Real-Time CVE Alerts & Vulnerability Tracker
Search enriched vulnerability intelligence โ EPSS exploitability scores, CVSS severity, CISA KEV status โ and get instant alerts to Slack, Telegram, Discord or Google Chat.
283,447 results
Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)
Envoy: use-after-free in QUIC on internal redirects
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy
Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check
Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket_options is null
Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST clusters
Envoy: oghttp2 upstream trailers incorrect handling
Denial-of-Service in the OpenCanary Redis service
No title available
Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values
Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool
Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault
luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root
No title available
luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entries
Tautulli: Reflected XSS in `/search` endpoint
Tautulli: Stored Cross-Site Scripting (XSS) in the newsletter
Tautulli: Open redirect via whitespace bypass in /auth/redirect
Tautulli: Path traversal / arbitrary file write via unsanitized upload filename in import_config and import_database
Never miss a critical vulnerability
Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS โ get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.
Slack ยท Telegram ยท Discord ยท Google Chat