Real-Time CVE Alerts & Vulnerability Tracker
Search enriched vulnerability intelligence — EPSS exploitability scores, CVSS severity, CISA KEV status — and get instant alerts to Slack, Telegram, Discord or Google Chat.
213,983 results
Website LLMs.txt <= 8.2.6 - Reflected Cross-Site Scripting
Website LLMs.txt <= 8.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting
Responsive Blocks <= 2.2.1 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions
Privilege Bypass in AiAssistant
Information Leak Vulnerability in Honor E
Privilege Bypass in PcManager
NewSoft|NewSoftOA - OS Command Injection
Plugin: CMS für Motorrad Werkstätten <= 1.0.0 - Authenticated (Subscriber+) SQL Injection via 'arttype' Parameter
Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter
FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)
No title available
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
Apktool: Path Traversal to Arbitrary File Write
OpenEXR has integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-2026-34589)
OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
OpenEXR has HTJ2K Signed Integer Overflow in ht_undo_impl()
Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
Neko has Self-service Privilege Escalation for Authenticated Users
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Never miss a critical vulnerability
Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS — get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.
Slack · Telegram · Discord · Google Chat