synced 4 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

395,010 records · updated every 15 minutes

02 Telemetry

Total CVEs395,010
New today76
Known-exploited (KEV)1,711
Sync lag14 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-890587.4High7.4HighResteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard configred hat21 MIN AGO
CVE-2026-890597.5High7.5HighResteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)red hat red hat red hat build of apache camel 4 for quarkus 3 red hat red hat build of apicurio registry 3 red hat red hat build of debezium 3 red hat red hat build of keycloak red hat red hat build of quarkus red hat red hat certificate system 10 red hat red hat certificate system 11 red hat red hat enterprise linux 10 red hat red hat enterprise linux 8 red hat red hat enterprise linux 9 red hat28 MIN AGO
CVE-2024-386394.8Medium4.8MediumQTSqnap systems inc. qts50 MIN AGO
CVE-2024-271235.2Medium5.2MediumQcalAgentqnap systems inc. qcalagent52 MIN AGO
CVE-2026-925616.1Medium6.1MediumBooking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameterwpdevelop booking calendar1 HR AGO
CVE-2026-893306.1Medium6.1MediumEmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameterswpdevteam embedpress – pdf embedder, 3d pdf flipbook, google reviews, youtube videos, upload & embed pdf documents1 HR AGO
CVE-2026-892785.3Medium5.3MediumGPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Public Frontend Inline Scriptjohn-dagelmore gptranslate – multilingual ai translation agent for wordpress: translate your site with ai1 HR AGO
CVE-2026-849096.4Medium6.4MediumCustom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attributesmub custom twitter feeds – a tweets widget or x feed widget1 HR AGO
CVE-2026-121066.4Medium6.4MediumAuto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of Tagsairani auto upload images1 HR AGO
CVE-2026-926197.2High7.2HighBooking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameterwpdevelop booking calendar1 HR AGO
CVE-2026-750174.3Medium4.3MediumMagazine Blocks <= 1.8.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification / Site-Wide Template Takeover via Builder Templates REST Endpointwpblockart magazine blocks – blog designer, magazine & newspaper website builder, page builder with posts blocks, post grid1 HR AGO
CVE-2026-917075.3Medium5.3MediumDivi <= 5.11.1 - Missing Authorization to Unauthenticated Arbitrary Registered Shortcode Execution via 'content' Parameter via Shortcode Module REST Endpointelegant themes divi1 HR AGO
CVE-2026-891384.3Medium4.3MediumFilter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'image_id' Parameter via ufg_save_gallery AJAX Actionfarazfrank filter gallery1 HR AGO
CVE-2026-927146.5Medium6.5MediumDownload Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parametercodename065 download manager1 HR AGO
CVE-2026-750166.4Medium6.4MediumMagazine Blocks <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'clientId' Block Attributewpblockart magazine blocks – blog designer, magazine & newspaper website builder, page builder with posts blocks, post grid1 HR AGO

05 Recently added to KEV

KEVCVE-2026-58704google androidAdded 2026-09-16
KEVCVE-2026-76461cisco cisco secure emailAdded 2026-09-14
KEVCVE-2026-85706gitlab gitlabAdded 2026-09-11
KEVCVE-2026-84869connectwise screenconnectAdded 2026-09-11
KEVCVE-2026-42018jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-42016jfrog artifactoryAdded 2026-09-11