VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,557 CVE recordsPage 909 of 1238 · EPSS data 2026.08.09
ReviewCritical
CVE-2026-26217

unclecode Crawl4AI, crawl4ai

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can access sensitive files such as /etc/passwd, /etc/shadow, application configuration files, and environment variables via /proc/self/environ, potentially exposing credentials, API keys, and internal application structure.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-26216

unclecode Crawl4AI, crawl4ai

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-26214

Xiaomi Technology Co., Ltd. Galaxy FDS Android SDK

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications t...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2007

PostgreSQL, Red Hat Enterprise Linux 10, Red Hat Hardened Images

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2006

PostgreSQL, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-2004

PostgreSQL, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-26215

zyddnys manga-image-translator

manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled request bodies using pickle.loads() without validation. Although a nonce-based authorization check is intended to restrict access, the nonce defaults to an empty string and the check is skipped, allowing remote attackers to execute arbitrary code in the server context by sending a crafted pickle payload.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2026-20700

Apple Multiple Products

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2026-20652

Apple Safari, iOS and iPadOS, macOS

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1669

Google Keras, Red Hat OpenShift AI (RHOAI), keras

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-26158

Red Hat Red Hat Hardened Images, Red Hat Enterprise Linux 6, RUGGEDCOM RST2428P

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-26157

Red Hat Red Hat Hardened Images, Red Hat Enterprise Linux 6, RUGGEDCOM RST2428P

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69872

Red Hat OpenShift AI 3.3, Red Hat Satellite 6.18

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

The CVSS severity warrants an early asset and exposure review.