synced 1 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

404,332 records · updated every 15 minutes

02 Telemetry

Total CVEs404,332
New today225
Known-exploited (KEV)1,739
Sync lag74 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1089767.8High—7.8HighGNU Emacs before 31.2 (and TRAMP through 2.8.2) allows OS command injection via a filename because tramp-user-regexp has an incomplete list of disallowed inputs. NOTE: this issue exists because of angnu emacs1 HR AGO
CVE-2026-1089638.8High—8.8Highdatabasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example,david-crty databasement1 HR AGO
CVE-2026-1087685.3Medium—5.3Mediumzhayujie CowAgent Streaming Tool-Call Argument json.loads allocation of resourceszhayujie cowagent2 HR AGO
CVE-2026-1089256.1Medium—6.1MediumCohesity - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)cohesity netbackup administration console web interface3 HR AGO
CVE-2026-595085.9Medium—5.9MediumInteruse i-Bos CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')interuse i-bos3 HR AGO
CVE-2026-197406.5Medium—6.5MediumBluetooth LE Controller: retained RX node leak and reachable assertion in the PHY Update procedurezephyrproject zephyr4 HR AGO
CVE-2026-197396.5Medium—6.5MediumBluetooth LE controller leaks a retained RX node when an unexpected LL Control PDU arrives during a Connection Updatezephyrproject zephyr4 HR AGO
CVE-2026-197386.5Medium—6.5MediumRetained RX node leak and reachable assertion in Bluetooth Controller CIS Create procedureszephyrproject zephyr4 HR AGO
CVE-2026-199357.5High—7.5HighUse-after-free of an L2CAP CoC channel object in the Zephyr Bluetooth host: RX work item is not cancelled on channel teardownzephyrproject zephyr4 HR AGO
CVE-2026-197375.5Medium—5.5MediumNULL pointer dereference in the ESP32 I2S driver when triggering an unsupported directionzephyrproject zephyr4 HR AGO
CVE-2026-184183.4Low—3.4LowOut-of-bounds read when the zbus proxy agent IPC backend logs a rejected peer frame's channel namezephyrproject zephyr4 HR AGO
CVE-2026-197367.8High—7.8HighOut-of-bounds write in the NXP MCUX TRNG entropy driver for non-word-multiple request lengthszephyrproject zephyr4 HR AGO
CVE-2026-197354.8Medium—4.8MediumPredictable TCP initial sequence numbers when the RFC 6528 secret key generation fails silently in the Zephyr TCP stackzephyrproject zephyr4 HR AGO
CVE-2026-195777.1High—7.1HighOut-of-bounds read in IPv6 route forwarding when the nexthop neighbor has no link-layer addresszephyrproject zephyr4 HR AGO
CVE-2026-195766.8Medium—6.8MediumStack out-of-bounds write in the Goodix GT911 touch controller driver from an unvalidated device-reported touch point countzephyrproject zephyr4 HR AGO

05 Recently added to KEV

KEVCVE-2023-22894Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that containAdded 2026-10-08
KEVCVE-2021-3199Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.Added 2026-10-08
KEVCVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related toAdded 2026-10-08
KEVCVE-2015-5477named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.Added 2026-10-08
KEVCVE-2015-3306The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.Added 2026-10-08
KEVCVE-2026-88779netscaler adc netscaler gatewayAdded 2026-10-04