02 Telemetry
FEED: ACQUIRING
03 Severity mix
WINDOW: T-30D
04 Latest published
FEED: ACQUIRING
01 Search consoleIDX: 384,699
The CVE corpus, on scope in milliseconds.
384,699 records · updated every 15 minutes
02 Telemetry
FEED: LIVETotal CVEs384,699
New today29
Known-exploited (KEV)1,685
Sync lag13 MIN
03 Severity mix
WINDOW: T-30D
CRITICAL 15%HIGH 46%MEDIUM 36%LOW 4%NONE 0%
04 Latest published
LAST 15 / 15-MIN SYNCCVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-826116.9Medium—6.9Mediumitsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injectionitsourcecode online medicine delivery system25 MIN AGO CVE-2026-826106.9Medium—6.9Mediumitsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injectionitsourcecode online medicine delivery system40 MIN AGO CVE-2026-827252.3Low—2.3LowAshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related dataash-project ash_phoenix46 MIN AGO CVE-2026-827247.6High—7.6HighBroken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomainash-project ash_phoenix47 MIN AGO CVE-2026-827266.3Medium—6.3MediumAshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenantash-project ash_phoenix49 MIN AGO CVE-2026-827272.3Low—2.3LowAshPhoenix Form.Auto leaks submitted params in an unknown _union_type error messageash-project ash_phoenix51 MIN AGO CVE-2026-826095.3Medium—5.3Mediumitsourcecode Sales and Inventory System inv_edit.php sql injectionitsourcecode sales and inventory system55 MIN AGO CVE-2026-826076.9Medium—6.9MediumCozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted uploadcozmoslabs profile builder plugin1 HR AGO CVE-2026-818522.1Low—2.1LowAshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypassash-project ash_admin1 HR AGO CVE-2026-826812.0Low—2.0LowQuery-parameter injection in AshAdmin row-action links via unencoded string primary keysash-project ash_admin1 HR AGO CVE-2026-778508.4High—8.4HighStored XSS in AshAdmin relationship typeahead via unescaped label_field contentash-project ash_admin1 HR AGO CVE-2026-827228.3High—8.3HighAshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)ash-project ash_admin1 HR AGO CVE-2026-757578.3High—8.3HighAshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomainash-project ash_admin1 HR AGO CVE-2026-826055.3Medium—5.3MediumBareBones BBEdit Lasso Language Tokenizer infinite loopbarebones bbedit1 HR AGO CVE-2026-826045.3Medium—5.3MediumBareBones BBEdit Java Language recursionbarebones bbedit1 HR AGO 05 Recently added to KEV
SRC: CISAKEVCVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has noAdded 2026-08-27