Vulnerability Intelligence

Know what's exploitable before it's exploited

CVE analysis built on public NVD and CISA KEV data — enriched with practical remediation, detection, and prioritization guidance.

3787
CVEs ingested
3144
Published
14
Known exploited
  • CVE-2022-26758HIGH 7.1

    CVE-2022-26758 is a memory corruption vulnerability in macOS that allows a malicious application running on the same system to alter memory regions shared between processes. An attacker with local access and the ability to execute code would be able to read sensitive data or modify system behavior by corrupting this shared memory. Apple resolved this through improved state management in macOS Monterey 12.4.

  • CVE-2022-48575LOW 3.5

    CVE-2022-48575 is a local bypass vulnerability in macOS that allows someone with physical access to a Mac to circumvent the Login Window security prompt. The issue stems from inconsistent state handling in the authentication system—essentially, the login screen may fail to properly enforce its security state in certain conditions, potentially allowing unauthorized access. Apple has patched this in macOS Monterey 12.4 and later.

  • CVE-2024-58350LOW 2.9

    Ghidra, the reverse-engineering framework maintained by the NSA, contains a memory management flaw that can cause the application to hang or crash during shutdown. The problem stems from improperly ordered cleanup of internal components, where the program attempts to access memory that has already been freed. An attacker with local access can trigger this condition, resulting in a denial-of-service effect. This is a low-severity issue with limited real-world impact, as it requires local execution and only affects availability during the shutdown phase.

  • CVE-2025-10237MEDIUM 6.7

    CVE-2025-10237 is a firmware vulnerability affecting ThinkPad embedded controllers that permits a user with administrative or system-level privileges to read from and write to sensitive memory regions that should be protected. An attacker with high-level local access could use this to manipulate firmware behavior, extract sensitive data, or establish persistence. The vulnerability requires elevated privileges to exploit, limiting the immediate attack surface, but the potential consequences—including complete system compromise at the firmware level—are serious.

  • CVE-2025-10238MEDIUM 6.7

    A vulnerability in ThinkPad BIOS could allow someone with administrative or system-level access to a machine to write data outside intended memory boundaries, potentially enabling them to execute malicious code at the System Management Mode (SMM) level. SMM is a privileged processor mode that runs independently of the operating system, giving an attacker the ability to compromise the system at its deepest firmware level.

  • CVE-2025-6254CRITICAL 9.8

    The Doctreat Core WordPress plugin contains a critical flaw in its user registration function that fails to validate the role assigned to new users. An attacker can register a new account and assign themselves administrator privileges without needing to authenticate first. This bypasses all normal access controls and gives an attacker complete control over the WordPress site immediately upon registration.

  • CVE-2025-62850HIGH 7.2

    A NULL pointer dereference flaw in QNAP QuTS hero operating system can allow an administrator account holder to crash the storage system, causing service interruption. The vulnerability requires valid admin credentials to exploit, limiting its immediate exposure to insider threats or compromised admin accounts. QNAP has released patched versions across multiple QuTS hero branches.

  • CVE-2025-62851MEDIUM 4.4

    CVE-2025-62851 is a path traversal vulnerability affecting QNAP License Center that allows a local administrator to read files and system data they should not have access to. An attacker who already has administrative credentials can use this flaw to navigate the file system and extract sensitive information. The vulnerability has a CVSS score of 4.4 (Medium severity) and is addressed in License Center version 1.9.56 and later.

  • CVE-2025-66273HIGH 7.2

    QNAP NAS systems running vulnerable versions of QTS and QuTS hero contain a command injection flaw that allows an authenticated administrator to execute arbitrary commands on the device. An attacker who obtains admin credentials—either through credential compromise, social engineering, or internal threat—can leverage this vulnerability to gain full control over the NAS, potentially accessing stored data, modifying configurations, or using the device as a pivot point into the network. The vulnerability requires valid administrative access, so it represents a privilege escalation or lateral movement risk rather than an unauthenticated remote attack.

  • CVE-2025-66276CRITICAL 9.8

    A critical remote vulnerability affects QNAP QTS systems, allowing unauthenticated attackers on the network to compromise affected devices completely. The issue enables attackers to read sensitive data, modify system files and configurations, and disrupt service availability—all without requiring user interaction or special system access. QNAP has already released a patch, and organizations running older QTS versions should prioritize immediate patching.

