02 Telemetry
FEED: ACQUIRING
03 Severity mix
WINDOW: T-30D
04 Latest published
FEED: ACQUIRING
01 Search consoleIDX: 384,578
The CVE corpus, on scope in milliseconds.
384,578 records · updated every 15 minutes
02 Telemetry
FEED: LIVETotal CVEs384,578
New today5
Known-exploited (KEV)1,685
Sync lag68 MIN
03 Severity mix
WINDOW: T-30D
CRITICAL 15%HIGH 46%MEDIUM 36%LOW 4%NONE 0%
04 Latest published
LAST 15 / 15-MIN SYNCCVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-778462.1Low—2.1LowJSON path injection via unescaped get_path segments in AshSqliteash-project ash_sqlite1 HR AGO CVE-2026-757597.6High—7.6HighEncrypted ID token or JARM response accepted without a nested signature in erlef oidccerlef oidcc2 HR AGO CVE-2026-778312.1Low—2.1LowAlgorithmic-complexity denial of service in AshPaperTrail full-diff list trackingash-project ash_paper_trail3 HR AGO CVE-2026-779705.9Medium—5.9MediumSensitive fields nested in embedded values are not redacted in AshPaperTrail versionsash-project ash_paper_trail3 HR AGO CVE-2026-758475.9Medium—5.9MediumSensitive attribute values stored in a non-sensitive public changes map in AshPaperTrailash-project ash_paper_trail3 HR AGO CVE-2026-825626.3Medium—6.3Mediumqs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391)ljharb qs4 HR AGO CVE-2026-824245.3Medium—5.3MediumPHPGurukul Student Information System student_edit1.php sql injectionphpgurukul student information system5 HR AGO CVE-2026-824235.3Medium—5.3Mediummacrozheng mall Payment Status Endpoint paySuccess behavioral workflowmacrozheng mall5 HR AGO CVE-2026-824225.3Medium—5.3Mediumitsourcecode Sales and Inventory System emp_del.php sql injectionitsourcecode sales and inventory system6 HR AGO CVE-2026-824215.3Medium—5.3Mediumitsourcecode Sales and Inventory System emp_edit.php sql injectionitsourcecode sales and inventory system7 HR AGO CVE-2026-153699.8Critical—9.8CriticalCustom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkoutaddify custom user registration fields for woocommerce8 HR AGO CVE-2026-758077.5High—7.5HighSAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoningcyberlord92 saml single sign on – sso login10 HR AGO CVE-2026-824766.9Medium—6.9MediumMemos through 0.30.0 SSRF via Omitted CGNAT Address Rangeusememos memos11 HR AGO CVE-2026-824758.6High—8.6HighiFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Checkiflytek astron-agent11 HR AGO CVE-2026-824748.5High—8.5HighSudo through 1.9.17p2 Intercept Policy Bypass via execveatsudo-project sudo11 HR AGO 05 Recently added to KEV
SRC: CISAKEVCVE-2023-49105An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has noAdded 2026-08-27