Browse 382,364+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-90970 | Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway | GitLab | GitLab AI Gateway | Critical | 9.9 | 2026-10-02 14:34:50 | Deep Dive |
| CVE-2026-104625 | CodeAstro Simple Loan Management System index.php sql injection | CodeAstro | Simple Loan Management System | Medium | 6.3 | 2026-10-02 14:30:11 | Deep Dive |
| CVE-2026-5782 | Reflected XSS in Loglama.NET's TurkHotspot | Loglama.net | TurkHotspot | Medium | 5.2 | 2026-10-02 14:13:02 | Deep Dive |
| CVE-2026-104026 | Sapling SCM <0.2.20260929-102736 代码执行漏洞 | Meta Platforms, Inc | Sapling SCM | - | - | 2026-10-02 14:06:02 | Deep Dive |
| CVE-2026-104614 | CodeAstro Simple Pharmacy Management System delete.php sql injection | CodeAstro | Simple Pharmacy Management System | Medium | 6.3 | 2026-10-02 14:00:09 | Deep Dive |
| CVE-2026-94422 | xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape | - | - | High | 8.8 | 2026-10-02 13:54:11 | Deep Dive |
| CVE-2026-19652 | Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter | DiviEngine | Divi Membership | Critical | 9.8 | 2026-10-02 13:29:06 | Deep Dive |
| CVE-2026-93875 | JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter | Crocoblock | JetAppointment | High | 7.2 | 2026-10-02 13:29:05 | Deep Dive |
| CVE-2026-104721 | Logback: Incomplete protection against CVE-2026-19880 | QOS.CH Sarl | Logback-classic | Medium | 6.3 | 2026-10-02 13:21:59 | Deep Dive |
| CVE-2026-104613 | CodeAstro Simple Pharmacy Management System view.php sql injection | CodeAstro | Simple Pharmacy Management System | Medium | 6.3 | 2026-10-02 13:15:08 | Deep Dive |
| CVE-2026-85215 | SQL Injection in GG Soft's Paperwork | GG Soft Software Services Inc. | Paperwork | High | 7.1 | 2026-10-02 13:01:52 | Deep Dive |
| CVE-2026-66054 | Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize | Apache Software Foundation | Apache Thrift | Medium | 6.9 | 2026-10-02 12:58:06 | Deep Dive |
| CVE-2026-61374 | Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit | Apache Software Foundation | Apache Thrift | High | 7.1 | 2026-10-02 12:53:00 | Deep Dive |
| CVE-2026-63772 | Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count | Apache Software Foundation | Apache Thrift | High | 8.7 | 2026-10-02 12:52:07 | Deep Dive |
| CVE-2026-66055 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language) | Apache Software Foundation | Apache Thrift | High | 8.2 | 2026-10-02 12:49:41 | Deep Dive |
| CVE-2026-104612 | SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting | SourceCodester | Student Result Management System | Medium | 4.3 | 2026-10-02 12:45:16 | Deep Dive |
| CVE-2026-11795 | User Enumeration in Softtr's E-Commerce Pack | Softtr Informatics Trading Limited Company | E-Commerce Pack | Medium | 5.3 | 2026-10-02 12:42:20 | Deep Dive |
| CVE-2026-102797 | WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability | ThemeREX Group | ThemeREX Addons | Medium | 6.4 | 2026-10-02 12:39:35 | Deep Dive |
| CVE-2026-102798 | WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability | ThemeREX Group | ThemeREX Addons | Medium | 6.5 | 2026-10-02 12:38:28 | Deep Dive |
| CVE-2026-66081 | Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages | Apache Software Foundation | Apache Thrift | High | 8.7 | 2026-10-02 12:33:14 | Deep Dive |