VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,954 CVE recordsPage 850 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-3499

jkohlbach Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type, ajax_adt_clear_custom_attributes_product_meta_keys, ajax_update_file_url_to_lower_case, ajax_use_legacy_filters_and_rules, and ajax_fix_duplicate_feed functions. This makes it possible for unauthenticated attackers to trigger feed migration, clear custom-attribute transient caches, rewrite feed file URLs to lowercase,...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-3296

wpeverest Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripp...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-33810

Go standard library crypto/x509, Cryostat 4 on RHEL 9, HawtIO HawtIO 4.4.0

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-32281

Go standard library crypto/x509, go

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27144

Go toolchain cmd/compile, go

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-27143

Go toolchain cmd/compile, go

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-3357

IBM Langflow Desktop, langflow

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1346

IBM Verify Identity Access Container, Security Verify Access Container, Verify Identity Access

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1343

IBM Verify Identity Access Container, Security Verify Access Container, Verify Identity Access

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5747

AWS Firecracker, firecracker

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1342

IBM Verify Identity Access Container, Security Verify Access Container, Verify Identity Access

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39937

The Wikimedia Foundation Mediawiki - CentralAuth Extension

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.

The CVSS severity warrants an early asset and exposure review.