Vulnerability Database & Cybersecurity Intelligence Platform

Real-time CVE vulnerability tracking, CVSS scoring, CISA KEV alerts, and EPSS data to protect your infrastructure from emerging threats.

Vulnerability Statistics

276,476
Total CVEs
14,342
Critical
51,766
High
66,610
Medium
5,482
Low
8,129
Last 30 Days

Critical Vulnerabilities

Highest priority threats requiring immediate attention

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not…

Jul 20, 2026
View Details

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork…

Jul 20, 2026
View Details

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains…

Jul 18, 2026
View Details

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected…

Jul 18, 2026
View Details

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_? in the UI and GET /resources/:resource/:id/:related/new…

Jul 17, 2026
View Details

Complete Security Platform

All the tools you need to monitor, analyze, and respond to vulnerabilities

Latest Published Vulnerabilities

Most recently added CVEs to our database

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within…

Jul 20, 2026

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert…

Jul 20, 2026

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to…

Jul 20, 2026

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape…

Jul 20, 2026

The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one…

Jul 20, 2026

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This…

Jul 20, 2026

Most Affected Vendors & Products

Vendors and products with the highest number of reported vulnerabilities

Protect Your Infrastructure

Explore our comprehensive CVE vulnerability database and stay informed about the latest threats.