VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 762 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-24193

NVIDIA GeForce, NVIDIA RTX, Quadro, NVS, Tesla

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24192

NVIDIA GeForce, NVIDIA RTX, Quadro, NVS, Tesla

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24191

NVIDIA GeForce, NVIDIA RTX, Quadro, NVS, Tesla

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24190

NVIDIA GeForce, NVIDIA RTX, Quadro, NVS, Tesla

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24187

NVIDIA GeForce, NVIDIA RTX, Quadro, NVS, Tesla

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48864

Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48697

fastnetmon

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but never calls set_verify_mode(boost::asio::ssl::verify_peer). Without this call, OpenSSL performs the TLS handshake without validating the server's certificate chain, making all HTTPS connections vulnerable to man-in-the-middle attacks. This function is used for telemetry reporting to community-stats.f...

The CVSS severity warrants an early asset and exposure review.