Real-Time CVE Alerts & Vulnerability Tracker
Search enriched vulnerability intelligence β EPSS exploitability scores, CVSS severity, CISA KEV status β and get instant alerts to Slack, Telegram, Discord or Google Chat.
247,821 results
ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite
PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions
Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field
Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Forgery via 'ga_id' Parameter
Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter
No title available
No title available
Path Traversal via Percent-Encoding in nltk.data.find() and nltk.data.load()
NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure
Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
Apache Tomcat: Security constraints for default servlet ignored method
Apache Tomcat: EncryptInterceptor not protected against replay attacks
Apache Tomcat: Logged effective web.xml is incomplete
CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path
Never miss a critical vulnerability
Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS β get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.
Slack Β· Telegram Β· Discord Β· Google Chat