Browse 2,449+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-85706 KEV 📌 💣 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab EPSS 0.91 | GitLab | GitLab | Critical | 10.0 | 2026-09-12 02:46:32 | Deep Dive |
| CVE-2026-81578 KEV 📌 💣 | PaperCut MF/NG: Authentication Bypass EPSS 0.85 | PaperCut | PaperCut MF/NG | High | 8.8 | 2026-08-28 11:39:45 | Deep Dive |
| CVE-2026-71362 KEV 📌 💣 | Adobe Commerce | Incorrect Authorization (CWE-863) EPSS 0.88 | Adobe | Adobe Commerce | Critical | 9.1 | 2026-08-11 17:52:48 | Deep Dive |
| CVE-2026-63077 KEV 📌 💣 | JetBrains TeamCity 反序列化注入漏洞 EPSS 0.90 | JetBrains | TeamCity | Critical | 9.8 | 2026-07-27 16:44:32 | Deep Dive |
| CVE-2026-16232 KEV 📌 💣 | Authentication Bypass in the SmartConsole Login Process Using an Application Token EPSS 0.78 | checkpoint | Quantum Security Management | Critical | 9.3 | 2026-07-22 13:53:10 | Deep Dive |
| CVE-2026-48908 KEV 📌 | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 EPSS 0.89 | joomshaper.net | SP Page Builder extension for Joomla | Critical | 10.0 | 2026-06-20 11:57:01 | Deep Dive |
| CVE-2026-20253 KEV 🧪 💣 | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise EPSS 0.97 | Splunk | Splunk Enterprise | Critical | 9.8 | 2026-06-10 17:16:21 | Deep Dive |
| CVE-2026-25089 KEV | Fortinet多款产品 操作系统命令注入漏洞 EPSS 0.76 | Fortinet | FortiSandbox | Critical | 9.8 | 2026-06-09 14:27:47 | Deep Dive |
| CVE-2026-10520 KEV 📌 💣 | Ivanti Sentry 操作系统命令注入漏洞 EPSS 1.00 | ivanti | Sentry | Critical | 10.0 | 2026-06-09 14:10:22 | Deep Dive |
| CVE-2026-8037 KEV 📌 💣 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF EPSS 0.77 | Progress Software | LoadMaster | Critical | 9.6 | 2026-06-04 13:13:46 | Deep Dive |
| CVE-2026-20230 KEV | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability EPSS 0.88 | Cisco | Cisco Unified Communications Manager | High | 8.6 | 2026-06-03 16:09:46 | Deep Dive |
| CVE-2026-20182 KEV 📌 💣 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability EPSS 0.92 | Cisco | Cisco Catalyst SD-WAN Controller | Critical | 10.0 | 2026-05-14 16:08:26 | Deep Dive |
| CVE-2026-0257 KEV 📌 | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities EPSS 0.96 | Palo Alto Networks | Cloud NGFW | - | - | 2026-05-13 18:15:10 | Deep Dive |
| CVE-2026-42271 KEV 📌 💣 | LiteLLM: Authenticated command execution via MCP stdio test endpoints EPSS 0.93 | BerriAI | litellm | - | - | 2026-05-08 03:35:17 | Deep Dive |
| CVE-2026-41940 KEV 🧪 💣 | WebPros cPanel and WHM Authentication Bypass via Login Flow EPSS 0.99 | WebPros | cPanel | Critical | 9.8 | 2026-04-29 15:10:38 | Deep Dive |
| CVE-2026-20079 KEV 📌 💣 | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability EPSS 0.88 | Cisco | Cisco Secure Firewall Management Center (FMC) | Critical | 10.0 | 2026-03-04 17:17:36 | Deep Dive |
| CVE-2026-20127 KEV 💣 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability EPSS 0.88 | Cisco | Cisco Catalyst SD-WAN Manager | Critical | 10.0 | 2026-02-25 16:14:20 | Deep Dive |
| CVE-2026-2041 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability EPSS 0.74 | Nagios | Host | - | - | 2026-02-20 22:22:18 | Deep Dive |
| CVE-2026-2043 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability EPSS 0.74 | Nagios | Host | - | - | 2026-02-20 22:22:07 | Deep Dive |
| CVE-2026-1603 KEV 📌 💣 | Ivanti Endpoint Manager 安全漏洞 EPSS 0.88 | Ivanti | Endpoint Manager | High | 8.6 | 2026-02-10 15:09:35 | Deep Dive |