VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 828 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2026-41649

outline

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId` and `documentId` are provided in the request, the authorization logic only checks access to the collection, completely ignoring the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including documents belonging to other workspaces. The full document contents can then be retrieved via the `documents.info`...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-41446

Snap One, LLC WattBox 800, WattBox 820

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-60889

hpx

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7324

Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10

Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7323

Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7322

Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2026-27760

opencats

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2025-48431

Apache Software Foundation Apache Thrift, Cryostat 4 on RHEL 9, Red Hat Advanced Cluster Management for Kubernetes 2.14

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2024-54013

Hanwha Vision QND-8080R, knb-2000 firmware, knb-2000

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds

The CVSS severity warrants an early asset and exposure review.