synced JUST NOW
01 Search console

The CVE corpus, on scope in milliseconds.

401,022 records · updated every 15 minutes

02 Telemetry

Total CVEs401,022
New today106
Known-exploited (KEV)1,733
Sync lag5 HR

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-964518.8High—8.8HighWordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerabilityultimate member ultimate member6 HR AGO
CVE-2026-1033427.1High—7.1HighWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerabilityunlimited elements unlimited elements for elementor (free widgets, addons, templates)7 HR AGO
CVE-2026-1030658.2High—8.2HighWordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerabilitythemeum kirki7 HR AGO
CVE-2026-1051225.3Medium—5.3MediumOpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uriopenidentityplatform openam9 HR AGO
CVE-2026-1051216.9Medium—6.9MediumOpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scopingopenidentityplatform openam9 HR AGO
CVE-2026-1051206.9Medium—6.9MediumOpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpointopenidentityplatform openam9 HR AGO
CVE-2026-1051197.6High—7.6HighOpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flowsopenidentityplatform openam9 HR AGO
CVE-2026-1051182.3Low—2.3LowOpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSessionopenidentityplatform openam9 HR AGO
CVE-2026-1051175.3Medium—5.3MediumOpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actionsopenidentityplatform openam9 HR AGO
CVE-2026-1051165.1Medium—5.1MediumOpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Pageopenidentityplatform openam9 HR AGO
CVE-2026-1051158.8High—8.8HighOpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interfaceopenidentityplatform openam9 HR AGO
CVE-2026-1051145.3Medium—5.3MediumOpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Pageopenidentityplatform openam9 HR AGO
CVE-2026-1051137.1High—7.1HighNezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlocknezhahq nezha9 HR AGO
CVE-2026-1051126.0Medium—6.0MediumNezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpointsnezhahq nezha9 HR AGO
CVE-2026-1051059.8Critical—9.8CriticalUnauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltrationnasa-ammos ait-core9 HR AGO

05 Recently added to KEV

KEVCVE-2026-102490zammad gmbh zammadAdded 2026-10-02
KEVCVE-2026-102489zammad gmbh zammadAdded 2026-10-02
KEVCVE-2026-104286fortinet fortimailAdded 2026-10-01
KEVCVE-2026-76504cisco cisco catalyst sd-wan managerAdded 2026-09-30
KEVCVE-2026-86950apple ios and ipados apple macosAdded 2026-09-29
KEVCVE-2026-88772citrix netscaler adc citrix netscaler gatewayAdded 2026-09-27