VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 829 of 1286 · EPSS data 2026.08.11
ReviewHigh
CVE-2024-54012

Hanwha Vision QND-8080R, knb-2000 firmware, knb-2000

Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40356

MIT Kerberos 5, kerberos 5

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40355

MIT Kerberos 5, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7219

Totolink N300RT

A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS. Executing a manipulation of the argument entry_name can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7218

Totolink N300RT

A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1460

Zyxel DX3301-T0 firmware, EX3301-T0 firmware, nebula fwa70 firmware

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7204

Totolink A8000RU

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7203

Totolink A8000RU

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-7202

Totolink A8000RU

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41371

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41370

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41369

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.

The CVSS severity warrants an early asset and exposure review.