synced 4 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

395,903 records · updated every 15 minutes

02 Telemetry

Total CVEs395,903
New today243
Known-exploited (KEV)1,717
Sync lag20 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-466499.1Critical9.1CriticalJoplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpointlaurent22 joplin29 MIN AGO
CVE-2026-551796.5Medium6.5MediumJoplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server IDlaurent22 joplin30 MIN AGO
CVE-2026-598164.3Medium4.3MediumJoplin: Path traversal in transcribe proxy endpoint via URL-encoded slashlaurent22 joplin32 MIN AGO
CVE-2026-494492.5Low2.5LowJoplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windowslaurent22 joplin35 MIN AGO
CVE-2026-494537.0High7.0HighJoplin: Path traversal in resource sync — silent arbitrary file write outside the resource directorylaurent22 joplin36 MIN AGO
CVE-2026-494507.1High7.1HighJoplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherNamelaurent22 joplin38 MIN AGO
CVE-2026-799196.3Medium6.3MediumMaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)1panel-dev maxkb39 MIN AGO
CVE-2026-799186.3Medium6.3MediumMaxKB: Sandbox escape via unhooked fexecve1panel-dev maxkb39 MIN AGO
CVE-2026-945884.4Medium4.4MediumIn Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlyingproxmox pmg-api40 MIN AGO
CVE-2026-775175.4Medium5.4MediumMaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base1panel-dev maxkb40 MIN AGO
CVE-2026-7752110.0Critical10.0CriticalMaxKB: Prompt-injectable agent can lead to command execution1panel-dev maxkb41 MIN AGO
CVE-2026-944249.3Critical9.3CriticalMoore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflowmoore threads mtt s80 driver package42 MIN AGO
CVE-2026-775224.3Medium4.3MediumMaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)1panel-dev maxkb42 MIN AGO
CVE-2026-799176.5Medium6.5MediumMaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation1panel-dev maxkb43 MIN AGO
CVE-2026-775165.4Medium5.4MediumMaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path1panel-dev maxkb46 MIN AGO

05 Recently added to KEV

KEVCVE-2026-7273zyxel gs1900-10hp firmware zyxel gs1900-16 firmware zyxel gs1900-24 firmware zyxel gs1900-24e firmware zyxel gs1900-24ep firmware zyxel gs1900-24hpv2 firmware zyxel gs1900-48 firmware zyxel gs1900-48hpv2 firmware zyxel gs1900-8 firmware zyxel gs1900-8hp firmwareAdded 2026-09-21
KEVCVE-2026-53266linux linuxAdded 2026-09-18
KEVCVE-2025-39964linux linuxAdded 2026-09-18
KEVCVE-2025-39682linux linuxAdded 2026-09-18
KEVCVE-2026-87886acronis acronis backup extension for plesk acronis acronis backup plugin for cpanel & whm acronis acronis backup plugin for directadminAdded 2026-09-16
KEVCVE-2026-76460cisco cisco identity services engine software cisco cisco ise passive identity connectorAdded 2026-09-16