02 Telemetry
FEED: ACQUIRING
03 Severity mix
WINDOW: T-30D
04 Latest published
FEED: ACQUIRING
01 Search consoleIDX: 383,404
The CVE corpus, on scope in milliseconds.
383,404 records · updated every 15 minutes
02 Telemetry
FEED: LIVETotal CVEs383,404
New today3
Known-exploited (KEV)1,681
Sync lag110 MIN
03 Severity mix
WINDOW: T-30D
CRITICAL 15%HIGH 45%MEDIUM 36%LOW 3%NONE 0%
04 Latest published
LAST 15 / 15-MIN SYNCCVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-193986.8Medium—6.8Medium“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) or BIOS corruption via aasus fa507nu asus fa507nv1 HR AGO CVE-2026-814866.9Medium—6.9Mediumbsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversalbsmi021 mcp-file-context-server2 HR AGO CVE-2026-814856.9Medium—6.9Mediumdanielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path traversaldanielpopamd linkedin-ads-mcp2 HR AGO CVE-2026-478745.3Medium—5.3MediumReactor Netty HTTP Server Denial of Service With Pipelined Requestsspring reactor netty4 HR AGO CVE-2026-478616.3Medium—6.3MediumUDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=falsespring spring integration4 HR AGO CVE-2026-814216.9Medium—6.9Mediumddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgeryddfourtwo sentry-selfhosted-mcp4 HR AGO CVE-2026-478635.9Medium—5.9MediumReactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flushspring reactor core4 HR AGO CVE-2026-478625.4Medium—5.4MediumZipTransformer uses file_name header to build workDirectory path without sanitizationspring spring integration4 HR AGO CVE-2026-478606.5Medium—6.5MediumUnbounded decompression of attacker-supplied compressed message bodiesspring spring amqp4 HR AGO CVE-2026-478595.4Medium—5.4MediumUnbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoSspring spring integration4 HR AGO CVE-2026-478575.9Medium—5.9MediumReactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-aroundspring reactor core4 HR AGO CVE-2026-478566.3Medium—6.3MediumJsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-listspring spring integration4 HR AGO CVE-2026-478527.5High—7.5HighPredictable cache directory location allows local ONNX model substitution in Spring AIspring spring ai4 HR AGO CVE-2026-478517.5High—7.5HighUnbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Readerspring spring ai4 HR AGO CVE-2026-478504.3Medium—4.3MediumSpring Data REST allows mutation of the version property of immutable aggregates via PUTspring spring data rest4 HR AGO 05 Recently added to KEV
SRC: CISAKEVCVE-2019-1068microsoft microsoft sql server microsoft microsoft sql server 2014 service pack 2 for 32-bit systems (gdr) microsoft microsoft sql server 2014 service pack 2 for x64-based systems (gdr) microsoft microsoft sql server 2014 service pack 3 for 32-bit systems (cu) microsoft microsoft sql server 2014 service pack 3 for 32-bit systems (gdr) microsoft microsoft sql server 2014 service pack 3 forAdded 2026-08-26 KEVCVE-2015-5287The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictableAdded 2026-08-26 KEVCVE-2015-3246libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of serviceAdded 2026-08-26