VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 82 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-12990

Ghost Robotics Vision 60

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12989

Ghost Robotics Vision 60

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58662

Apache Software Foundation Apache Thrift, thrift

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58389

Apache Software Foundation Apache Thrift, thrift

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55969

Apache Software Foundation Apache Thrift, thrift

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55968

Apache Software Foundation Apache Thrift, thrift

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49158

Apache Software Foundation Apache Thrift, thrift

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48586

Apache Software Foundation Apache Thrift, thrift

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-48145

Apache Software Foundation Apache Thrift, thrift

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-48144

Apache Software Foundation Apache Thrift, thrift

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-43871

Apache Software Foundation Apache Thrift, thrift

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41608

Apache Software Foundation Apache Thrift, thrift

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17527

Red Hat Red Hat OpenShift Virtualization 4

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use th...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17523

Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

The CVSS severity warrants an early asset and exposure review.