01 Search console
The CVE corpus, on scope in milliseconds.
400,482 records · updated every 15 minutes
02 Telemetry
Total CVEs400,482
New today362
Known-exploited (KEV)1,731
Sync lag20 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-344937.2High—- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.johnson controls easyio fs3223 MIN AGO
CVE-2026-7144910.0Critical—: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.johnson controls easyio fs3225 MIN AGO
CVE-2026-714485.6Medium—: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.johnson controls easyio fs3226 MIN AGO
CVE-2026-714545.8Medium—Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affectscwe-79 - cross-site scripting capec-6329 MIN AGO
CVE-2026-714535.6Medium—- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.johnson controls easyio fs3232 MIN AGO
CVE-2026-1040518.8High—PictShare < 3.7.1 Sensitive Information Disclosure via info APIhascheksolutions pictshare33 MIN AGO
CVE-2026-714528.4High—- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.johnson controls easyio fs3235 MIN AGO
CVE-2026-1040026.0Medium—Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)aws powertools-lambda-python36 MIN AGO
CVE-2026-714517.2High—- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.johnson controls easyio fs3242 MIN AGO
CVE-2026-278745.9Medium—: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.johnson controls easyio fs3246 MIN AGO
CVE-2026-1023705.4Medium—Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71tp-link systems inc. kasa ec70 v4 tp-link systems inc. kasa ec71 v454 MIN AGO
CVE-2026-1040208.7High—Uncontrolled recursion in the Ion reader in Amazon Ion Pythonamazon ion-python1 HR AGO
CVE-2026-967808.2High—figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small widthpatorjk figlet.js1 HR AGO
CVE-2026-1041835.1Medium—stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objectsuhop stream-json1 HR AGO
CVE-2026-1041826.2Medium—stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunkuhop stream-json1 HR AGO