  • CVE-2025-66279HIGH 7.2

    A command injection flaw in QNAP operating systems allows an authenticated administrator to run arbitrary commands on affected NAS devices. The vulnerability requires valid admin credentials, limiting exposure to insider threats or attackers who have compromised an admin account. QNAP has patched multiple OS versions including QTS 5.2.9.3410 build 20260214 and later, and several QuTS hero releases.

  • CVE-2025-66280HIGH 7.2

    QNAP has patched an integer overflow vulnerability affecting their NAS operating systems. The flaw requires an attacker to first obtain administrator credentials, then exploit the memory handling weakness to gain elevated control or crash the system. While the barrier to entry is high—needing valid admin access—the potential impact is severe because it affects core system integrity. QNAP has released patched versions across QTS and QuTS hero product lines.

  • CVE-2025-66281HIGH 7.2

    CVE-2025-66281 is a NULL pointer dereference vulnerability affecting QNAP NAS operating systems. When triggered, the flaw causes the application to crash, resulting in a denial-of-service condition. An attacker with high-level administrative privileges can remotely exploit this to disrupt NAS availability. While the vulnerability requires elevated credentials to trigger, the impact is immediate and can leave your storage infrastructure offline until patched.

  • CVE-2025-71329HIGH 7.5

    The image-size Node.js library versions up to 2.0.2 contain a vulnerability that allows an attacker to crash applications by sending a specially crafted image file. The attacker exploits how the library processes certain image formats (JXL and HEIF) by creating a box structure with a size field set to zero. This causes the parser to enter an infinite loop, freezing the application's event loop indefinitely. The attack requires no authentication and can be triggered remotely by any user who can send an image to an affected application.

  • CVE-2025-71330HIGH 7.5

    The image-size Node.js library through version 2.0.2 contains a denial-of-service flaw that allows attackers to freeze an application's event loop indefinitely. By sending a maliciously crafted ICNS image file with specific properties—valid header signature but a zero-length entry field—an attacker can cause the parser to spin in an endless loop, rendering the application unresponsive. No authentication is required, and the attack succeeds over the network against any system processing untrusted ICNS image data.

  • CVE-2025-8444MEDIUM 6.4

    A WordPress plugin called Animation Addons for Elementor (versions up to 2.6.7) allows authenticated users with contributor-level permissions to inject malicious scripts into pages. When other users visit those pages, the scripts execute in their browsers, potentially stealing session data, modifying page content, or performing actions on their behalf. The vulnerability stems from the plugin's failure to properly clean and validate user input before storing it.

  • CVE-2026-0266MEDIUM 4.8

    A stored cross-site scripting (XSS) vulnerability exists in Palo Alto Networks PAN-OS that allows an authenticated administrator to inject malicious JavaScript into the web interface. The payload persists in the system and executes when other users access the affected interface, potentially compromising their sessions or stealing sensitive data. The vulnerability requires valid administrator credentials to exploit, which significantly limits the attack surface but remains a genuine concern for insider threats or compromised admin accounts.

  • CVE-2026-0267MEDIUM 5.5

    A vulnerability in Palo Alto Networks' GlobalProtect app for macOS allows a local user to read stored passcodes that protect critical app functions. Once an attacker learns these passcodes, they can disable, disconnect, or uninstall GlobalProtect even when the app's security policy would normally prevent such actions. This is a local-only risk that requires prior access to the affected macOS device.

  • CVE-2026-0268MEDIUM 4.4

    A vulnerability in Palo Alto Networks' Prisma Access Agent for Linux allows a local user on an affected system to bypass security controls and route network traffic outside the intended VPN tunnel. This is a local attack that requires an authenticated user account and does not affect Windows, macOS, iOS, Android, or ChromeOS deployments. An attacker exploiting this could potentially access resources or send data outside the VPN tunnel without proper security monitoring.

  • CVE-2026-0269MEDIUM 5.7

    An authenticated attacker can cause a Palo Alto Networks PAN-OS firewall to reboot by sending specially crafted packets that exploit a memory corruption flaw in tunnel traffic processing. Sending multiple malicious packets repeatedly forces the firewall into maintenance mode, rendering it unavailable until manual intervention occurs. This is not a remote unauthenticated attack—the attacker must already have network access and valid credentials.

  • CVE-2026-0270HIGH 7.5

    Palo Alto Networks Cortex XSOAR running on Linux contains a flaw that lets an attacker on the same network write files to the server if they can intercept and modify network traffic in transit. The vulnerability requires the attacker to be positioned to perform a man-in-the-middle attack, but once they are, they can exploit the path traversal weakness to place arbitrary files on the host system. This is a significant risk in environments where XSOAR is exposed to untrusted network segments or where network security controls may be incomplete.

