synced 1 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

398,538 records · updated every 15 minutes

02 Telemetry

Total CVEs398,538
New today139
Known-exploited (KEV)1,726
Sync lag20 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1008812.1Low—2.1Lowzhistaredu StarTraining application.yml cross site scriptingzhistaredu startraining10 MIN AGO
CVE-2026-962816.2Medium—6.2MediumFlatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimesred hat red hat enterprise linux 10 red hat red hat enterprise linux 7 red hat red hat enterprise linux 8 red hat red hat enterprise linux 924 MIN AGO
CVE-2026-1008805.1Medium—5.1Mediumzhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scriptingzhistaredu startraining25 MIN AGO
CVE-2026-1010909.3Critical—9.3CriticalNezha through 2.2.3 Host Header Injection via OAuth2 redirect_urinezhahq nezha35 MIN AGO
CVE-2026-1010892.3Low—2.3LowNezha before 2.2.7 Information Disclosure via /api/v1/profilenezhahq nezha35 MIN AGO
CVE-2026-1010886.0Medium—6.0MediumNezha before 2.3.1 Denial of Service via Concurrent Server Deletenezhahq nezha35 MIN AGO
CVE-2026-1010875.3Medium—5.3MediumNezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6nezhahq nezha35 MIN AGO
CVE-2026-1010867.1High—7.1HighNezha Dashboard before 2.3.5 Task Type Validation Bypassnezhahq nezha35 MIN AGO
CVE-2026-1010857.1High—7.1HighNezha before 2.3.8 Denial of Service via Alert Rulenezhahq nezha35 MIN AGO
CVE-2026-1010849.3Critical—9.3Criticalobot before v0.21.1 Authorization Bypass via /mcp-connectobot-platform obot35 MIN AGO
CVE-2026-1010659.3Critical—9.3CriticalObot Quickstart Docker Deployment Unauthenticated Admin Accessobot-platform obot35 MIN AGO
CVE-2026-1010648.3High—8.3HighObot before v0.23.0 Server-Side Request Forgery via MCPobot-platform obot35 MIN AGO
CVE-2026-1010636.9Medium—6.9MediumObot before v0.23.0 Authentication Bypass via Registry APIobot-platform obot35 MIN AGO
CVE-2026-1010628.7High—8.7HighObot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registrationobot-platform obot35 MIN AGO
CVE-2026-1008795.3Medium—5.3Mediumzhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed authorizationzhistaredu startraining40 MIN AGO

05 Recently added to KEV

KEVCVE-2026-87902wordpress wordpressAdded 2026-09-25
KEVCVE-2026-67279mikrotik routerosAdded 2026-09-25
KEVCVE-2026-65660microsoft microsoft sharepoint enterprise server 2016 microsoft microsoft sharepoint server 2019 microsoft microsoft sharepoint server subscription editionAdded 2026-09-25
KEVCVE-2026-71362adobe adobe commerce adobe adobe commerce b2b adobe magento open sourceAdded 2026-09-24
KEVCVE-2026-5430wso2 wso2 api control plane wso2 wso2 api manager wso2 wso2 carbon api manager rest api utility wso2 wso2 traffic manager wso2 wso2 universal gatewayAdded 2026-09-24
KEVCVE-2026-94127f5 big-ipAdded 2026-09-22