VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,946 CVE recordsPage 886 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-27877

Grafana Grafana, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-27876

Grafana Grafana, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. Only instances in the following version ranges are affected: - 11.6.0 (inclusive) to 11.6.14 (exclusive): 11.6.14 has the fix. 11.5 and below are not affected. - 12.0.0 (inclusive) to 12.1.10 (exclusive): 12.1.10 has the fix. 12.0 did not receive an...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27858

Open-Xchange GmbH OX Dovecot Pro, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27857

Open-Xchange GmbH OX Dovecot Pro, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24031

Open-Xchange GmbH OX Dovecot Pro, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-59032

Open-Xchange GmbH OX Dovecot Pro, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-33701

open-telemetry opentelemetry-java-instrumentation, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27893

vllm-project vllm, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2100

p11-glue p11-kit, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-4926

path-to-regexp path-to-regexp, Cryostat 4 on RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Workarounds: Limit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-30463

fuel cms

Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-30458

fuel cms

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

The CVSS severity warrants an early asset and exposure review.