VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 76 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-28973

Apple iOS and iPadOS, macOS, watchOS

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28945

Apple macOS, macos

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28931

Apple iOS and iPadOS, macOS, tvOS

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-28928

Apple iOS and iPadOS, macOS, tvOS

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28926

Apple macOS, macos

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28912

Apple macOS, macos

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-28911

Apple macOS, macos

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-28896

Apple macOS, macos

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66015

jfrog artifactory

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-66014

jfrog artifactory

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65921

jfrog artifactory

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65617

jfrog artifactory

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65616

jfrog artifactory

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-64649

vercel next.js

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization. Applications that use Server Actions are affected when the incoming host header is not fixed to a trusted val...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-56748

Cribl Cribl Stream

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.

The CVSS severity warrants an early asset and exposure review.