Browse 1,637+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-56291KEV | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 | balbooa.com | balbooa.com Balbooa Forms extension for Joomla | 超危 | - | 2026-07-09 09:53:58 | Deep Dive |
| CVE-2026-48939KEV | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 | icagenda.com | iCagenda extension for Joomla | 超危 | - | 2026-06-20 11:56:51 | Deep Dive |
| CVE-2026-56290KEV🧪💣 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 | joomlack.fr | JoomlaCK.fr Page Builder CK extension for Joomla | 超危 | - | 2026-06-29 14:31:38 | Deep Dive |
| CVE-2026-55255KEV🧪 | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow | langflow-ai | langflow | High | 8.4 | 2026-06-23 16:28:21 | Deep Dive |
| CVE-2026-48908KEV | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 | joomshaper.net | SP Page Builder extension for Joomla | 超危 | - | 2026-06-20 11:57:01 | Deep Dive |
| CVE-2026-48282KEV📌💣 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) EPSS 0.29 | Adobe | ColdFusion | Critical | 10.0 | 2026-06-30 15:11:57 | Deep Dive |
| CVE-2026-45659KEV | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | Microsoft SharePoint Enterprise Server 2016 | High | 8.8 | 2026-05-22 22:04:34 | Deep Dive |
| CVE-2026-48558KEV | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification | SimpleHelp | SimpleHelp | Critical | 10.0 | 2026-06-12 17:07:05 | Deep Dive |
| CVE-2026-20230KEV | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability EPSS 0.42 | Cisco | Cisco Unified Communications Manager | High | 8.6 | 2026-06-03 16:09:46 | Deep Dive |
| CVE-2026-12569KEV | Remote Code Execution (RCE) vulnerability in Windchill PDMlink | PTC | Windchill PDMLink | 超危 | - | 2026-06-18 00:11:35 | Deep Dive |
| CVE-2026-34910KEV📌💣 | Ubiquiti UniFi OS Server 安全漏洞 EPSS 0.79 | Ubiquiti Inc | UniFi OS Server | Critical | 10.0 | 2026-05-22 00:43:49 | Deep Dive |
| CVE-2026-34909KEV | Ubiquiti UniFi OS Server 安全漏洞 | Ubiquiti Inc | UniFi OS Server | Critical | 10.0 | 2026-05-22 00:43:49 | Deep Dive |
| CVE-2026-34908KEV | Ubiquiti UniFi OS Server 安全漏洞 | Ubiquiti Inc | UniFi OS Server | Critical | 10.0 | 2026-05-22 00:43:49 | Deep Dive |
| CVE-2025-67038KEV | Lantronix EDS5000 安全漏洞 | - | - | - | - | 2026-03-11 00:00:00 | Deep Dive |
| CVE-2026-20253KEV🧪💣 | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise EPSS 0.88 | Splunk | Splunk Enterprise | Critical | 9.8 | 2026-06-10 17:16:21 | Deep Dive |
| CVE-2026-48907KEV📌💣 | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 EPSS 0.80 | joomlacontenteditor.net | Joomla Content Editor (JCE) extension for Joomla | 中危 | - | 2026-06-05 07:31:30 | Deep Dive |
| CVE-2026-54420KEV | LiteSpeed cPanel Plugin 后置链接漏洞 | LiteSpeed Technologies | cPanel Plugin | High | 8.5 | 2026-06-14 03:23:13 | Deep Dive |
| CVE-2026-20262KEV | Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability | Cisco | Cisco Catalyst SD-WAN Manager | Medium | 6.5 | 2026-06-15 16:21:10 | Deep Dive |
| CVE-2026-35273KEV📌💣 | Oracle PeopleSoft Enterprise PeopleTools 访问控制错误漏洞 EPSS 0.92 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | Critical | 9.8 | 2026-06-11 02:25:15 | Deep Dive |
| CVE-2026-10520KEV📌💣 | Ivanti Sentry 操作系统命令注入漏洞 EPSS 0.99 | ivanti | Sentry | Critical | 10.0 | 2026-06-09 14:10:22 | Deep Dive |