Browse 29,354+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-84434 📌 💣 | Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field | Gravity Forms | Gravity Forms | Critical | 9.8 | 2026-09-19 02:27:10 | Deep Dive |
| CVE-2026-54645 💣 | CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass | cubecart | v6 | Medium | 4.8 | 2026-09-17 22:06:29 | Deep Dive |
| CVE-2026-54644 💣 | CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System | cubecart | v6 | Medium | 6.1 | 2026-09-17 22:03:42 | Deep Dive |
| CVE-2026-54647 💣 | CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php | cubecart | v6 | High | 7.2 | 2026-09-17 22:02:48 | Deep Dive |
| CVE-2026-54646 💣 | CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php | cubecart | v6 | High | 7.2 | 2026-09-17 22:01:54 | Deep Dive |
| CVE-2026-52824 📌 💣 | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover | kimai | kimai | Critical | 9.1 | 2026-09-15 10:40:29 | Deep Dive |
| CVE-2026-51133 💣 | za-internet C-MOR ≤6.0104 跨站脚本漏洞 | - | - | - | - | 2026-09-15 00:00:00 | Deep Dive |
| CVE-2026-51134 💣 | C-MOR 6.0104 视频监控系统路径遍历 | - | - | - | - | 2026-09-15 00:00:00 | Deep Dive |
| CVE-2026-85200 📌 💣 | GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion | ninjew | GEO my WP | High | 7.5 | 2026-09-12 07:39:14 | Deep Dive |
| CVE-2026-85706 KEV 📌 💣 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | GitLab | GitLab | Critical | 10.0 | 2026-09-12 02:46:32 | Deep Dive |
| CVE-2026-88062 📌 💣 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | diegosouzapw | OmniRoute | Critical | 9.5 | 2026-09-10 19:14:18 | Deep Dive |
| CVE-2025-57231 📌 💣 | Docmost 路径遍历漏洞 | - | - | 高危 | - | 2026-09-10 00:00:00 | Deep Dive |
| CVE-2026-87820 📌 💣 | CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner | usmannasir | cyberpanel | Medium | 5.3 | 2026-09-09 11:21:06 | Deep Dive |
| CVE-2026-80099 📌 💣 | Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret | Newfold | WP Plugin Web | High | 8.8 | 2026-09-09 08:28:22 | Deep Dive |
| CVE-2026-86426 📌 💣 | LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion | librenms | librenms | Critical | 9.2 | 2026-09-07 12:53:48 | Deep Dive |
| CVE-2026-86218 KEV 📌 💣 | pre-authentication remote code execution | N-able | N-central | Critical | 10.0 | 2026-09-06 02:15:29 | Deep Dive |
| CVE-2026-86206 📌 💣 | Access control filter bypass allows unauthorised access to APIs | N-able | N-central | Medium | 6.9 | 2026-09-05 19:17:51 | Deep Dive |
| CVE-2026-86207 📌 💣 | Authentication bypass leads to unauthorised access to N-central | N-able | N-central | High | 7.7 | 2026-09-05 19:12:06 | Deep Dive |
| CVE-2026-52774 📌 💣 | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki | YesWiki | yeswiki | Medium | 6.1 | 2026-09-04 23:51:19 | Deep Dive |
| CVE-2026-52773 📌 💣 | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki | YesWiki | yeswiki | Medium | 6.1 | 2026-09-04 23:44:40 | Deep Dive |