Vulnerability Database & Cybersecurity Intelligence Platform

Real-time CVE vulnerability tracking, CVSS scoring, CISA KEV alerts, and EPSS data to protect your infrastructure from emerging threats.

Vulnerability Statistics

237,293
Total CVEs
11,173
Critical
38,564
High
52,296
Medium
4,249
Low
6,702
Last 30 Days

Critical Vulnerabilities

Highest priority threats requiring immediate attention

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a…

Apr 14, 2026
View Details

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not…

Apr 14, 2026
View Details

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an…

Apr 14, 2026
View Details

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…

Apr 14, 2026
View Details

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.

Apr 14, 2026
View Details

Complete Security Platform

All the tools you need to monitor, analyze, and respond to vulnerabilities

Latest Published Vulnerabilities

Most recently added CVEs to our database

A out-of-bounds write vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow…

Apr 14, 2026

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of…

Apr 14, 2026

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior…

Apr 14, 2026

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the…

Apr 14, 2026

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in…

Apr 14, 2026

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability…

Apr 14, 2026

Most Affected Vendors & Products

Vendors and products with the highest number of reported vulnerabilities

Protect Your Infrastructure

Explore our comprehensive CVE vulnerability database and stay informed about the latest threats.