01 Search console
The CVE corpus, on scope in milliseconds.
401,022 records · updated every 15 minutes
02 Telemetry
Total CVEs401,022
New today106
Known-exploited (KEV)1,733
Sync lag5 HR
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-964518.8High—WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerabilityultimate member ultimate member6 HR AGO
CVE-2026-1033427.1High—WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerabilityunlimited elements unlimited elements for elementor (free widgets, addons, templates)7 HR AGO
CVE-2026-1030658.2High—WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerabilitythemeum kirki7 HR AGO
CVE-2026-1051225.3Medium—OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uriopenidentityplatform openam9 HR AGO
CVE-2026-1051216.9Medium—OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scopingopenidentityplatform openam9 HR AGO
CVE-2026-1051206.9Medium—OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpointopenidentityplatform openam9 HR AGO
CVE-2026-1051197.6High—OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flowsopenidentityplatform openam9 HR AGO
CVE-2026-1051182.3Low—OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSessionopenidentityplatform openam9 HR AGO
CVE-2026-1051175.3Medium—OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actionsopenidentityplatform openam9 HR AGO
CVE-2026-1051165.1Medium—OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Pageopenidentityplatform openam9 HR AGO
CVE-2026-1051158.8High—OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interfaceopenidentityplatform openam9 HR AGO
CVE-2026-1051145.3Medium—OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Pageopenidentityplatform openam9 HR AGO
CVE-2026-1051137.1High—Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlocknezhahq nezha9 HR AGO
CVE-2026-1051126.0Medium—Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpointsnezhahq nezha9 HR AGO
CVE-2026-1051059.8Critical—Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltrationnasa-ammos ait-core9 HR AGO