VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 99 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-49744

Imagination Technologies Graphics DDK

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-49743

Imagination Technologies Graphics DDK

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-24727

SUNNET Technology Co., Ltd. Corporate Training Management System

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-15704

Eclipse Foundation Eclipse BaSyx Go Components

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However, the ABAC middleware evaluated the original request path including the trailing slash. If ABAC route lookup did not find a matching slash-suffixed route, the request was passed onward and the router...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16519

GeoVision Inc. GV-IP Device Utility

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14603

WowOptin: Next-Gen Popup Maker

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14172

Rapid7 InsightVM, Nexpose, Insight Agent

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12981

CAFEHAUS API

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-12877

Project Management, Bug and Issue Tracking Plugin

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12497

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16870

Snowflake Snowflake libsnowflakeclient, Snowflake PHP PDO Driver, Snowflake ODBC Driver

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66141

Exim

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66140

Exim

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66138

OpenStack Ironic Python Agent

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12736

wpify WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the permission_callback only verifies the manage_woocommerce capability. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to Administrator by overwriting arbitrary W...

The CVSS severity warrants an early asset and exposure review.