01 Search console
The CVE corpus, on scope in milliseconds.
390,671 records · updated every 15 minutes
02 Telemetry
Total CVEs390,671
New today5
Known-exploited (KEV)1,708
Sync lag23 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-904939.3Critical—Tonec Internet Download Manager Kernel Driver idmwfp.sys access controltonec internet download manager23 MIN AGO
CVE-2026-906688.7High—The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption andunrealircd unrealircd1 HR AGO
CVE-2026-904925.3Medium—webgjc web_robot web.py controller_recover os command injectionwebgjc web_robot1 HR AGO
CVE-2026-904915.3Medium—sanjevirau gsubs Electron index.js showQuerySuccessPage code injectionsanjevirau gsubs2 HR AGO
CVE-2026-906518.1High—Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configurationsocket socket firewall3 HR AGO
CVE-2026-906487.1High—wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() inwebassembly wabt4 HR AGO
CVE-2026-904885.3Medium—Xuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injectionxuxueli xxl-job4 HR AGO
CVE-2026-904875.3Medium—Xuxueli xxl-job JobGroupController.java privileges managementxuxueli xxl-job4 HR AGO
CVE-2026-904865.3Medium—openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgeryopenstatushq openstatus4 HR AGO
CVE-2026-906479.1Critical—ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows akalkitech ase2000 v2 communication test set4 HR AGO
CVE-2026-793003.5Low—SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Activesep sesam5 HR AGO
CVE-2026-904856.8Medium—IOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereferenceiobit uninstaller6 HR AGO
CVE-2026-906167.4High—In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a differentflatpak flatpak7 HR AGO