synced 7 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

391,183 records · updated every 15 minutes

02 Telemetry

Total CVEs391,183
New today383
Known-exploited (KEV)1,708
Sync lag18 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-558326.1Medium6.1MediumTract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnxsonos tract24 MIN AGO
CVE-2026-541815.4Medium5.4Mediumbackpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are invertedlaravel-backpack crud26 MIN AGO
CVE-2026-541776.6Medium6.6Mediumbackpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserverlaravel-backpack crud27 MIN AGO
CVE-2026-541766.5Medium6.5Mediumbackpack/crud: MyAccountController allows changing the login email without a current-password checklaravel-backpack crud28 MIN AGO
CVE-2026-541807.6High7.6Highbackpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)laravel-backpack crud29 MIN AGO
CVE-2026-910816.9Medium6.9MediumDocs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpointsuitenumerique docs29 MIN AGO
CVE-2026-910808.7High8.7Highwebhook through 2.8.3 Memory Exhaustion via Oversized Request Bodyadnanh webhook29 MIN AGO
CVE-2026-910796.3Medium6.3MediumHuly Platform through 0.7.426 SSRF via Print Servicehcengineering platform29 MIN AGO
CVE-2026-909468.7High8.7HighDeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocketasyncfuncai deepwiki-open29 MIN AGO
CVE-2026-909459.3Critical9.3CriticalCrawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secretcrawlab-team crawlab29 MIN AGO
CVE-2026-909448.8High8.8HighKrayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parsekrayin laravel-crm29 MIN AGO
CVE-2026-909429.3Critical9.3CriticalCasdoor through 4.4.0 Private Key Exposure via Certificate Endpointscasdoor casdoor29 MIN AGO
CVE-2026-575706.5Medium6.5Mediumbackpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelationlaravel-backpack crud30 MIN AGO
CVE-2026-541788.1High8.1Highbackpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisklaravel-backpack crud32 MIN AGO
CVE-2026-541828.1High8.1Highbackpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)laravel-backpack crud33 MIN AGO

05 Recently added to KEV

KEVCVE-2026-84869connectwise screenconnectAdded 2026-09-11
KEVCVE-2026-42018jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-42016jfrog artifactoryAdded 2026-09-11
KEVCVE-2026-86060mikrotik routerosAdded 2026-09-10
KEVCVE-2026-67277mikrotik routerosAdded 2026-09-10
KEVCVE-2026-87491google chromeAdded 2026-09-09