synced 6 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

390,671 records · updated every 15 minutes

02 Telemetry

Total CVEs390,671
New today5
Known-exploited (KEV)1,708
Sync lag23 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-904939.3Critical9.3CriticalTonec Internet Download Manager Kernel Driver idmwfp.sys access controltonec internet download manager23 MIN AGO
CVE-2026-906688.7High8.7HighThe webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption andunrealircd unrealircd1 HR AGO
CVE-2026-904925.3Medium5.3Mediumwebgjc web_robot web.py controller_recover os command injectionwebgjc web_robot1 HR AGO
CVE-2026-904915.3Medium5.3Mediumsanjevirau gsubs Electron index.js showQuerySuccessPage code injectionsanjevirau gsubs2 HR AGO
CVE-2026-904905.3Medium5.3Mediumlenve vhr MailReceiver deserializationlenve vhr2 HR AGO
CVE-2026-906518.1High8.1HighSocket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configurationsocket socket firewall3 HR AGO
CVE-2026-904895.1Medium5.1MediumXuxueli xxl-job insert cross site scriptingxuxueli xxl-job3 HR AGO
CVE-2026-906487.1High7.1Highwasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() inwebassembly wabt4 HR AGO
CVE-2026-904885.3Medium5.3MediumXuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injectionxuxueli xxl-job4 HR AGO
CVE-2026-904875.3Medium5.3MediumXuxueli xxl-job JobGroupController.java privileges managementxuxueli xxl-job4 HR AGO
CVE-2026-904865.3Medium5.3MediumopenstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgeryopenstatushq openstatus4 HR AGO
CVE-2026-906479.1Critical9.1CriticalASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows akalkitech ase2000 v2 communication test set4 HR AGO
CVE-2026-793003.5Low3.5LowSEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Activesep sesam5 HR AGO
CVE-2026-904856.8Medium6.8MediumIOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereferenceiobit uninstaller6 HR AGO
CVE-2026-906167.4High7.4HighIn Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a differentflatpak flatpak7 HR AGO

05 Recently added to KEV

KEVCVE-2026-84869connectwise screenconnectAdded 2026-09-11
KEVCVE-2026-42018jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-42016jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-86060mikrotik routerosAdded 2026-09-10
KEVCVE-2026-67277mikrotik routerosAdded 2026-09-10
KEVCVE-2026-87491google chromeAdded 2026-09-09