synced 9 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

402,494 records · updated every 15 minutes

02 Telemetry

Total CVEs402,494
New today987
Known-exploited (KEV)1,734
Sync lag17 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1064974.3Medium—4.3MediumBackstage: Inconsistent catalog property permission evaluation@backstage plugin-catalog-backend backstage backstage22 MIN AGO
CVE-2026-97208—Unrated——UnratedGitea push mirror API bypass of DISABLE_NEW_PUSH policygitea gitea23 MIN AGO
CVE-2026-1064963.1Low—3.1LowBackstage: Inconsistent enforcement of allowed location types during catalog processing@backstage plugin-catalog-backend backstage backstage23 MIN AGO
CVE-2026-86684—Unrated——UnratedGitea push mirror local path check uses the repository ownergitea gitea23 MIN AGO
CVE-2026-1065883.1Low—3.1LowIn sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.openbsd openssh31 MIN AGO
CVE-2026-651427.8High—7.8HighNVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering,nvidia model-optimizer37 MIN AGO
CVE-2026-1065873.6Low—3.6LowIn sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.openbsd openssh39 MIN AGO
CVE-2026-651225.5Medium—5.5MediumNVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service.nvidia tensorrt39 MIN AGO
CVE-2026-1065862.5Low—2.5LowIn sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.openbsd openssh43 MIN AGO
CVE-2026-1064944.4Medium—4.4MediumBackstage: Improper input validation in cloud storage URL readers@backstage backend-defaults backstage backstage46 MIN AGO
CVE-2026-1065856.5Medium—6.5MediumIn sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.openbsd openssh48 MIN AGO
CVE-2026-1064933.0Low—3.0LowBackstage: Cloud storage catalog locations may cross configured storage boundaries@backstage plugin-catalog-backend-module-aws @backstage plugin-catalog-backend-module-azure backstage backstage48 MIN AGO
CVE-2026-1064927.6High—7.6HighBackstage: Improper preservation of access restrictions during service credential delegation@backstage backend-defaults backstage backstage52 MIN AGO
CVE-2026-1065842.5Low—2.5LowIn ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certainopenbsd openssh53 MIN AGO
CVE-2026-1064916.4Medium—6.4MediumBackstage: Improper input validation in proxy-backend@backstage plugin-proxy-backend backstage backstage55 MIN AGO

05 Recently added to KEV

KEVCVE-2026-88779netscaler adc netscaler gatewayAdded 2026-10-04
KEVCVE-2026-102490zammad gmbh zammadAdded 2026-10-02
KEVCVE-2026-102489zammad gmbh zammadAdded 2026-10-02
KEVCVE-2026-104286fortinet fortimailAdded 2026-10-01
KEVCVE-2026-76504cisco cisco catalyst sd-wan managerAdded 2026-09-30
KEVCVE-2026-86950apple ios and ipados apple macosAdded 2026-09-29