  • CVE-2026-0271HIGH 7.8

    A privilege escalation vulnerability exists in Palo Alto Networks' Prisma Access Agent on Linux systems. An attacker with local access to an affected Linux device can exploit this flaw to gain elevated privileges and run code with higher permissions than their current account level. This capability is limited to Linux deployments; Windows, macOS, iOS, Android, and ChromeOS installations are unaffected.

  • CVE-2026-0272HIGH 7.2

    CVE-2026-0272 is a privilege escalation flaw in Palo Alto Networks PAN-OS that lets an authenticated administrator with CLI access run commands as root. While the vulnerability requires pre-existing admin credentials and CLI access, the impact is severe: a malicious or compromised admin account could gain unrestricted control of the firewall. The risk is substantially reduced when CLI access is tightly limited to a small trusted group and the management interface is restricted to known internal IP ranges.

  • CVE-2026-0273HIGH 7.2

    A command injection flaw in Palo Alto Networks PAN-OS allows any authenticated administrator who can reach the CLI or web management interface to execute arbitrary commands with root privileges. The vulnerability affects PA-Series, VM-Series firewalls, and Panorama deployments, but not Cloud NGFW or Prisma Access. While the flaw requires legitimate admin credentials to exploit, an insider threat or compromised admin account could lead to complete system compromise. The risk is materially lower when CLI access is tightly restricted and the management interface is isolated to trusted internal networks only.

  • CVE-2026-0274CRITICAL 9.1

    A security flaw in how Palo Alto Networks' Cortex XSIAM and Cortex XSOAR platforms validate credentials when integrated with Commvault SecurityIQ allows attackers without authentication to gain access to sensitive resources and make unauthorized changes. Because no login is required and the flaw can be exploited over a network, this poses an immediate and severe risk to organizations using this integration.

  • CVE-2026-10142HIGH 7.5

    kafka-python versions before 2.3.2 contain a denial-of-service flaw that allows attackers to crash or freeze Kafka client applications. By sending a malformed network message with an oversized frame length, an attacker positioned as a rogue broker or intercepting traffic can force the client to either allocate massive amounts of memory (potentially gigabytes) or encounter an error that leaves the connection broken. When this happens, consumer applications stop responding to heartbeat signals and become unresponsive until manually restarted.

  • CVE-2026-10143HIGH 7.5

    kafka-python versions before 2.3.2 contain a denial-of-service flaw in their SCRAM authentication mechanism. When connecting to a Kafka broker, the client accepts an iteration count from the broker without validation and passes it directly to a cryptographic hashing function. A malicious broker or attacker positioned between client and broker can send an extremely large iteration count, causing the client's event loop to freeze during authentication. This blocks all Kafka operations—producers cannot send messages, consumers cannot poll, admin commands fail, and heartbeats stop. Frozen clients are evicted from consumer groups and enter a cycle of reconnection failures, effectively denying service to applications relying on Kafka.

  • CVE-2026-10740MEDIUM 5.3

    AWS's s2n-quic library contains a memory management flaw in its QUIC protocol handler that can be triggered by specially crafted network packets. An unauthenticated attacker can exploit this remotely to degrade service availability by exhausting server memory, without needing credentials or user interaction. The vulnerability affects versions before 1.8.2.

  • CVE-2026-10846HIGH 7.5

    NLnet Labs ldns, a DNS library used by many applications for DNS resolution, contains a critical validation flaw in its UDP stub resolver implementation. When applications use ldns to resolve DNS queries over UDP, the library fails to properly verify that responses match their requests—it doesn't check the source address, port, query ID, or even the question being asked. This oversight enables attackers on the network to inject malicious DNS responses without being on the direct path between the client and the legitimate DNS server, a technique known as off-path poisoning. The drill diagnostic tool bundled with ldns is directly affected.

  • CVE-2026-11417HIGH 7.3

    AWS CDK (Cloud Development Kit) contains a command injection vulnerability in how it bundles Node.js functions for local development and deployment. An attacker who can control certain bundling settings—such as external modules, code definitions, loaders, injections, or esbuild arguments—can inject shell commands that execute on the developer's machine when the CDK toolchain runs. This requires an attacker to have influence over the CDK application configuration, making it relevant primarily in shared development environments or when developers use untrusted CDK configurations.

