---
Vulnerabilities
---
Vendors
---
Products
Vulnerability Media Exposure
These listed vulnerabilities have been referenced across multiple public sources, indicating high media attention and potential significance.
CVE-2026-83548 EUVD-2026-69704
CRITICAL

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

sonicwall:sma8200v
sonicwall:sma6210_firmware
sonicwall:sma7210_firmware
CVE-2026-83549 EUVD-2026-69707
HIGH

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

sonicwall:sma8200v
sonicwall:sma6210_firmware
sonicwall:sma7210_firmware
CVE-2026-62911 EUVD-2026-56688
HIGH

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

microsoft:exchange_server
CVE-2026-44496 EUVD-2026-36259
HIGH

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.

Red Hat:Red Hat Ansible Automation Platform 2.5 for RHEL 8
Red Hat:Red Hat Ansible Automation Platform 2.5 for RHEL 9
Red Hat:Red Hat build of Apicurio Registry 3.3.1
Red Hat:multicluster engine for Kubernetes 2.10
Red Hat:multicluster engine for Kubernetes 2.6
Red Hat:multicluster engine for Kubernetes 2.8
Red Hat:multicluster engine for Kubernetes 2.9
Red Hat:Red Hat Advanced Cluster Management for Kubernetes 2.11
Red Hat:Red Hat Advanced Cluster Management for Kubernetes 2.13
Red Hat:Red Hat Advanced Cluster Management for Kubernetes 2.14
Red Hat:Red Hat Advanced Cluster Management for Kubernetes 2.15
Red Hat:Red Hat Advanced Cluster Management for Kubernetes 2.16
Red Hat:Red Hat Advanced Cluster Security for Kubernetes 4.10
Red Hat:Red Hat Advanced Cluster Security for Kubernetes 4.9
Red Hat:Red Hat Ansible Automation Platform 2.7
Red Hat:Red Hat Developer Hub 1.10
Red Hat:Red Hat Developer Hub 1.9
Red Hat:Red Hat Discovery 2
Red Hat:Red Hat Migration Toolkit 1.8
Red Hat:Red Hat Migration Toolkit for Applications 8.1
Red Hat:Red Hat OpenShift AI 3.4
Red Hat:Red Hat OpenShift Container Platform 4.14
Red Hat:Red Hat OpenShift Container Platform 4.15
Red Hat:Red Hat OpenShift Container Platform 4.16
Red Hat:Red Hat OpenShift Container Platform 4.19
Red Hat:Red Hat OpenShift Container Platform 4.20
Red Hat:Red Hat OpenShift Container Platform 4.21
Red Hat:Red Hat OpenShift Dev Spaces 3.29
Red Hat:Red Hat OpenShift Service Mesh 2.6
Red Hat:Red Hat OpenShift Service Mesh 3.0
Red Hat:Red Hat OpenShift Service Mesh 3.1
Red Hat:Red Hat OpenShift Service Mesh 3.2
Red Hat:Red Hat OpenShift Service Mesh 3.3
Red Hat:Red Hat Quay 3.1
Red Hat:Red Hat Quay 3.12
Red Hat:Red Hat Quay 3.15
Red Hat:Red Hat Quay 3.16
Red Hat:Red Hat Quay 3.9
Red Hat:Red Hat Trusted Artifact Signer 1.3
axios:axios
Newly recorded security issues per week
Stay up to date! New information is added to our knowledge database every day. Here you can see the history of newly added vulnerabilities that have been added to our CVE DB in recent years.
Vulnerabilities by severity (over the last 7 days)
Information about the vulnerabilities of the last 7 days can be found here. As you can see, critical vulnerabilities are also added on a daily basis. Therefore, validate your current security situation sets on a daily basis to ensure the security of your IT.
CVSS Score Distribution
The CVSS score rates security vulnerabilities from 0 to 10, based on factors like attack vectors and impacts on confidentiality, integrity, and availability.
EPSS Score Distribution
The EPSS score predicts the likelihood of a known vulnerability being exploited, complementing CVSS by assessing real-world exploitability based on threat activity and exploit availability.
Enginsight Threat Intelligence
Our multi-source enrichment pipeline aggregates vulnerability data from dozens of security organizations worldwide — delivering affected product details and severity scores before the NVD has completed their analysis.
5,358
Early Detections
Vulnerabilities identified
before NVD analysis
2,510
Critical + High
CVSS 7.0 or above
among early detections
20+
Intelligence Sources
Security organizations
contributing data
---
Detections / Week
New vulnerabilities enriched
ahead of NVD each week
Monthly Early Detections
Vulnerabilities enriched with affected product data before NVD has completed analysis.
Severity Distribution
Severity breakdown of vulnerabilities detected ahead of the NVD.
Top Intelligence Sources
Security organizations contributing the most vulnerability intelligence to our database.
NVD Analysis Gap
Where our early detections stand in the NVD pipeline — most are still waiting for official analysis.
Latest Vulnerability Reports
The 10 most recently published CVE reports.
  • CVE-2026-84857 EUVD-2026-70279
    MEDIUM

    A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

  • CVE-2026-84856 EUVD-2026-70268
    MEDIUM

    A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 0.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended. The legacy Next.js app was deleted at 0.9.2 rather than patched, leaving no security control behind.

  • CVE-2026-84852 EUVD-2026-70259
    MEDIUM

    A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument _display_name leads to path traversal. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

  • CVE-2026-84452 EUVD-2026-70264
    UNKNOWN

    Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a user can send cross-origin requests to /v1/cli/build or /v1/cli/config and set the trust_remote_code parameter to true, which is converted to the --trust-remote-code command-line flag without validation. This reaches AutoConfig.from_pretrained with trust_remote_code=True in src/winml/modelkit/loader/_autoconfig.py and imports Python code from an attacker-controlled model repository, resulting in arbitrary code execution as the server user. This issue is fixed in version 0.4.0.

  • CVE-2026-84292 EUVD-2026-70280
    HIGH

    fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.

  • CVE-2026-82524 EUVD-2026-70265
    HIGH

    UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute arbitrary operating system commands on the server by accessing the uploaded file at the URL returned in the server response.

  • CVE-2026-78662 EUVD-2026-70266
    UNKNOWN

    Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

  • CVE-2026-75137 EUVD-2026-70262
    MEDIUM

    UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers can use the PROCESS_VM_READ permission to read the memory space of UpSignOn.exe and extract sensitive fields including entry names, URLs, usernames, passwords, TOTP secrets, and notes.

  • CVE-2026-75136 EUVD-2026-70261
    MEDIUM

    UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication prompt. Attackers can access the stored biometric key from a standard local process within the same Windows session to decrypt the protected vault files and export the entire password manager contents in cleartext.

  • CVE-2026-75135 EUVD-2026-70260
    MEDIUM

    UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locked. Attackers can extract the backup key from process memory to decrypt the encrypted master password backup stored in v6-vault1.DATA.txt, then use the recovered master password to decrypt the main vault and export all password manager entries in cleartext.