VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 792 of 1286 · EPSS data 2026.08.11
ReviewCritical
CVE-2026-24214

NVIDIA Triton Inference Server, triton inference server

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24213

NVIDIA Triton Inference Server, triton inference server

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24163

NVIDIA TensorRT-LLM, tensorrt llm

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24160

NVIDIA TensorRT-LLM, tensorrt llm

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24142

NVIDIA TensorRT-LLM, tensorrt llm

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-33255

NVIDIA TensorRT-LLM, tensorrt llm

NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7467

edmonparker Read More & Accordion

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it possible for authenticated attackers, with permission granted by the site owner through the plugin's role settings, to insert arbitrary rows into the 'wp_users' and 'wp_usermeta' tables, including the 'wp_capabilities' field, allowing them to create a new administrator account and...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-7284

themewant Easy Elements for Elementor – Addons & Website Templates

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-6555

prosolution ProSolution WP Client

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file.

The CVSS severity warrants an early asset and exposure review.