synced 11 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

401,464 records · updated every 15 minutes

02 Telemetry

Total CVEs401,464
New today370
Known-exploited (KEV)1,734
Sync lag17 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1054445.3Medium—5.3Mediumdotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injectiondotnet eshop21 MIN AGO
CVE-2026-1057417.1High—7.1HighLangflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Writelangflow-ai langflow26 MIN AGO
CVE-2026-1057409.9Critical—9.9CriticalLangflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the serverlangflow-ai langflow35 MIN AGO
CVE-2026-1054385.3Medium—5.3MediumO2OA General url ActionUploadExcelWithUrl server-side request forgeryo2oa36 MIN AGO
CVE-2026-1057737.3High—7.3HighCanimaan Software ClamXAV local privilege escalationcanimaan software clamxav43 MIN AGO
CVE-2026-1056997.1High—7.1HighLangflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlerslangflow-ai langflow44 MIN AGO
CVE-2026-1022627.0High—7.0HighNewell Brands DYMO ID parent directory open to path traversal through improper spheres of controlnewell brands dymo id44 MIN AGO
CVE-2026-1018935.1Medium—5.1MediumNewell Brands DYMO ID document parsing failing file type extension authentication checknewell brands dymo id45 MIN AGO
CVE-2026-1054475.5Medium—5.5MediumQuay: quay: global read-only superuser can access build trigger write credentialsred hat red hat quay 352 MIN AGO
CVE-2026-849006.8Medium—6.8MediumHP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updateshp inc thinpro 8.1 hp inc thinpro 953 MIN AGO
CVE-2026-772269.2Critical—9.2CriticalCamunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpointcamunda camunda 756 MIN AGO
CVE-2026-1056985.4Medium—5.4MediumLangflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpointslangflow-ai langflow langflow-ai langflow-base1 HR AGO
CVE-2026-1057686.3Medium—6.3Mediumapko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as rootchainguard-dev apko1 HR AGO
CVE-2026-1056979.9Critical—9.9CriticalLangflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurationlangflow-ai langflow langflow-ai langflow-base langflow-ai lfx1 HR AGO
CVE-2026-933266.0Medium—6.0MediumCrafted Git build source can bypass certain policy validationmoby buildkit1 HR AGO

05 Recently added to KEV

KEVCVE-2026-88779netscaler adc netscaler gatewayAdded 2026-10-04
KEVCVE-2026-102490zammad gmbh zammadAdded 2026-10-02
KEVCVE-2026-102489zammad gmbh zammadAdded 2026-10-02
KEVCVE-2026-104286fortinet fortimailAdded 2026-10-01
KEVCVE-2026-76504cisco cisco catalyst sd-wan managerAdded 2026-09-30
KEVCVE-2026-86950apple ios and ipados apple macosAdded 2026-09-29