Browse 21,062+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-93978 🧪 | code-projects Internship Management System login.php sql injection | code-projects | Internship Management System | High | 7.3 | 2026-09-20 10:30:09 | Deep Dive |
| CVE-2026-86555 🧪 | Hardcoded Key Vulnerability in ZTE SmartLife APP | ZTE | SmartLife | Medium | 6.2 | 2026-09-20 09:15:44 | Deep Dive |
| CVE-2026-84434 📌 | Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field | Gravity Forms | Gravity Forms | Critical | 9.8 | 2026-09-19 02:27:10 | Deep Dive |
| CVE-2026-91716 🧪 | Google Chrome 资源管理错误漏洞 | Chrome | 超危 | - | 2026-09-15 20:41:33 | Deep Dive | |
| CVE-2026-89308 🧪 | Arbitrary command execution in TrxTimeATTENDANCE | TREXOM | TrxTimeATTENDANCE | Critical | 9.3 | 2026-09-15 11:44:01 | Deep Dive |
| CVE-2026-52824 📌 💣 | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover | kimai | kimai | Critical | 9.1 | 2026-09-15 10:40:29 | Deep Dive |
| CVE-2026-76461 KEV 🧪 | Cisco Secure Email Gateway SQL Injection Vulnerability | Cisco | Cisco Secure Email | Critical | 9.8 | 2026-09-14 16:09:08 | Deep Dive |
| CVE-2026-85200 📌 💣 | GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion | ninjew | GEO my WP | High | 7.5 | 2026-09-12 07:39:14 | Deep Dive |
| CVE-2026-85706 KEV 📌 💣 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab EPSS 0.15 | GitLab | GitLab | Critical | 10.0 | 2026-09-12 02:46:32 | Deep Dive |
| CVE-2026-62105 🧪 | WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability | ThemeRex | ThemeREX Addons | Critical | 9.8 | 2026-09-11 18:12:04 | Deep Dive |
| CVE-2026-88062 📌 💣 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | diegosouzapw | OmniRoute | Critical | 9.5 | 2026-09-10 19:14:18 | Deep Dive |
| CVE-2025-57231 📌 💣 | Docmost 路径遍历漏洞 | - | - | 高危 | - | 2026-09-10 00:00:00 | Deep Dive |
| CVE-2026-87820 📌 💣 | CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner | usmannasir | cyberpanel | Medium | 5.3 | 2026-09-09 11:21:06 | Deep Dive |
| CVE-2026-86426 📌 💣 | LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion | librenms | librenms | Critical | 9.2 | 2026-09-07 12:53:48 | Deep Dive |
| CVE-2026-86218 KEV 📌 💣 | pre-authentication remote code execution | N-able | N-central | Critical | 10.0 | 2026-09-06 02:15:29 | Deep Dive |
| CVE-2026-86206 📌 💣 | Access control filter bypass allows unauthorised access to APIs | N-able | N-central | Medium | 6.9 | 2026-09-05 19:17:51 | Deep Dive |
| CVE-2026-86207 📌 💣 | Authentication bypass leads to unauthorised access to N-central | N-able | N-central | High | 7.7 | 2026-09-05 19:12:06 | Deep Dive |
| CVE-2026-52774 📌 💣 | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki | YesWiki | yeswiki | Medium | 6.1 | 2026-09-04 23:51:19 | Deep Dive |
| CVE-2026-52773 📌 💣 | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki | YesWiki | yeswiki | Medium | 6.1 | 2026-09-04 23:44:40 | Deep Dive |
| CVE-2026-52767 🧪 | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` | YesWiki | yeswiki | High | 8.2 | 2026-09-04 23:40:40 | Deep Dive |