VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 853 of 1264 · EPSS data 2026.08.10
ReviewCritical
CVE-2025-69515

the affected product

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-56015

genieacs

In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-14859

Semtech LR1110, LR1120, LR1121

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39355

MGeurts genealogy

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces and unrestricted access to all genealogy data associated with the compromised team. This vulnerability is fixed in 5.9.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-71058

the affected product

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject forged responses and poison the DNS cache, potentially redirecting victims to attacker-controlled destinations.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39344

ChurchCRM CRM, churchcrm

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused by the lack of sanitization or encoding of the username parameter received from the URL. The username parameter value is directly displayed in the login page input element without filter, allowing attackers to insert malicious JavaScript scripts. If successful, script can be executed on the client side, potentially stealing sensitive data such as session cookies or replacing the display to show the attacker's login form. This...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39343

ChurchCRM CRM, churchcrm

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is only accessible to administrators. The EN_tyid POST parameter is not sanitized before being used in a SQL query, allowing an administrator to execute arbitrary SQL commands directly against the database. This vulnerability is fixed in 7.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-39342

ChurchCRM CRM, churchcrm

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39341

ChurchCRM CRM, churchcrm

ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not used to create the SQL query. This vulnerability is fixed in 7.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24156

NVIDIA DALI, data loading library

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22682

HKUDS OpenHarness

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope. Attackers can exploit the path parameter not being passed to the PermissionChecker in read_file, write_file, edit_file, and notebook_edit tools to bypass deny rules and access sensitive files such as configuration files, credentials, and SSH material, or create and overwrite files in restricted...

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2026-4631

Red Hat Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.

FIRST EPSS indicates an elevated probability of exploitation.
PriorityCritical
CVE-2026-23696

Windmill Labs Windmill CE (Community Edition), Windmill EE (Enterprise Edition)

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2025-14821

Red Hat Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-33816

github.com/jackc/pgx/v5 github.com/jackc/pgx/v5/pgproto3, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10

CVE-2026-33816 affects github.com/jackc/pgx/v5 github.com/jackc/pgx/v5/pgproto3, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.