Look up vulnerabilities across multiple sources
Correlate vulnerability advisories from national databases, CSAF providers and community feeds, link them to real-world sightings, and coordinate their disclosure — all in one place.
Trending over the last month
Minimum sightings per line
1
2
3
4
5
Loading…
Loading…
Loading…
Loading…
Sighting types
- Seen
- The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed
- The vulnerability has been validated from an analyst's perspective.
- Exploited
- The vulnerability was observed as exploited by the user who reported the sighting.
- Published Proof of Concept
- A public proof of concept is available for this vulnerability.
CVE Program structure
Structure on cve.orgThis diagram is rendered live from the CNA partner catalogue stored in our database, synchronized from cve.org via GCVE — not a static image.
-
42Gears ABB ADI AMI arcinfo Armis ASR ASRG ASUS azure-access B.Braun BAE Baxter BD BECDX BECLS BHV bosch Carrier CEP CODRA Cribl CTOne CyberDanube Cytiva Danfoss Deltaww Digi Dragos eclypsium Entrust Gallagher GE_Healthcare GE_Vernova Hackrate HemoCue Hitachi_Energy Hologic Honeywell hsi IDBS IDT-DNA jci JupiterOne LeicaBiosystems Leonardo LMS Medtronic MHV MIM MolDev Moxa MyMMT NetRise NIBEGroup OMICRON ONEKEY Pall Philips PTC Radiometer Roche Rockwell runZero SCIEX Secomea SEL siemens Simplinx SOCRadar SRA Stryker tlt_net TMUS TRO TXOne Vantive Verizon vx WindRiver wolfSSL XONA Xylem
-
CERTVDE CNA 0 CNAs
-
- 1 CNAs directly under CISA
-
375 CNAs directly under mitre
2N 9front @huntr_ai Absolute Acer Acronis adobe AHA airbus Airlock AlgoSec alibaba Almaviva Altera Altium AMD Ampere AMZN Anolis Antenna Anthropic apache AppCheck apple ARCON Arista Arm Arxscan ASUSTOR atlassian autodesk Automox avaya Axis AxxonSoft Baidu BCNY bcorg Bitdefender bizerba blackberry BlackDuck BLSOPS BombadilSystems brocade BT Bugcrowd ByteDance ca Caliptra Canon_EMEA canonical Canva Cato Censys Centreon CERT-In certcc Checkmarx Checkmk checkpoint Ciena cirosec cisco Citrix ClickHouse cloudflare Commvault ConcreteCMS ConnectWise CoolKit Crafter_CMS Crestron CrowdStrike CSA CSAI CSW CyberArk cygence Cynet dahua Dassault_Systemes debian Delinea dell DevCycle DEVOLUTIONS Dfinity DHIS2 directcyber Docker dotCMS Dremio drupal DSF DTEX DualVS EA Eaton Echo eclipse EDB EEF ELAN elastic ERIC Esri Everpure ExtremeNetworks F5 Fidelis flexera floragunn Fluid_Attacks forcepoint Forescout fortinet Fortra Foxit freebsd FSI FSOFT FTI FULL GEN Genetec Gitea GitHub_M GitHub_P GitLab GRAFANA GreenRocketSecurity GV hackerone Halborn Hanwha_Vision HashiCorp HCL HeroDevs HiddenLayer hikvision Hillstone Hitachi_Vantara Honor hp hpe huawei Huntress HYPR ibm ICT IDEMIA Illumio imaginationtech iManage INCD Insyde intel Intigriti IoT83 isc ivanti JAMF Jaspersoft jenkins JetBrains JFrog Joomla juniper Kaspersky KCFTech KeeperSecurity KNIME Kong KoreLogic krcert kubernetes larry_cashdollar lenovo Lexmark LGE libreswan Liferay linqi Linux Logitech M-Files Mattermost Mautic MediaTek Meta Microchip microsoft milestonesys Mirantis MON-CSIRT mongodb mozilla N-able naver NCSC.ch Neo4j netapp netflix NETGEAR NetScaler Netskope NI NLnet_Labs nodejs Nokia Nozomi Nutanix nvidia NX OAI OB obdev Octopus ODA odoo Okta Omnissa OnLogic OpenBMC openEuler openGauss OpenHarmony OpenNMS openssl OpenText OpenVPN Opera OPPO oracle OS-S OTRS OX Palantir palo_alto PangeaCyber PaperCut Patchstack Payara Pega Pentraze Perforce Phoenix php PingCAP PingIdentity PlexTrac postiz PRJBLK Profelis Profisee ProgressSoftware Proofpoint Proton PSF QCI qnap Qt qualcomm Qualys rami.io rapid7 RealPage Replicated Ribose RTI SailPoint Salesforce samsung.tv_appliance Samsung_Mobile sap Saviynt sba-research schneider SCHUTZWERK SDC Seagate seal SEC-VLab sec1 securepoint Securifera securin Semtech senhasegura ShopBeat SICK_AG Silabs Silver_Peak sirius SmileDigitalHealth SN Snow SNOW snyk Softing SoftIron SolarWinds Solidigm Sonatype sonicwall Sophos Spotfire Stackable STAR_Labs StrongDM Supermicro suse Swift symantec Synaptics Syncro synology Synopsys talos Tanium TCL_Smart_Terminal Tcpdump TeamViewer TECNOMobile Tego_Cyber Temporal tenable The_Missing_Link ThinkstAppliedResearch TianoCore tibco Tigera Toreon TPLink TR-CERT Trellix trendmicro tuxcare twcert TYPO3 Unisoc Uniview upKeeper Vaadin Vestel Vivo vmware VulDB VulnCheck watchdog WatchGuard WDC_PSIRT wikimedia-foundation Wiz Wordfence WPScan WrenSecurity WSO2 XEN Xerox XI Xiaomi yandex Yugabyte Zabbix zdi zephyr Zohocorp Zoom Zowe Zscaler ZTE ZUSO_ART Zyxel
Latest vulnerabilities published by the CNAs operating under each root of the CVE Program.
