Browse 20,918+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-52774 📌 💣 | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki | YesWiki | yeswiki | Medium | 6.1 | 2026-09-04 23:51:19 | Deep Dive |
| CVE-2026-52773 📌 💣 | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki | YesWiki | yeswiki | Medium | 6.1 | 2026-09-04 23:44:40 | Deep Dive |
| CVE-2026-52767 🧪 | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` | YesWiki | yeswiki | High | 8.2 | 2026-09-04 23:40:40 | Deep Dive |
| CVE-2026-44402 🧪 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | Voltronic Power | SNMP Web Pro | Critical | 9.8 | 2026-09-04 15:31:12 | Deep Dive |
| CVE-2026-85381 🧪 | light0011 cms Chapter Controller ChapterController.class.php authorization | light0011 | cms | Medium | 5.3 | 2026-09-04 01:00:10 | Deep Dive |
| CVE-2026-71963 🧪 | Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection | NousResearch | hermes-agent | High | 8.8 | 2026-09-03 15:19:30 | Deep Dive |
| CVE-2023-54391 📌 💣 | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter | Proxmox Server Solutions GmbH | Proxmox Virtual Environment (VE) | Critical | 9.8 | 2026-09-01 21:59:13 | Deep Dive |
| CVE-2026-76657 🧪 | Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access | Hewlett Packard Enterprise (HPE) | Fabric Composer | Critical | 10.0 | 2026-09-01 19:47:53 | Deep Dive |
| CVE-2026-82971 🧪 | QVidium Opera11 CGI Script net_tr.cgi command injection | QVidium | Opera11 | Critical | 10.0 | 2026-08-31 22:15:40 | Deep Dive |
| CVE-2026-82921 🧪 | ShopEx ECShop pack.php check_img_type unrestricted upload | ShopEx | ECShop | High | 7.3 | 2026-08-31 21:15:35 | Deep Dive |
| CVE-2026-81779 🧪 | WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability | Silk Themes | Newspapers X | Critical | 10.0 | 2026-08-31 20:42:27 | Deep Dive |
| CVE-2026-82602 🧪 | SeaCMS ass.php authorization | - | SeaCMS | Medium | 5.3 | 2026-08-31 01:30:09 | Deep Dive |
| CVE-2026-82475 🧪 | iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check | iflytek | astron-agent | High | 8.1 | 2026-08-29 16:35:35 | Deep Dive |
| CVE-2026-82329 KEV 📌 💣 | Potential authentication bypass leading to administrative access in Artifactory | jfrog | artifactory | Critical | 9.8 | 2026-08-28 18:27:44 | Deep Dive |
| CVE-2026-82275 🧪 | Qwen-Agent Arbitrary File Read via Caller-Supplied Document Path | QwenLM | Qwen-Agent | High | 7.5 | 2026-08-28 16:18:57 | Deep Dive |
| CVE-2026-82222 🧪 | WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability | Liquid Web / StellarWP | GiveWP | Critical | 10.0 | 2026-08-28 10:46:14 | Deep Dive |
| CVE-2026-19092 📌 💣 | Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing | Unknown | Tutor LMS | Critical | 9.8 | 2026-08-27 17:05:38 | Deep Dive |
| CVE-2026-75005 🧪 | Apache APISIX: Unauthenticated CPU-exhaustion DoS | Apache Software Foundation | Apache APISIX | High | 8.7 | 2026-08-27 09:15:32 | Deep Dive |
| CVE-2026-81491 🧪 | boxpositron with-context-mcp index.ts project_folder path traversal | boxpositron | with-context-mcp | High | 7.3 | 2026-08-27 02:15:10 | Deep Dive |
| CVE-2026-81421 🧪 | ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery | ddfourtwo | sentry-selfhosted-mcp | High | 7.3 | 2026-08-26 23:45:10 | Deep Dive |