Browse 340,191+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-9134 | Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter | fooplugins | Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel | Medium | 6.4 | 2026-06-13 06:48:00 | Deep Dive |
| CVE-2026-9062 | Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal | Unknown | Store Locator WordPress | - | - | 2026-06-13 06:00:02 | Deep Dive |
| CVE-2026-9061 | Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name | Unknown | Store Locator WordPress | - | - | 2026-06-13 06:00:02 | Deep Dive |
| CVE-2026-9109 | GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage | john-dagelmore | GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites | High | 7.2 | 2026-06-13 05:32:37 | Deep Dive |
| CVE-2026-11769 | Operator - Namespaced User Path Traversal | Grafana | Grafana Operator | - | - | 2026-06-13 04:17:41 | Deep Dive |
| CVE-2026-54231 | Abrt: unsanitized systemd journal content written to dump directory files enables content injection | Red Hat | Red Hat Enterprise Linux 6 | Medium | 5.5 | 2026-06-13 02:34:37 | Deep Dive |
| CVE-2026-54230 | Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites | Red Hat | Red Hat Enterprise Linux 6 | High | 7.0 | 2026-06-13 02:34:36 | Deep Dive |
| CVE-2026-54229 | Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking | Red Hat | Red Hat Enterprise Linux 6 | High | 7.0 | 2026-06-13 02:34:31 | Deep Dive |
| CVE-2026-54228 | Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories | Red Hat | Red Hat Enterprise Linux 6 | High | 7.8 | 2026-06-13 02:34:25 | Deep Dive |
| CVE-2026-9848 | WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter | emarket-design | Customer Support Ticket System & Helpdesk | High | 7.5 | 2026-06-13 02:29:03 | Deep Dive |
| CVE-2026-12089 | WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read | aurelienlws | LWS Optimize – All-in-One Speed Booster & Cache Tools | Medium | 4.9 | 2026-06-13 02:29:02 | Deep Dive |
| CVE-2026-11443 | Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability | Allegra | Allegra | - | - | 2026-06-12 23:04:45 | Deep Dive |
| CVE-2026-11442 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability | Allegra | Allegra | - | - | 2026-06-12 23:04:07 | Deep Dive |
| CVE-2026-12068 | Avira Password Manager credential disclosure via cross-origin autofill in Firefox | Gen Digital | Avira Password Manager | High | 7.4 | 2026-06-12 22:19:19 | Deep Dive |
| CVE-2026-6676 | Avira antivirus engine heap buffer OOB write when scanning a malformed POSIX tar archive | Gen Digital | Avira Antivirus | High | 7.8 | 2026-06-12 22:16:28 | Deep Dive |
| CVE-2025-14098 | Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file | Gen Digital | Avira Antivirus | High | 7.8 | 2026-06-12 22:16:01 | Deep Dive |
| CVE-2025-9033 | Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 3) | Gen Digital | Avira Antivirus | High | 7.8 | 2026-06-12 22:15:25 | Deep Dive |
| CVE-2025-9032 | Avira antivirus engine heap buffer OOB read when scanning a malformed PE file | Gen Digital | Avira Antivirus | High | 7.8 | 2026-06-12 22:14:51 | Deep Dive |
| CVE-2025-7019 | Avast antivirus stack overflow when scanning a malformed Office Open XML file | Gen Digital | Avast Antivirus | Medium | 5.5 | 2026-06-12 22:14:19 | Deep Dive |
| CVE-2025-7018 | Avira antivirus engine null pointer dereference when scanning a malformed PE file | Gen Digital | Avira Antivirus | Medium | 5.5 | 2026-06-12 22:13:50 | Deep Dive |