VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,562 CVE recordsPage 906 of 1238 · EPSS data 2026.08.09
ReviewHigh
CVE-2025-67733

valkey-io valkey, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same connection. The error handling code for lua scripts does not properly handle null characters. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-14905

Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8, Red Hat Directory Server 11.7 E4S for RHEL 8, Red Hat Directory Server 11.9 for RHEL 8

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25747

Apache Software Foundation Apache Camel LevelDB, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files used by a Camel application can inject a crafted serialized Java object that, when deserialized during normal aggregation repository operations, results in arbitrary code execution in the context of the application. This issue affects Apache Ca...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2998

eAI Technologies ERP F2

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27134

strimzi strimzi-kafka-operator, streams for Apache Kafka 2, streams for Apache Kafka 3

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS authentication on the internal as well as user-configured listeners. All CAs from the CA chain will be trusted. And users with certificates signed by any of the CAs in the chain will be able to authenticate. This issue affects only users using a custom Cluster or Clients CA with a...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2635

MLflow MLflow, Red Hat OpenShift AI (RHOAI)

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the administrator. Was ZDI-CAN-28256.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2492

TensorFlow TensorFlow, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI)

TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of plugins. The application loads plugins from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25480.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2048

GIMP GIMP, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the c...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2047

GIMP GIMP, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICNS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2045

GIMP GIMP, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the c...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2044

GIMP GIMP, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support

GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PGM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28158.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2033

MLflow MLflow, Red Hat OpenShift AI (RHOAI)

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of artifact file paths. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26649.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-0797

GIMP GIMP, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the cu...

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-25896

NaturalIntelligence fast-xml-parser, Red Hat Advanced Cluster Security 4.8, Red Hat Advanced Cluster Security 4.9

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2472

Google Cloud Vertex AI SDK for Python, Red Hat OpenShift AI 2.25

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab environment via injecting script escape sequences into model evaluation results or dataset JSON data.

The CVSS severity warrants an early asset and exposure review.