-
CVE-2026-34492 2026-08-14Airwall - Arbitrary file read
-
CVE-2026-64887 2026-08-14Airwall - Hardcoded Secrets
-
CVE-2026-27871 2026-08-14TL280
-
CVE-2025-7639 2026-08-14AVEVA Enterprise SCADA Deserialization of Untrusted Data
-
CVE-2026-19188 2026-08-14Haiwell IoT Cloud HMI Gateway OS Command Injection
-
CVE-2026-18164 2026-08-13Flow Neuroscience FL-100 Use of Hard-coded Credentials
-
CVE-2026-73669 2026-08-13Philips Hue Bridge Pro MQTT broker missing authentication
-
CVE-2026-18368 2026-08-13Heap buffer overflow in Modbusgwd
-
CVE-2026-16455 2026-08-13Local privilege escalation via improper input sanitization in execl() call
-
CVE-2025-41771 2026-08-12SQL injection
-
CVE-2026-75531 2026-08-17Stored Cross-Site Scripting in URL Observables via Lookyloo Submissio…
-
CVE-2026-75529 2026-08-17Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads …
-
CVE-2026-40126 2026-08-17DOM-based Cross-Site Scripting in OutSystems Service Center
-
CVE-2026-74767 2026-08-15Unbounded DAA Decompression in Pandora Allows Denial of Service via D…
-
CVE-2026-74764 2026-08-15Path Traversal in TAR Archive Extraction Allows Arbitrary File Write …
-
CVE-2026-59109 2026-08-13Zalktis: SQL injection via partner-controlled fields in imported e-invoices
-
CVE-2026-73432 2026-08-12Stored Server-Side Request Forgery in Remote-Instance Synchronization…
-
CVE-2026-73431 2026-08-12Reusable Account Activation and Recovery Tokens Allow Repeated Accoun…
-
CVE-2026-73405 2026-08-12Authorization Bypass in SSE Pub/Sub Allows Unconfirmed Accounts to Ac…
-
CVE-2026-73374 2026-08-12Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in…
-
CVE-2026-15623 2026-08-17Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboa…
-
CVE-2026-46603 2026-08-14Excessive memory allocation during VP8L decoding in golang.org/x/image
-
CVE-2026-56860 2026-08-13Avoid quadratic complexity in resolvePath in net/url
-
CVE-2026-56864 2026-08-13Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mo…
-
CVE-2026-56865 2026-08-13Fix transparency log tile verification bypass in golang.org/x/mod/sum…
-
CVE-2026-56858 2026-08-13Fix Javascript regexp context tracking in html/template
-
CVE-2026-56862 2026-08-13Limit handshake messages we are willing to accept post-handshake in c…
-
CVE-2026-56853 2026-08-13Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
-
CVE-2026-56859 2026-08-13Add recursion depth guard during decode in encoding/xml
-
CVE-2026-33818 2026-08-13Enforce maximum recursion depth in encoding/asn1
-
CVE-2026-34492 2026-08-14Airwall - Arbitrary file read
-
CVE-2026-64887 2026-08-14Airwall - Hardcoded Secrets
-
CVE-2026-27871 2026-08-14TL280
-
CVE-2025-7639 2026-08-14AVEVA Enterprise SCADA Deserialization of Untrusted Data
-
CVE-2026-19188 2026-08-14Haiwell IoT Cloud HMI Gateway OS Command Injection
-
CVE-2026-18164 2026-08-13Flow Neuroscience FL-100 Use of Hard-coded Credentials
-
CVE-2026-18368 2026-08-13Heap buffer overflow in Modbusgwd
-
CVE-2026-16455 2026-08-13Local privilege escalation via improper input sanitization in execl() call
-
CVE-2025-41771 2026-08-12SQL injection
-
CVE-2025-41770 2026-08-12Unauthenticated Denial of Service
-
CVE-2026-19871 2026-08-14Use of hard-coded credentials in Prospero Flow CRM employee onboarding
-
CVE-2026-19870 2026-08-14IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and …
-
CVE-2026-19744 2026-08-13Stored Cross-site Scripting in Pentestify Markdown renderer via unesc…
-
CVE-2026-19734 2026-08-13IDOR in Prospero Flow CRM allows cross-tenant product disclosure and …
-
CVE-2026-19716 2026-08-13Stored Cross-site Scripting in Pentestify user account deletion via u…
-
CVE-2026-19539 2026-08-11IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking,…
-
CVE-2026-19434 2026-08-11Stored Cross-site Scripting in Pentestify finding severity field
-
