01 Search console
The CVE corpus, on scope in milliseconds.
390,577 records · updated every 15 minutes
02 Telemetry
Total CVEs390,577
New today5
Known-exploited (KEV)1,708
Sync lag29 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-8570610.0Critical—Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab gitlab36 MIN AGO
CVE-2026-904676.3Medium—aiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addressescole aiosmtplib1 HR AGO
CVE-2026-892685.1Medium—QloApps through 1.7.0 Reflected XSS via List Filter Parameterswebkul qloapps1 HR AGO
CVE-2026-892675.3Medium—starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypassjowilf starlette-admin1 HR AGO
CVE-2026-892668.8High—stb_vorbis through 1.22 heap buffer overflow via codebook multiplicandsnothings stb_vorbis3 HR AGO
CVE-2026-904576.9Medium—The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissionscisa malcolm5 HR AGO
CVE-2026-904569.2Critical—An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file intocisa malcolm5 HR AGO
CVE-2026-904556.3Medium—A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processingcisa malcolm5 HR AGO
CVE-2026-904545.3Medium—A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tagscisa malcolm5 HR AGO
CVE-2026-904535.1Medium—A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. Thiscisa malcolm5 HR AGO
CVE-2026-904526.0Medium—Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attackercisa malcolm5 HR AGO
CVE-2026-904518.2High—An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies thiscisa malcolm5 HR AGO
CVE-2026-904505.3Medium—The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any requestcisa malcolm5 HR AGO
CVE-2026-904496.9Medium—When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway'scisa malcolm5 HR AGO