VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 879 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-30290

intouch contacts & caller id

An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30285

zora

An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-3356

Anritsu Remote Spectrum Monitor MS27100A, Remote Spectrum Monitor MS27101A, Remote Spectrum Monitor MS27102A

The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5190

AWS aws-c-event-stream

Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. To remediate this issue, users should upgrade to version 0.6.0 or later.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-32726

scitokens scitokens-cpp, scitokens cpp library

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple string-prefix comparison when checking whether a requested resource path was covered by a token's authorized scope path. Because the check did not require a path-segment boundary, a token scoped to one path could incorrectly authorize access to sibling paths that merely started with the same prefix. This issue has been patched in version 1.4.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-32725

scitokens scitokens-cpp, scitokens cpp library

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses ".." path components instead of rejecting them. As a result, an attacker can use parent-directory traversal in the scope claim to broaden the effective authorization beyond the intended directory. This issue has been patched in version 1.4.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30286

zefiro

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30283

animal sounds and ringtones

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30282

cast to tv

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-30279

my location

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30278

fly is fun

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-30277

mobile print

An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2123

OpenText Operations Agent, operations agent, windows

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-34361

hapifhir org.hl7.fhir.core, hl7 fhir core

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by registering a domain that prefix-matches a configured server URL. This issue has been patched in...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-34359

hapifhir org.hl7.fhir.core, hl7 fhir core

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g., http://tx.fhir.org) lack a trailing slash or host boundary check, an attacker-controlled domain like http://tx.fhir.org.attacker.com matches the prefix and receives Bearer tokens, Basic auth credentials, or API keys when the HTTP client follows a redirect to that domain. This i...

The CVSS severity warrants an early asset and exposure review.