02 Telemetry
FEED: ACQUIRING
03 Severity mix
WINDOW: T-30D
04 Latest published
FEED: ACQUIRING
01 Search consoleIDX: 385,446
The CVE corpus, on scope in milliseconds.
385,446 records · updated every 15 minutes
02 Telemetry
FEED: LIVETotal CVEs385,446
New today24
Known-exploited (KEV)1,687
Sync lag13 MIN
03 Severity mix
WINDOW: T-30D
CRITICAL 15%HIGH 45%MEDIUM 36%LOW 4%NONE 0%
04 Latest published
LAST 15 / 15-MIN SYNCCVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-197548.6High—8.6HighBaserow 2.3.3 - SQL injection in formula index() JSONB array extractionbaserow baserow23 MIN AGO CVE-2026-844424.8Medium—4.8MediumMapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt getDataColumn path traversalmapquest get directions app1 HR AGO CVE-2026-149828.1High—8.1HighWP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameterjoomunited wp file download1 HR AGO CVE-2026-149577.5High—7.5HighFIPS mode assertion failure via malicious CERT payloadthe libreswan project libreswan1 HR AGO CVE-2026-844416.9Medium—6.9MediumPiwigo Image Derivative i.php path traversalpiwigo1 HR AGO CVE-2026-844385.1Medium—5.1MediumOpenCart Autocomplete Workflow edit.php cross site scriptingopencart2 HR AGO CVE-2026-829686.4Medium—6.4MediumKeycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providersred hat red hat build of keycloak red hat red hat single sign-on 72 HR AGO CVE-2026-844375.1Medium—5.1MediumOpenCart Autocomplete Workflow address.php cross site scriptingopencart2 HR AGO CVE-2026-847158.7High—8.7HighFeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Updatemythicalltd featherpanel2 HR AGO CVE-2026-844858.7High—8.7HighAPITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpointapitable apitable2 HR AGO CVE-2026-844848.7High—8.7HighION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnvnasa-jpl ion-dtn2 HR AGO CVE-2026-844314.8Medium—4.8MediumAirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path traversalairasia move app2 HR AGO CVE-2026-844305.3Medium—5.3Mediumgouguoa edit_personal Endpoint Index.php update dynamically-determined object attributesgouguoa3 HR AGO CVE-2026-847028.7High—8.7Highfacefusion before 3.7.0 Path Traversal via Job Identifierfacefusion facefusion3 HR AGO CVE-2026-847015.1Medium—5.1MediumNocoBase Rich Text Field Stored Cross-Site Scripting via APInocobase nocobase3 HR AGO 05 Recently added to KEV
SRC: CISAKEVCVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has noAdded 2026-08-27