CVE-2026-19433 2026-08-10Authorization Bypass Through User-Controlled Key in Prospero Flow CRM…
-
CVE-2026-59233 2026-08-10Missing Authorization in Prospero Flow CRM permission save endpoint a…
-
CVE-2026-59232 2026-07-31Stored Cross-site Scripting in Prospero Flow CRM lead name field
-
CVE-2026-72506 2026-08-13VoiceTra provided by National Institute of Information and Communicat…
-
CVE-2026-66411 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authenticati…
-
CVE-2026-66410 2026-08-10Android and iOS apps ECOVACS PRO App improperly validate server certi…
-
CVE-2026-66409 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords…
-
CVE-2026-66408 2026-08-10The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configure…
-
CVE-2026-66407 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authenticatio…
-
CVE-2026-66406 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certi…
-
CVE-2026-66405 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. …
-
CVE-2026-66404 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificate…
-
CVE-2026-66403 2026-08-10DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging…
-
CVE-2026-34884 2026-08-18Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL E…
-
CVE-2026-15371 2026-08-18Velociraptor Stored XSS in URL column types
-
CVE-2026-75091 2026-08-18Quill Forms <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting
-
CVE-2026-15748 2026-08-18Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload vi…
-
CVE-2026-11801 2026-08-18WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensiti…
-
CVE-2026-75151 2026-08-18SourceCodester Onlne Examination & Learning Management System cross-s…
-
CVE-2026-75094 2026-08-18COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection
-
CVE-2026-75093 2026-08-18sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size
-
CVE-2026-75090 2026-08-18EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf…
-
CVE-2026-75089 2026-08-18PHPGurukul Complaint Management System check_availability.php sql injection
-
CVE-2026-66795 2026-08-17Managedcluster-import-controller: managedcluster-import-controller: c…
-
CVE-2026-71472 2026-08-17Acm-search-v2-rhel9: search-v2-operator: shell-command and sql inject…
-
CVE-2026-70495 2026-08-17Search-v2-operator: search-v2-operator: cluster-wide impersonate on u…
-
CVE-2026-66792 2026-08-17Multicloud-operators-subscription: multicloud-operators-subscription:…
-
CVE-2026-15218 2026-08-17Models-as-a-service: red hat openshift ai: maas-api and maas-controll…
-
CVE-2026-72888 2026-08-16Net::OAuth versions before 0.32 for Perl allow memory exhaustion via …
-
CVE-2026-72887 2026-08-16Net::OAuth::Client versions before 0.32 for Perl allow the service pr…
-
CVE-2026-19349 2026-08-16Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 …
-
CVE-2026-18165 2026-08-15@fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies
-
CVE-2026-19474 2026-08-15@fastify/multipart vulnerable to Denial of Service via temporary file…
-
CVE-2026-9007 2026-07-15Reflected XSS in HCL Notes
-
CVE-2026-13014 2026-07-13Remote Code Execution vulnerability in "Suspicious" application
-
CVE-2026-6805 2026-05-07Vulnerability on Cryptobox external sharing feature
-
CVE-2026-6501 2026-05-04Improper restriction of XML external entity reference vulnerability i…
-
CVE-2026-6500 2026-05-04Plaintext storage of a password vulnerability in ILM Informatique Ope…
-
CVE-2026-6499 2026-05-04Incorrect Permission Assignment for Critical Resource vulnerability i…
-
CVE-2026-5794 2026-04-28Vulnerability in Cryptobox allows an authenticated user to trigger an…
-
CVE-2026-3457 2026-03-27Stored XSS vulnerability in Sentinel ACC
-
CVE-2026-0872 2026-02-13Improper Certificate Validation vulnerability in Thales SafeNet Agent…
-
CVE-2026-2344 2026-02-11Stored XSS on Plunet BusinessManager