02 Telemetry
FEED: ACQUIRING
03 Severity mix
WINDOW: T-30D
04 Latest published
FEED: ACQUIRING
01 Search consoleIDX: 384,013
The CVE corpus, on scope in milliseconds.
384,013 records · updated every 15 minutes
02 Telemetry
FEED: LIVETotal CVEs384,013
New today4
Known-exploited (KEV)1,685
Sync lag102 MIN
03 Severity mix
WINDOW: T-30D
CRITICAL 16%HIGH 45%MEDIUM 36%LOW 4%NONE 0%
04 Latest published
LAST 15 / 15-MIN SYNCCVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-388227.6High—7.6HighIn openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET queryopennds opennds3 HR AGO CVE-2026-388217.1High—7.1HighA heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) andopennds opennds3 HR AGO CVE-2026-388208.3High—8.3HighopenNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.opennds opennds3 HR AGO CVE-2026-388195.3Medium—5.3MediumMultiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.opennds opennds3 HR AGO CVE-2026-618026.5Medium—6.5MediumWazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/configwazuh wazuh4 HR AGO CVE-2026-786164.8Medium—4.8MediumDimension Stored XSS via Trusted CA Certificate Configurationwatchguard dimension4 HR AGO CVE-2026-784985.1Medium—5.1MediumDimension Server-Side Request Forgery via Email Server Test Settingswatchguard dimension4 HR AGO CVE-2026-781955.1Medium—5.1MediumDimension Stored XSS via Backup Historical Data Featurewatchguard dimension4 HR AGO CVE-2026-786128.6High—8.6HighDimension SQL Injection in Scheduled Reportwatchguard dimension4 HR AGO CVE-2026-781035.1Medium—5.1MediumDimension Log Server Configuration Lock Bypass Vulnerabilitywatchguard dimension4 HR AGO CVE-2026-786154.6Medium—4.6MediumWatchGuard Dimension Reflected DOM-Based XSS in Report Detail Pagewatchguard dimension4 HR AGO CVE-2026-786138.6High—8.6HighDimension SQL Injection in Log Viewerwatchguard dimension4 HR AGO CVE-2026-784955.3Medium—5.3MediumDimension Server-Side Request Forgery via Remote Backup Connection Testwatchguard dimension4 HR AGO CVE-2026-786176.3Medium—6.3MediumWatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limitingwatchguard dimension4 HR AGO CVE-2026-780475.1Medium—5.1MediumDimension Stored XSS in Scheduled Report Taskwatchguard dimension4 HR AGO 05 Recently added to KEV
SRC: CISAKEVCVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has noAdded 2026-08-27