Real-Time CVE Alerts & Vulnerability Tracker
Search enriched vulnerability intelligence — EPSS exploitability scores, CVSS severity, CISA KEV status — and get instant alerts to Slack, Telegram, Discord or Google Chat.
279,838 results
No title available
No title available
No title available
IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUpdate::updateDisplayOrder) allows an authenticated sitemap user to reorder arbitrary pages
Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote file import when multiple URLs share a host but use different ports
Netmaker has a boolean‑based SQL Injection
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
Go-getter vulnerable to a privilege escalation issue in its archive decompression handling
Out-of-bounds read in IMAP response parser
Buffer overrun in IMAP
Ambiguous parsing of mail headers
OpenCTI: Synchronizer SSRF: stream fetch has no URL validation
OpenCTI: User-Controlled ReDoS in JSON Ingestion Mapper
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search pres
Http4s: DigestAuth allows replay of captured requests
Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Authorization and CSRF Token Validation
Http4s Ember HTTP/2: unbounded inbound body buffering
Unauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways
Never miss a critical vulnerability
Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS — get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.
Slack · Telegram · Discord · Google Chat