VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 81 of 1178 · EPSS data 2026.08.06
ReviewCritical
CVE-2026-59527

RomanCode MapSVG

CVE-2026-59527 affects RomanCode MapSVG. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-59172

Ericsson Packet Core Controller (PCC)

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-61511

vBulletin

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59690

Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59689

Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59688

Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59687

Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-59686

Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12991

Ghost Robotics Vision 60

The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integri...

The CVSS severity warrants an early asset and exposure review.