synced 14 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

390,577 records · updated every 15 minutes

02 Telemetry

Total CVEs390,577
New today5
Known-exploited (KEV)1,708
Sync lag29 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-8570610.0Critical10.0CriticalImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab gitlab36 MIN AGO
CVE-2026-877199.9Critical9.9CriticalDeserialization of Untrusted Data in GitLabgitlab gitlab36 MIN AGO
CVE-2026-904676.3Medium6.3Mediumaiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addressescole aiosmtplib1 HR AGO
CVE-2026-892685.1Medium5.1MediumQloApps through 1.7.0 Reflected XSS via List Filter Parameterswebkul qloapps1 HR AGO
CVE-2026-892675.3Medium5.3Mediumstarlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypassjowilf starlette-admin1 HR AGO
CVE-2026-892668.8High8.8Highstb_vorbis through 1.22 heap buffer overflow via codebook multiplicandsnothings stb_vorbis3 HR AGO
CVE-2026-904576.9Medium6.9MediumThe administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissionscisa malcolm5 HR AGO
CVE-2026-904569.2Critical9.2CriticalAn example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file intocisa malcolm5 HR AGO
CVE-2026-904556.3Medium6.3MediumA prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processingcisa malcolm5 HR AGO
CVE-2026-904545.3Medium5.3MediumA deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tagscisa malcolm5 HR AGO
CVE-2026-904535.1Medium5.1MediumA file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. Thiscisa malcolm5 HR AGO
CVE-2026-904526.0Medium6.0MediumRequests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attackercisa malcolm5 HR AGO
CVE-2026-904518.2High8.2HighAn example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies thiscisa malcolm5 HR AGO
CVE-2026-904505.3Medium5.3MediumThe application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any requestcisa malcolm5 HR AGO
CVE-2026-904496.9Medium6.9MediumWhen a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway'scisa malcolm5 HR AGO

05 Recently added to KEV

KEVCVE-2026-84869connectwise screenconnectAdded 2026-09-11
KEVCVE-2026-42018jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-42016jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-86060mikrotik routerosAdded 2026-09-10
KEVCVE-2026-67277mikrotik routerosAdded 2026-09-10
KEVCVE-2026-87491google chromeAdded 2026-09-09