  • CVE-2026-11596MEDIUM 4.7

    ScreenConnect versions before 26.2 contain a weakness in how it validates input when administrators or authorized users create Host Pass tokens—special access credentials that grant temporary delegated access. An authenticated user with Host Pass creation privileges can bypass the intended expiration time limits and specify tokens that remain valid far longer than intended, potentially allowing extended unauthorized access to systems after the token should have expired.

  • CVE-2026-11837HIGH 7.3

    A vulnerability in Ansible's posix authorized_key module allows a local user to escalate their privileges to root. The flaw stems from how the module handles SSH key file operations: it follows symbolic links when changing file ownership instead of operating directly on the link itself. An attacker with a local account can create malicious symbolic links in their .ssh directory, then wait for a system administrator to run an Ansible task that manages authorized keys with elevated privileges. When that happens, the module will change ownership of arbitrary files on the system—potentially giving the attacker control over critical system files and full system access.

  • CVE-2026-11852MEDIUM 6.5

    Debusine, a tool used to build and maintain Debian-based Linux distributions, contains a permission-checking flaw in its artifact management system. When users or services create or delete relationships between artifacts (the packaged components that make up a distribution), the system fails to verify whether the requester has authorization to perform those actions. An attacker who can see an artifact can manipulate its relationships without proper permission checks, potentially corrupting the integrity of a distribution build or exposing sensitive artifacts to unauthorized access.

  • CVE-2026-11853MEDIUM 6.5

    Debusine, a tool for building and maintaining Debian-based Linux distributions, contains a vulnerability in how it parses Debian package manifest files (.dsc and .changes files). These manifests list the files that make up a software package. An attacker can craft malicious manifest files that trick Debusine's parser into creating symbolic links (shortcuts) pointing anywhere on the system. If exploited during the "mergeuploads" task, this could allow an attacker to overwrite files that the Debusine worker process has permission to access, potentially compromising the integrity of package builds or the system itself.

  • CVE-2026-11884MEDIUM 6.5

    A flaw in 389 Directory Server allows an attacker with administrative privileges—or someone controlling a replication server—to crash the service by creating directory object definitions with unusually long inheritance fields. The underlying issue is that the server calculates buffer space without accounting for the full size of these fields, leading to memory corruption when data is written. This is a remnant of an earlier incomplete patch attempt.

  • CVE-2026-1220HIGH 7.5

    A race condition in Google Chrome's V8 JavaScript engine could allow an attacker to trick the browser into confusing data types when processing a malicious webpage. An attacker would need to craft a specific HTML page and convince a user to visit it, but if successful, the vulnerability could lead to information disclosure, data tampering, or application crashes. Chrome versions before 144.0.7559.99 are affected.

  • CVE-2026-20251HIGH 8.8

    A vulnerability in Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway allows low-privileged users without admin or power roles to execute arbitrary code remotely. The flaw stems from unsafe deserialization of data stored in Splunk's KV Store (key-value store) component. An attacker only needs basic user credentials to potentially compromise the entire Splunk environment. This is a serious issue because privilege escalation to code execution typically requires administrative access; this vulnerability bypasses that requirement entirely.

  • CVE-2026-20252HIGH 7.6

    A vulnerability in Splunk Enterprise and Splunk Cloud Platform allows low-privileged users to make unauthorized server-side requests to internal systems through the PDF export feature in Dashboard Studio. The flaw stems from weak validation of trusted domains—attackers can bypass the allowlist by registering subdomains (e.g., docs.splunk.com.evil.com) and leveraging automatic HTTP redirect following to reach unintended targets. An authenticated user without admin or power roles can exploit this to probe or attack internal infrastructure.

  • CVE-2026-20253KEVCRITICAL 9.8

    An unauthenticated attacker can create or delete files on Splunk Enterprise systems through an unprotected PostgreSQL service interface. The vulnerability affects Splunk 10.2 before version 10.2.4 and Splunk 10 before 10.0.7. Because no credentials are required and the service is accessible over the network, any attacker who can reach the affected system can exploit this without authentication. Splunk 9.4 and earlier versions are unaffected.

  • CVE-2026-20254MEDIUM 5.7

    A vulnerability in Splunk Enterprise and Splunk Cloud Platform allows low-privileged users to create malicious dashboards that steal sensitive data when viewed by administrators or power users. The attack works by injecting CSS code into dashboard styling that bypasses Splunk's security controls designed to prevent outbound connections to untrusted servers. An attacker without admin privileges can craft a specially designed 'classic' dashboard that, when opened by someone with higher permissions, silently sends sensitive information—including credentials—to a server they control.