01 Search console
The CVE corpus, on scope in milliseconds.
401,464 records · updated every 15 minutes
02 Telemetry
Total CVEs401,464
New today370
Known-exploited (KEV)1,734
Sync lag17 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1054445.3Medium—dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injectiondotnet eshop21 MIN AGO
CVE-2026-1057417.1High—Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Writelangflow-ai langflow26 MIN AGO
CVE-2026-1057409.9Critical—Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the serverlangflow-ai langflow35 MIN AGO
CVE-2026-1054385.3Medium—O2OA General url ActionUploadExcelWithUrl server-side request forgeryo2oa36 MIN AGO
CVE-2026-1057737.3High—Canimaan Software ClamXAV local privilege escalationcanimaan software clamxav43 MIN AGO
CVE-2026-1056997.1High—Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlerslangflow-ai langflow44 MIN AGO
CVE-2026-1022627.0High—Newell Brands DYMO ID parent directory open to path traversal through improper spheres of controlnewell brands dymo id44 MIN AGO
CVE-2026-1018935.1Medium—Newell Brands DYMO ID document parsing failing file type extension authentication checknewell brands dymo id45 MIN AGO
CVE-2026-1054475.5Medium—Quay: quay: global read-only superuser can access build trigger write credentialsred hat red hat quay 352 MIN AGO
CVE-2026-849006.8Medium—HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updateshp inc thinpro 8.1 hp inc thinpro 953 MIN AGO
CVE-2026-772269.2Critical—Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpointcamunda camunda 756 MIN AGO
CVE-2026-1056985.4Medium—Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpointslangflow-ai langflow langflow-ai langflow-base1 HR AGO
CVE-2026-1057686.3Medium—apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as rootchainguard-dev apko1 HR AGO
CVE-2026-1056979.9Critical—Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurationlangflow-ai langflow langflow-ai langflow-base langflow-ai lfx1 HR AGO
CVE-2026-933266.0Medium—Crafted Git build source can bypass certain policy validationmoby buildkit1 HR AGO