Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE Database & AI Vulnerability Analysis

Browse 2,449+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.

Trusted by security teams 1,150+ security practitioners 560+ company & university domains · security vendors · in-house teams · academia · bug-bounty hunters
Found 2449 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-85706 KEV 📌 💣 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab EPSS 0.91 GitLab GitLab Critical 10.0 2026-09-12 02:46:32 Deep Dive
CVE-2026-81578 KEV 📌 💣 PaperCut MF/NG: Authentication Bypass EPSS 0.85 PaperCut PaperCut MF/NG High 8.8 2026-08-28 11:39:45 Deep Dive
CVE-2026-71362 KEV 📌 💣 Adobe Commerce | Incorrect Authorization (CWE-863) EPSS 0.88 Adobe Adobe Commerce Critical 9.1 2026-08-11 17:52:48 Deep Dive
CVE-2026-63077 KEV 📌 💣 JetBrains TeamCity 反序列化注入漏洞 EPSS 0.90 JetBrains TeamCity Critical 9.8 2026-07-27 16:44:32 Deep Dive
CVE-2026-16232 KEV 📌 💣 Authentication Bypass in the SmartConsole Login Process Using an Application Token EPSS 0.78 checkpoint Quantum Security Management Critical 9.3 2026-07-22 13:53:10 Deep Dive
CVE-2026-48908 KEV 📌 Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 EPSS 0.89 joomshaper.net SP Page Builder extension for Joomla Critical 10.0 2026-06-20 11:57:01 Deep Dive
CVE-2026-20253 KEV 🧪 💣 Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise EPSS 0.97 Splunk Splunk Enterprise Critical 9.8 2026-06-10 17:16:21 Deep Dive
CVE-2026-25089 KEV Fortinet多款产品 操作系统命令注入漏洞 EPSS 0.76 Fortinet FortiSandbox Critical 9.8 2026-06-09 14:27:47 Deep Dive
CVE-2026-10520 KEV 📌 💣 Ivanti Sentry 操作系统命令注入漏洞 EPSS 1.00 ivanti Sentry Critical 10.0 2026-06-09 14:10:22 Deep Dive
CVE-2026-8037 KEV 📌 💣 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF EPSS 0.77 Progress Software LoadMaster Critical 9.6 2026-06-04 13:13:46 Deep Dive
CVE-2026-20230 KEV Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability EPSS 0.88 Cisco Cisco Unified Communications Manager High 8.6 2026-06-03 16:09:46 Deep Dive
CVE-2026-20182 KEV 📌 💣 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability EPSS 0.92 Cisco Cisco Catalyst SD-WAN Controller Critical 10.0 2026-05-14 16:08:26 Deep Dive
CVE-2026-0257 KEV 📌 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities EPSS 0.96 Palo Alto Networks Cloud NGFW - - 2026-05-13 18:15:10 Deep Dive
CVE-2026-42271 KEV 📌 💣 LiteLLM: Authenticated command execution via MCP stdio test endpoints EPSS 0.93 BerriAI litellm - - 2026-05-08 03:35:17 Deep Dive
CVE-2026-41940 KEV 🧪 💣 WebPros cPanel and WHM Authentication Bypass via Login Flow EPSS 0.99 WebPros cPanel Critical 9.8 2026-04-29 15:10:38 Deep Dive
CVE-2026-20079 KEV 📌 💣 Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability EPSS 0.88 Cisco Cisco Secure Firewall Management Center (FMC) Critical 10.0 2026-03-04 17:17:36 Deep Dive
CVE-2026-20127 KEV 💣 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability EPSS 0.88 Cisco Cisco Catalyst SD-WAN Manager Critical 10.0 2026-02-25 16:14:20 Deep Dive
CVE-2026-2041 Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability EPSS 0.74 Nagios Host - - 2026-02-20 22:22:18 Deep Dive
CVE-2026-2043 Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability EPSS 0.74 Nagios Host - - 2026-02-20 22:22:07 Deep Dive
CVE-2026-1603 KEV 📌 💣 Ivanti Endpoint Manager 安全漏洞 EPSS 0.88 Ivanti Endpoint Manager High 8.6 2026-02-10 15:09:35 Deep Dive

Frequently Asked Questions

340,000+ CVEs aggregated from NVD and CNNVD, updated daily with AI-generated Chinese translations.

Basic CVE data is completely free. AI PoC generation and premium intelligence features require a Pro or Pro+ subscription.

When a CVE has no public proof-of-concept, Shenlong AI automatically generates exploit code and a technical analysis report based on the vulnerability description and references.

Yes. Shenlong AI has translated NVD English descriptions into Chinese, so you can search CVEs using Chinese keywords directly.