VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 880 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-24165

NVIDIA BioNeMo Framework, bionemo framework

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24164

NVIDIA BioNeMo Framework, bionemo framework

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24148

NVIDIA Jetson Xavier Series and Jetson Orin Series, jetson linux, jetson agx orin 32gb

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tampering, and partial denial of service across devices sharing the same machine ID.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5204

Tenda CH22, ch22 firmware, ch22

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5087

JJNAPIORK PAGI::Middleware::Session::Store::Cookie, pagi::middleware::session::store::cookie

PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the /dev/urandom device directly. If that fails (for example, on systems without the device, such as Windows), then it will emit a warning that recommends the user install Crypt::URandom, and then return a string of random bytes generated by the built-in rand function, which is unsuitable for cryptographic applications. This modules does not use the Crypt::URandom module, and installing it will not fix the problem...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4818

floragunn Search Guard FLX, flx

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34573

parse-community parse-server

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a crafted query with binary fan-out fragment spreads. A single unauthenticated request can block the Node.js event loop for seconds, denying service to all concurrent users. This only affects deployments that have enabled the requestComplexity.graphQLDepth or requestComplexity.graphQLFields configuration options. This issue has been patched in versio...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-34243

njzjz wenxian

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runner. At time of publication, there are no publicly available patches.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34240

appsup-dart jose

JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could treat header-provided jwk as a verification candidate even when that key was not present in the trusted key store. Since JOSE headers are untrusted input, an attacker could exploit this by creating a token payload, embedding an attacker-controlled public key in the header, and signing with the matc...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34221

mikro-orm mikro-orm, mikroorm

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM when merging object structures. The function did not prevent special keys such as __proto__, constructor, or prototype, allowing attacker-controlled input to modify the JavaScript object prototype when merged. This issue has been patched in versions 6.6.10 and 7.0.6.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-34220

mikro-orm mikro-orm, mikroorm

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-34219

libp2p rust-libp2p, libp2p-gossipsub

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff value, the value is accepted and stored as an Instant near the representable upper bound. On a later heartbeat, the implementation performs unchecked Instant + Duration arithmetic (backoff_time + slack), which can overflow and panic with: overflow when adding duration to insta...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-30284

voice recorder

An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30281

neo.maru

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30276

document translator

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

The CVSS severity warrants an early asset and exposure review.