VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 876 of 1264 · EPSS data 2026.08.10
ReviewCritical
CVE-2026-35002

Agno Agno, agno

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34797

Endian Endian Firewall, firewall community

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34796

Endian Endian Firewall, firewall community

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34795

Endian Endian Firewall, firewall community

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34794

Endian Endian Firewall, firewall community

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34793

Endian Endian Firewall, firewall community

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34792

Endian Endian Firewall, firewall community

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-32871

PrefectHQ fastmcp, Red Hat Satellite 6.18, Red Hat OpenShift AI (RHOAI)

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability exists in the _build_url() method. When an OpenAPI operation defines path parameters (e.g., /api/v1/users/{user_id}), the system directly substitutes parameter values into the URL template string without URL-encoding. Subsequently, urllib.parse.urljoin() resolves the final URL. Since urljoin() int...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-3692

Progress Software Flowmon, flowmon

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2737

Progress Software Flowmon, flowmon

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4636

Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.4

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4634

Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.4

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4282

Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.4

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-3872

Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.4

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-3987

WatchGuard Fireware OS

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.

The CVSS severity warrants an early asset and exposure review.