VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 798 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-8813

exifreader

This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-47311

Samsung Open Source Escargot, escargot

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-47310

Samsung Open Source Escargot, escargot

Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47309

Samsung Open Source Escargot, escargot

Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-15609

Fortis for WooCommerce

The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47308

Samsung Open Source Walrus, walrus

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-47307

Samsung Open Source Walrus, walrus

NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions. This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27648

OpenHarmony

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25781

OpenHarmony

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24792

OpenHarmony

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-33233

Significant-Gravitas AutoGPT

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache bytes using pickle.loads without integrity/authenticity checks. The write path serializes values with pickle.dumps(...) into Redis and the read path blindly invokes pickle.loads(...) on bytes with no HMAC/signature or strict schema validation gating deserialization. If an attacker can poison a shared-cache key in Redis, arbitrary command execution is possible in the backend container context, affect...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-33232

Significant-Gravitas AutoGPT

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to uncontrolled disk space consumption. The download_agent_file endpoint creates persistent temporary files for every request but fails to delete them after they are served. An unauthenticated attacker can repeatedly call this endpoint to exhaust the server's disk space, causing the database or other system services to fail due to "No space left on device" e...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-32323

mullvad mullvadvpn-app, mullvad vpn

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is attacker-controlled or that the path is the legitimate Mullvad application. A user in the admin group can pre-place a crafted application bundle at that location and may be able to achieve code execution as root. Since the issue only affected the installer, there is no immediate need for users to upd...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-30950

Significant-Gravitas AutoGPT

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's session, they can take it over, reading any messages in it and locking the legitimate user out. The PATCH /sessions/{session_id}/assign-user endpoint authenticates the caller but never verifies session ownership: the service layer invokes the session lookup with user_id=None, which the data access layer in...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27891

NeoRazorX facturascripts

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leading to Arbitrary File Write and Remote Code Execution (RCE) by overwriting sensitive .php files outside the designated plugins directory. The vulnerability is located in Plugins.php. While the testZipFile function attempts to validate that the ZIP contains only one root folder, it does not sanitize...

The CVSS severity warrants an early asset and exposure review.