Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE Database & AI Vulnerability Analysis

Browse 382,364+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.

Trusted by security teams 1,150+ security practitioners 560+ company & university domains · security vendors · in-house teams · academia · bug-bounty hunters
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-90970 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway GitLab GitLab AI Gateway Critical 9.9 2026-10-02 14:34:50 Deep Dive
CVE-2026-104625 CodeAstro Simple Loan Management System index.php sql injection CodeAstro Simple Loan Management System Medium 6.3 2026-10-02 14:30:11 Deep Dive
CVE-2026-5782 Reflected XSS in Loglama.NET's TurkHotspot Loglama.net TurkHotspot Medium 5.2 2026-10-02 14:13:02 Deep Dive
CVE-2026-104026 Sapling SCM <0.2.20260929-102736 代码执行漏洞 Meta Platforms, Inc Sapling SCM - - 2026-10-02 14:06:02 Deep Dive
CVE-2026-104614 CodeAstro Simple Pharmacy Management System delete.php sql injection CodeAstro Simple Pharmacy Management System Medium 6.3 2026-10-02 14:00:09 Deep Dive
CVE-2026-94422 xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape - - High 8.8 2026-10-02 13:54:11 Deep Dive
CVE-2026-19652 Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter DiviEngine Divi Membership Critical 9.8 2026-10-02 13:29:06 Deep Dive
CVE-2026-93875 JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter Crocoblock JetAppointment High 7.2 2026-10-02 13:29:05 Deep Dive
CVE-2026-104721 Logback: Incomplete protection against CVE-2026-19880 QOS.CH Sarl Logback-classic Medium 6.3 2026-10-02 13:21:59 Deep Dive
CVE-2026-104613 CodeAstro Simple Pharmacy Management System view.php sql injection CodeAstro Simple Pharmacy Management System Medium 6.3 2026-10-02 13:15:08 Deep Dive
CVE-2026-85215 SQL Injection in GG Soft's Paperwork GG Soft Software Services Inc. Paperwork High 7.1 2026-10-02 13:01:52 Deep Dive
CVE-2026-66054 Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize Apache Software Foundation Apache Thrift Medium 6.9 2026-10-02 12:58:06 Deep Dive
CVE-2026-61374 Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit Apache Software Foundation Apache Thrift High 7.1 2026-10-02 12:53:00 Deep Dive
CVE-2026-63772 Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count Apache Software Foundation Apache Thrift High 8.7 2026-10-02 12:52:07 Deep Dive
CVE-2026-66055 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language) Apache Software Foundation Apache Thrift High 8.2 2026-10-02 12:49:41 Deep Dive
CVE-2026-104612 SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting SourceCodester Student Result Management System Medium 4.3 2026-10-02 12:45:16 Deep Dive
CVE-2026-11795 User Enumeration in Softtr's E-Commerce Pack Softtr Informatics Trading Limited Company E-Commerce Pack Medium 5.3 2026-10-02 12:42:20 Deep Dive
CVE-2026-102797 WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability ThemeREX Group ThemeREX Addons Medium 6.4 2026-10-02 12:39:35 Deep Dive
CVE-2026-102798 WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability ThemeREX Group ThemeREX Addons Medium 6.5 2026-10-02 12:38:28 Deep Dive
CVE-2026-66081 Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages Apache Software Foundation Apache Thrift High 8.7 2026-10-02 12:33:14 Deep Dive

Frequently Asked Questions

340,000+ CVEs aggregated from NVD and CNNVD, updated daily with AI-generated Chinese translations.

Basic CVE data is completely free. AI PoC generation and premium intelligence features require a Pro or Pro+ subscription.

When a CVE has no public proof-of-concept, Shenlong AI automatically generates exploit code and a technical analysis report based on the vulnerability description and references.

Yes. Shenlong AI has translated NVD English descriptions into Chinese, so you can search CVEs using Chinese keywords directly.