01 Search console
The CVE corpus, on scope in milliseconds.
391,183 records · updated every 15 minutes
02 Telemetry
Total CVEs391,183
New today383
Known-exploited (KEV)1,708
Sync lag18 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-558326.1Medium—Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnxsonos tract24 MIN AGO
CVE-2026-541815.4Medium—backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are invertedlaravel-backpack crud26 MIN AGO
CVE-2026-541776.6Medium—backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserverlaravel-backpack crud27 MIN AGO
CVE-2026-541766.5Medium—backpack/crud: MyAccountController allows changing the login email without a current-password checklaravel-backpack crud28 MIN AGO
CVE-2026-541807.6High—backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)laravel-backpack crud29 MIN AGO
CVE-2026-910816.9Medium—Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpointsuitenumerique docs29 MIN AGO
CVE-2026-910808.7High—webhook through 2.8.3 Memory Exhaustion via Oversized Request Bodyadnanh webhook29 MIN AGO
CVE-2026-910796.3Medium—Huly Platform through 0.7.426 SSRF via Print Servicehcengineering platform29 MIN AGO
CVE-2026-909468.7High—DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocketasyncfuncai deepwiki-open29 MIN AGO
CVE-2026-909459.3Critical—Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secretcrawlab-team crawlab29 MIN AGO
CVE-2026-909448.8High—Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parsekrayin laravel-crm29 MIN AGO
CVE-2026-909429.3Critical—Casdoor through 4.4.0 Private Key Exposure via Certificate Endpointscasdoor casdoor29 MIN AGO
CVE-2026-575706.5Medium—backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelationlaravel-backpack crud30 MIN AGO
CVE-2026-541788.1High—backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisklaravel-backpack crud32 MIN AGO
CVE-2026-541828.1High—backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)laravel-backpack crud33 MIN AGO