Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE Database & AI Vulnerability Analysis

Browse 70+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.

Track malicious packages and archived sample intelligenceExplore malicious packages
Trusted by security teams 900+security practitioners400+company & university domains· security vendors · in-house teams · academia · bug-bounty hunters
Found 70 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-71287🧪 Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection Cacticacti High 8.8 2026-08-05 12:26:33 Deep Dive
CVE-2026-40941 Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages Cacticacti 高危 -2026-06-25 23:01:31 Deep Dive
CVE-2026-40084 Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter Cacticacti Medium 6.5 2026-06-25 22:43:47 Deep Dive
CVE-2026-40083🧪 Cacti: SQL Injection in managers.php Cacticacti High 7.2 2026-06-25 22:39:18 Deep Dive
CVE-2026-40082 Cacti: Session Fixation via missing session_regenerate_id() after login Cacticacti Medium 5.4 2026-06-25 22:33:46 Deep Dive
CVE-2026-40080 Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect Cacticacti Medium 6.1 2026-06-25 22:29:52 Deep Dive
CVE-2026-40079 Cacti: Command Injection via escape_command() no-op in RRDtool execution Cacticacti 高危 -2026-06-24 23:26:41 Deep Dive
CVE-2026-39951🧪 Cacti: Stored SQL Injection via graph_name_regexp in Reports feature Cacticacti High 7.6 2026-06-24 23:14:39 Deep Dive
CVE-2026-39948 Cacti has SQL Injection via rfilter parameter in RLIKE clauses Cacticacti 超危 -2026-06-24 23:06:39 Deep Dive
CVE-2026-39955🧪 Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php Cacticacti Critical 9.8 2026-06-24 22:49:14 Deep Dive
CVE-2026-39938🧪 Cacti: Unauthenticated RCE on Graph Image Cacticacti Critical 9.8 2026-06-24 22:41:05 Deep Dive
CVE-2026-39900 Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context Cacticacti 中危 -2026-06-24 22:37:18 Deep Dive
CVE-2026-39899 Cacti: Path Traversal via filename parameter in package_import.php Cacticacti--2026-06-24 22:33:14 Deep Dive
CVE-2026-39897 Cacti has a Reflected XSS Vulnerability via html_auth_footer Cacticacti 中危 -2026-06-24 22:00:56 Deep Dive
CVE-2026-39894 Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting Cacticacti Low 2.9 2026-06-24 21:55:50 Deep Dive
CVE-2026-39893🧪 Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php Cacticacti Critical 9.8 2026-06-24 21:45:35 Deep Dive
CVE-2025-66399 SNMP Command Injection leads to RCE in Cacti EPSS 0.11Cacticacti--2025-12-02 17:57:12 Deep Dive
CVE-2005-10004💣 Cacti graph_view.php RCE via graph_start Parameter Injection Raxnet/Ian BerryCacti High 8.7 2025-08-30 13:45:16 Deep Dive
CVE-2025-26520🧪 Cacti 安全漏洞 CactiCacti High 7.6 2025-02-12 00:00:00 Deep Dive
CVE-2025-24368 Cacti has a SQL Injection vulnerability when using tree rules through Automation API Cacticacti 中危 -2025-01-27 17:16:17 Deep Dive

Frequently Asked Questions

340,000+ CVEs aggregated from NVD and CNNVD, updated daily with AI-generated Chinese translations.

Basic CVE data is completely free. AI PoC generation and premium intelligence features require a Pro or Pro+ subscription.

When a CVE has no public proof-of-concept, Shenlong AI automatically generates exploit code and a technical analysis report based on the vulnerability description and references.

Yes. Shenlong AI has translated NVD English descriptions into Chinese, so you can search CVEs using Chinese keywords directly.