VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 765 of 1286 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-41401

libyang

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40034

gitoxide gitoxide, gix-submodule, gix

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40033

FreeRDP FreeRDP, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9543

Totolink N300RH

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-7374

Red Hat Red Hat Container Native Virtualization 4.12, Red Hat Container Native Virtualization 4.13, Red Hat Container Native Virtualization 4.14

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48133

checkpoint Quantum Security Gateway

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48132

checkpoint Quantum Security Gateway

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48131

checkpoint Quantum Security Gateway

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-11482

B&R Industrial Automation GmbH PPT30 Operating System

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39661

Magentech SW Core

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25713

MediaArea MediaInfoLib, mediainfolib

CVE-2026-25713 affects MediaArea MediaInfoLib, mediainfolib. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25104

MediaArea MediaInfoLib, mediainfolib

CVE-2026-25104 affects MediaArea MediaInfoLib, mediainfolib. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-44469

CODESYS CODESYS Development System, development system

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.

The CVSS severity warrants an early asset and exposure review.