VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 766 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-44468

CODESYS CODESYS Development System, development system

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9496

pacote, org.webjars.npm:pacote

Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-9538

BINGOS Archive::Tar, archive::tar

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42497

BINGOS Archive::Tar, archive::tar

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-42496

BINGOS Archive::Tar, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-8376

SHAY perl

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer. A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compi...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48837

Unlimited Elements Unlimited Elements For Elementor

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45438

WebToffee Smart Coupons for WooCommerce

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45216

StoreApps Smart Manager

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-45209

edward_plainview MyCryptoCheckout

Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-42774

Crocoblock JetEngine

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-42773

eMagicOne eMagicOne Store Manager

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind SQL Injection. This issue affects eMagicOne Store Manager: from n/a through 1.3.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39436

bgermann CformsII

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24937

VideoWhisper.com Broadcast Live Video

Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a before 7.1.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48848

Roundcube Webmail

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

The CVSS severity warrants an early asset and exposure review.