01 Search console
The CVE corpus, on scope in milliseconds.
395,903 records · updated every 15 minutes
02 Telemetry
Total CVEs395,903
New today243
Known-exploited (KEV)1,717
Sync lag20 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-466499.1Critical—Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpointlaurent22 joplin29 MIN AGO
CVE-2026-551796.5Medium—Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server IDlaurent22 joplin30 MIN AGO
CVE-2026-598164.3Medium—Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slashlaurent22 joplin32 MIN AGO
CVE-2026-494492.5Low—Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windowslaurent22 joplin35 MIN AGO
CVE-2026-494537.0High—Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directorylaurent22 joplin36 MIN AGO
CVE-2026-494507.1High—Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherNamelaurent22 joplin38 MIN AGO
CVE-2026-799196.3Medium—MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)1panel-dev maxkb39 MIN AGO
CVE-2026-945884.4Medium—In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlyingproxmox pmg-api40 MIN AGO
CVE-2026-775175.4Medium—MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base1panel-dev maxkb40 MIN AGO
CVE-2026-7752110.0Critical—MaxKB: Prompt-injectable agent can lead to command execution1panel-dev maxkb41 MIN AGO
CVE-2026-944249.3Critical—Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflowmoore threads mtt s80 driver package42 MIN AGO
CVE-2026-775224.3Medium—MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)1panel-dev maxkb42 MIN AGO
CVE-2026-799176.5Medium—MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation1panel-dev maxkb43 MIN AGO
CVE-2026-775165.4Medium—MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path1panel-dev maxkb46 MIN AGO
05 Recently added to KEV
KEVCVE-2026-7273zyxel gs1900-10hp firmware zyxel gs1900-16 firmware zyxel gs1900-24 firmware zyxel gs1900-24e firmware zyxel gs1900-24ep firmware zyxel gs1900-24hpv2 firmware zyxel gs1900-48 firmware zyxel gs1900-48hpv2 firmware zyxel gs1900-8 firmware zyxel gs1900-8hp firmwareAdded 2026-09-21
KEVCVE-2026-87886acronis acronis backup extension for plesk acronis acronis backup plugin for cpanel & whm acronis acronis backup plugin for directadminAdded 2026-09-16
KEVCVE-2026-76460cisco cisco identity services engine software cisco cisco ise passive identity connectorAdded 2026-09-16