Browse 356,454+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19279 | MIMICLab mcp-pdf-vision index.ts load_pdf command injection | MIMICLab | mcp-pdf-vision | Medium | 5.3 | 2026-08-08 10:15:09 | Deep Dive |
| CVE-2026-68081 | KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state | Linux | Linux | - | - | 2026-08-08 09:17:45 | Deep Dive |
| CVE-2026-68082 | libceph: fix two unsafe bare decodes in decode_lockers() | Linux | Linux | - | - | 2026-08-08 09:17:45 | Deep Dive |
| CVE-2026-19270 | Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal | Hulupeep | mcp-ui-probe | Medium | 5.3 | 2026-08-08 07:45:12 | Deep Dive |
| CVE-2026-19268 | abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection | abdullah1854 | MCPGateway | Medium | 6.3 | 2026-08-08 07:30:09 | Deep Dive |
| CVE-2026-19266 | Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection | Kirachon | context-engine | Medium | 5.5 | 2026-08-08 07:15:11 | Deep Dive |
| CVE-2026-19263🧪 | INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection | INQUIRELAB | mcp-bridge-api | High | 7.3 | 2026-08-08 06:45:09 | Deep Dive |
| CVE-2026-14526 | AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route | wupsales | AI Copilot – Content Generator | Critical | 9.8 | 2026-08-08 06:38:42 | Deep Dive |
| CVE-2026-16955 | AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription | Unknown | AI Engine | - | - | 2026-08-08 06:00:14 | Deep Dive |
| CVE-2026-16953 | AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie | Unknown | AI Engine | - | - | 2026-08-08 06:00:14 | Deep Dive |
| CVE-2026-16595 | WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure | Unknown | WP Directory Kit | - | - | 2026-08-08 06:00:13 | Deep Dive |
| CVE-2026-16608 | Download Monitor < 5.2.6 - Unauthenticated Download Log Injection | Unknown | Download Monitor | - | - | 2026-08-08 06:00:13 | Deep Dive |
| CVE-2026-16948 | Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure | Unknown | Solace Extra | - | - | 2026-08-08 06:00:13 | Deep Dive |
| CVE-2026-16594 | WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure | Unknown | WP Directory Kit | - | - | 2026-08-08 06:00:12 | Deep Dive |
| CVE-2026-16590 | WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure | Unknown | WP Directory Kit | - | - | 2026-08-08 06:00:12 | Deep Dive |
| CVE-2026-16578 | Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route | Unknown | Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection | - | - | 2026-08-08 06:00:12 | Deep Dive |
| CVE-2026-16574 | Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint | Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | - | - | 2026-08-08 06:00:12 | Deep Dive |
| CVE-2026-16562 | WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers | Unknown | WP Statistics | - | - | 2026-08-08 06:00:12 | Deep Dive |
| CVE-2026-16589 | WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter | Unknown | WP Directory Kit | - | - | 2026-08-08 06:00:12 | Deep Dive |
| CVE-2026-16535 | Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel | Unknown | Link Library | - | - | 2026-08-08 06:00:11 | Deep Dive |