Browse 29,068+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55592📌💣 | Dashy: XSS in workspace url parameter | lissy93 | dashy | Low | 3.9 | 2026-07-07 20:48:29 | Deep Dive |
| CVE-2026-27771📌💣 | Gitea Composer package source links use insufficient permission checks EPSS 0.41 | Gitea | Gitea Open Source Git Server | 高危 | - | 2026-07-03 20:19:37 | Deep Dive |
| CVE-2026-13731📌💣 | WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | High | 7.2 | 2026-07-01 03:43:34 | Deep Dive |
| CVE-2026-48313📌💣 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Adobe | ColdFusion | Critical | 9.3 | 2026-06-30 15:12:00 | Deep Dive |
| CVE-2026-48282KEV📌💣 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) EPSS 0.29 | Adobe | ColdFusion | Critical | 10.0 | 2026-06-30 15:11:57 | Deep Dive |
| CVE-2026-56782🧪💣 | Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints | gorse-io | gorse | Critical | 9.8 | 2026-06-29 17:16:14 | Deep Dive |
| CVE-2026-56290KEV🧪💣 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 | joomlack.fr | JoomlaCK.fr Page Builder CK extension for Joomla | 超危 | - | 2026-06-29 14:31:38 | Deep Dive |
| CVE-2026-58057💣 | Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity | Flowise | Flowise | Medium | 5.0 | 2026-06-28 01:32:59 | Deep Dive |
| CVE-2026-48778🧪💣 | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter | notepad-plus-plus | notepad-plus-plus | High | 7.8 | 2026-06-26 20:21:17 | Deep Dive |
| CVE-2026-10823📌💣 | YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure | Unknown | YMC Filter | 高危 | - | 2026-06-26 06:00:02 | Deep Dive |
| CVE-2026-56766🧪💣 | Hydra - Stack Buffer Overflow in NTLM Authentication Handler | vanhauser-thc | thc-hydra | High | 8.8 | 2026-06-25 18:01:07 | Deep Dive |
| CVE-2026-57588💣 | SQL Injection in Nessus via Malicious Scan Result File Import | tenable | Nessus | Low | 3.3 | 2026-06-25 13:47:28 | Deep Dive |
| CVE-2026-54069🧪💣 | SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist | siyuan-note | siyuan | 超危 | - | 2026-06-24 21:17:02 | Deep Dive |
| CVE-2026-54066🧪💣 | SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read) | siyuan-note | siyuan | High | 7.5 | 2026-06-24 21:13:25 | Deep Dive |
| CVE-2026-52815📌💣 | Gogs: Unauthenticated Organization Teams Information Disclosure via API | gogs | gogs | 中危 | - | 2026-06-24 20:01:03 | Deep Dive |
| CVE-2026-54157🧪💣 | LobeHub: Unauthenticated SSRF in `/webapi/proxy` | lobehub | lobehub | Critical | 9.0 | 2026-06-23 17:43:06 | Deep Dive |
| CVE-2026-28496📌💣 | FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE | FOSSBilling | FOSSBilling | 超危 | - | 2026-06-23 14:20:50 | Deep Dive |
| CVE-2026-54236📌💣 | vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router | vllm-project | vllm | Medium | 5.3 | 2026-06-22 22:09:15 | Deep Dive |
| CVE-2026-48909💣 | Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4 | joomshaper.net | SP LMS extension for Joomla | 超危 | - | 2026-06-20 11:56:47 | Deep Dive |
| CVE-2026-8383📌💣 | LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API | Unknown | LearnPress | 中危 | - | 2026-06-17 06:00:03 | Deep Dive |