01 Search console
The CVE corpus, on scope in milliseconds.
404,107 records · updated every 15 minutes
02 Telemetry
Total CVEs404,107
New today411
Known-exploited (KEV)1,739
Sync lag35 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1086805.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendTemplateAnnouncementjeecgboot jeecgboot1 HR AGO
CVE-2026-1086795.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusAnnouncementjeecgboot jeecgboot1 HR AGO
CVE-2026-1086785.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRolesjeecgboot jeecgboot1 HR AGO
CVE-2026-1086777.1High—JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByNamejeecgboot jeecgboot1 HR AGO
CVE-2026-1086765.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/downLoadFilesjeecgboot jeecgboot1 HR AGO
CVE-2026-1086755.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/editIzTopjeecgboot jeecgboot1 HR AGO
CVE-2026-1086745.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /openapi/queryByIdjeecgboot jeecgboot1 HR AGO
CVE-2026-1086735.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/exportXlsjeecgboot jeecgboot1 HR AGO
CVE-2026-1086725.3Medium—JeecgBoot through 3.9.5 Authorization Bypass via /airag/video/listByUserjeecgboot jeecgboot1 HR AGO
CVE-2026-1086717.1High—JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryByIdjeecgboot jeecgboot1 HR AGO
CVE-2026-1086705.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/experimentjeecgboot jeecgboot1 HR AGO
CVE-2026-1086695.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /airag/knowledge/embedding/searchjeecgboot jeecgboot1 HR AGO
CVE-2026-1086685.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBinjeecgboot jeecgboot1 HR AGO
CVE-2026-1086675.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/revertRecycleBinjeecgboot jeecgboot1 HR AGO
CVE-2026-1086665.3Medium—JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatchjeecgboot jeecgboot1 HR AGO
05 Recently added to KEV
KEVCVE-2023-22894Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that containAdded 2026-10-08
KEVCVE-2021-3199Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.Added 2026-10-08
KEVCVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related toAdded 2026-10-08
KEVCVE-2015-5477named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.Added 2026-10-08
KEVCVE-2015-3306The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.Added 2026-10-08