558

the affected product

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-49201

Acer Wave 7 router, wave 7 firmware, wave 7

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-46579

Red Hat Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-6075

dglingren Media Library Assistant

The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment metadata via a forged request.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-49200

Acer Wave 7 router, wave 7 firmware, wave 7

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

The CVSS severity warrants an early asset and exposure review.