01 Search console
The CVE corpus, on scope in milliseconds.
390,833 records · updated every 15 minutes
02 Telemetry
Total CVEs390,833
New today34
Known-exploited (KEV)1,708
Sync lag15 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-906196.9Medium—0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection0x4m4 hexstrike ai29 MIN AGO
CVE-2026-906186.9Medium—GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injectiongh05tcrew pentestagent44 MIN AGO
CVE-2026-906176.9Medium—GH05TCREW PentestAgent MCP HTTP Server main.py run_task os command injectiongh05tcrew pentestagent59 MIN AGO
CVE-2026-906155.3Medium—SourceCodester Class and Exam Timetabling System subject1.php cross site scriptingsourcecodester class and exam timetabling system1 HR AGO
CVE-2026-906145.3Medium—FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read_model deserializationfedml-ai fedml1 HR AGO
CVE-2026-906104.8Medium—GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-readgpac2 HR AGO
CVE-2026-906079.4Critical—Totolink A3002MU boa formNewSchedule buffer overflowtotolink a3002mu3 HR AGO
CVE-2026-389242.9Low—In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation,oraios ai serena3 HR AGO
CVE-2026-339703.5Low—An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, andsamsung exynos 850 firmware3 HR AGO
CVE-2026-339682.8Low—An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leadssamsung exynos 1330 firmware3 HR AGO