Real-Time CVE Alerts & Vulnerability Tracker
Search enriched vulnerability intelligence โ EPSS exploitability scores, CVSS severity, CISA KEV status โ and get instant alerts to Slack, Telegram, Discord or Google Chat.
283,122 results
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections
Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width
Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-password permission
Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership
Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clients
rclone serve docker Path Traversal via Volume Name
rclone before 1.75.1 Path Traversal via Directory Listing Names
OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
OpenPanel API Authentication Bypass via Unverified Client Secret
OpenPanel SQL Injection via ClickHouse Property Key Filter
OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext
hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM
Totolink A3002MU formWsc command injection
Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions
Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)
LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter
YS LeadGen โ Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input
Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action
WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints
Never miss a critical vulnerability
Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS โ get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.
Slack ยท Telegram ยท Discord ยท Google Chat