Browse 1,675+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-69836 KEV | Microsoft Entra ID Remote Code Execution Vulnerability | Microsoft | Microsoft Entra | Critical | 10.0 | 2026-08-20 21:43:13 | Deep Dive |
| CVE-2026-72530 KEV | TrueConf server 代码注入漏洞 | TrueConf | TrueConf Server | Critical | 9.0 | 2026-08-19 16:56:53 | Deep Dive |
| CVE-2026-72529 KEV | TrueConf server 授权问题漏洞 | TrueConf | TrueConf Server | Critical | 9.8 | 2026-08-19 16:55:15 | Deep Dive |
| CVE-2026-64849 KEV 📌 💣 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | mlflow | mlflow | Critical | 9.3 | 2026-08-17 21:16:11 | Deep Dive |
| CVE-2026-73570 KEV 🧪 | Zimbra<10.1.20 SNMP未授权远程代码执行漏洞 | Zimbra | Collaboration | High | 8.9 | 2026-08-13 15:19:42 | Deep Dive |
| CVE-2026-20349 KEV | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High | 8.6 | 2026-08-11 17:06:03 | Deep Dive |
| CVE-2026-68820 KEV | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | Windows 10 Version 1607 | High | 7.0 | 2026-08-11 17:05:16 | Deep Dive |
| CVE-2026-72898 KEV 🧪 💣 | Metabase SQL injection via password reset endpoint EPSS 0.10 | Metabase | Metabase | Critical | 10.0 | 2026-08-10 17:55:55 | Deep Dive |
| CVE-2026-65400 KEV | macOS身份验证绕过漏洞 | Apple | macOS | - | - | 2026-08-06 18:17:18 | Deep Dive |
| CVE-2026-18577 KEV | Incomplete patch leads to administrative account takeover | N-able | N-central | High | 8.2 | 2026-08-02 22:06:18 | Deep Dive |
| CVE-2026-18556 KEV | Unauthenticated administrative account takeover | N-able | N-central | High | 8.2 | 2026-08-01 19:59:31 | Deep Dive |
| CVE-2026-59310 KEV | vCenter directory-traversal vulnerability | VMware | Cloud Foundation | Critical | 9.8 | 2026-07-30 12:19:25 | Deep Dive |
| CVE-2026-20316 KEV | Cisco Secure Firewall Management Center Software Static Credential Vulnerability | Cisco | Cisco Secure Firewall Management Center (FMC) | Medium | 5.3 | 2026-07-29 16:22:09 | Deep Dive |
| CVE-2026-63077 KEV 📌 💣 | JetBrains TeamCity 反序列化注入漏洞 EPSS 0.12 | JetBrains | TeamCity | Critical | 9.8 | 2026-07-27 16:44:32 | Deep Dive |
| CVE-2026-16812 KEV | VeloCloud Orchestrator OS Command Injection | Arista Networks | VeloCloud Orchestrator On-Prem | Critical | 10.0 | 2026-07-27 16:11:01 | Deep Dive |
| CVE-2026-16232 KEV 📌 | Authentication Bypass in the SmartConsole Login Process Using an Application Token EPSS 0.73 | checkpoint | Quantum Security Management | Critical | 9.3 | 2026-07-22 13:53:10 | Deep Dive |
| CVE-2026-63030 KEV 🧪 💣 | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution EPSS 0.96 | WordPress | WordPress | Critical | 9.8 | 2026-07-17 19:14:13 | Deep Dive |
| CVE-2026-60137 KEV | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query EPSS 0.73 | WordPress | WordPress | Medium | 5.9 | 2026-07-17 19:14:12 | Deep Dive |
| CVE-2026-9198 KEV 📌 💣 | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation EPSS 0.19 | IBM | Langflow OSS | Critical | 9.8 | 2026-07-17 17:36:11 | Deep Dive |
| CVE-2021-27137 KEV 📌 | DD-WRT 缓冲区错误漏洞 EPSS 0.16 | DD-WRT | DD-WRT | High | 8.1 | 2026-07-16 00:00:00 | Deep Dive |