synced 11 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

389,949 records · updated every 15 minutes

02 Telemetry

Total CVEs389,949
New today81
Known-exploited (KEV)1,705
Sync lag15 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-170377.2High7.2HighKirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameterthemeum kirki – freeform page builder, website builder & customizer23 MIN AGO
CVE-2026-878595.3Medium5.3Mediummorgan vulnerable to Log Injection via unescaped double quote in quoted log fieldsmorgan morgan35 MIN AGO
CVE-2026-478399.2Critical9.2CriticalFederated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admincloud foundry foundation cf-deployment cloud foundry foundation uaa36 MIN AGO
CVE-2026-804698.3High8.3HighCVE-2026-80469sick ag sentio creator extension 'device manager'1 HR AGO
CVE-2026-194868.7High8.7HighSSRF in Gemini Enterprise Agent Platform App Buildergoogle cloud gemini enterprise agent platform app builder1 HR AGO
CVE-2026-877276.9Medium6.9Mediuma-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.appleple inc. a-blog cms1 HR AGO
CVE-2025-156797.3High7.3HighBMC root account active without passwordbull bullsequana xh3406 bull bullsequana xh35151 HR AGO
CVE-2026-66406.4Medium6.4MediumMedia Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameterdglingren media library assistant2 HR AGO
CVE-2026-66426.4Medium6.4MediumMedia Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Importdglingren media library assistant2 HR AGO
CVE-2026-66416.4Medium6.4MediumMedia Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameterdglingren media library assistant2 HR AGO
CVE-2026-891795.3Medium5.3MediumHowyar|WeenyGenius - Missing Support for Integrity Checkhowyar weenygenius2 HR AGO
CVE-2026-891788.7High8.7HighHowyar|WeenyGenius - Origin Validation Errorhowyar weenygenius2 HR AGO
CVE-2026-891778.7High8.7HighHowyar|WeenyGenius - Use of Insecure Protocolhowyar weenygenius2 HR AGO
CVE-2026-891768.7High8.7HighHowyar|WeenyGenius - Missing Authenticationhowyar weenygenius2 HR AGO
CVE-2026-891756.9Medium6.9MediumKingdom Communication Associated|Smart Video Intercom System - Client-Side Authenticationkingdom communication associated eh1000b kingdom communication associated eh2070 kingdom communication associated eh3040 kingdom communication associated eh42002 HR AGO

05 Recently added to KEV

KEVCVE-2026-86060mikrotik routerosAdded 2026-09-10
KEVCVE-2026-67277mikrotik routerosAdded 2026-09-10
KEVCVE-2026-87491google chromeAdded 2026-09-09
KEVCVE-2026-20079cisco cisco secure firewall management center (fmc)Added 2026-09-09
KEVCVE-2026-19490netscaler adc netscaler gatewayAdded 2026-09-09
KEVCVE-2025-25249fortinet fortios fortinet fortiswitchmanagerAdded 2026-09-09