Vulnerability Database & Cybersecurity Intelligence Platform

Real-time CVE vulnerability tracking, CVSS scoring, CISA KEV alerts, and EPSS data to protect your infrastructure from emerging threats.

Vulnerability Statistics

281,219
Total CVEs
15,208
Critical
54,297
High
67,768
Medium
5,646
Low
9,547
Last 30 Days

Critical Vulnerabilities

Highest priority threats requiring immediate attention

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its…

Jul 31, 2026
View Details

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition…

Jul 31, 2026
View Details

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in…

Jul 31, 2026
View Details

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer…

Jul 31, 2026
View Details

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read…

Jul 31, 2026
View Details

Complete Security Platform

All the tools you need to monitor, analyze, and respond to vulnerabilities

Latest Published Vulnerabilities

Most recently added CVEs to our database

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent,…

Jul 31, 2026

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute…

Jul 31, 2026

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing…

Jul 31, 2026

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until…

Jul 31, 2026

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an…

Jul 31, 2026

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in…

Jul 31, 2026

Most Affected Vendors & Products

Vendors and products with the highest number of reported vulnerabilities

Protect Your Infrastructure

Explore our comprehensive CVE vulnerability database and stay informed about the latest threats.