synced 7 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

398,387 records · updated every 15 minutes

02 Telemetry

Total CVEs398,387
New today236
Known-exploited (KEV)1,726
Sync lag58 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-829019.8Critical—9.8CriticalUltra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Fieldthemefic ultra addons for contact form 72 HR AGO
CVE-2026-772038.8High—8.8HighGroups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcodeitthinx groups – memberships and access control3 HR AGO
CVE-2026-859849.8Critical—9.8CriticalminiOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parametercyberlord92 miniorange otp login, verification and sms notifications3 HR AGO
CVE-2026-971619.2Critical—9.2CriticalJoomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29lomart.fr up plugin for joomla6 HR AGO
CVE-2026-9716310.0Critical—10.0CriticalJoomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29lomart.fr up plugin for joomla6 HR AGO
CVE-2026-971628.3High—8.3HighJoomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29lomart.fr up plugin for joomla6 HR AGO
CVE-2026-971609.4Critical—9.4CriticalJoomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29lomart.fr up plugin for joomla6 HR AGO
CVE-2026-941318.3High—8.3HighJoomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0acymailing.com acymailing extension for joomla6 HR AGO
CVE-2026-941329.5Critical—9.5CriticalJoomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0acymailing.com acymailing enterprise extension for joomla6 HR AGO
CVE-2026-941309.3Critical—9.3CriticalJoomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3joomlaboat.com youtube gallery extension for joomla7 HR AGO
CVE-2026-1006265.3Medium—5.3Mediumcapgo through 12.128.2 IDOR via PUT /app icon endpointcap-go capgo.app7 HR AGO
CVE-2026-1007209.3Critical—9.3CriticalFroxlor before 2.3.12 Stored XSS via SSL certificate issuerfroxlor froxlor7 HR AGO
CVE-2026-1007197.1High—7.1HighFroxlor before 2.3.12 Credential Disclosure via DirProtections APIfroxlor froxlor7 HR AGO
CVE-2026-1007187.1High—7.1HighFroxlor before 2.3.12 Authentication Bypass via EmailSender.addfroxlor froxlor7 HR AGO
CVE-2026-1007178.5High—8.5Highfroxlor before 2.3.12 CRLF Injection via validateUrl userinfofroxlor froxlor7 HR AGO

05 Recently added to KEV

KEVCVE-2026-87902wordpress wordpressAdded 2026-09-25
KEVCVE-2026-67279mikrotik routerosAdded 2026-09-25
KEVCVE-2026-65660microsoft microsoft sharepoint enterprise server 2016 microsoft microsoft sharepoint server 2019 microsoft microsoft sharepoint server subscription editionAdded 2026-09-25
KEVCVE-2026-71362adobe adobe commerce adobe adobe commerce b2b adobe magento open sourceAdded 2026-09-24
KEVCVE-2026-5430wso2 wso2 api control plane wso2 wso2 api manager wso2 wso2 carbon api manager rest api utility wso2 wso2 traffic manager wso2 wso2 universal gatewayAdded 2026-09-24
KEVCVE-2026-94127f5 big-ipAdded 2026-09-22