vuln
feed
2026-08-04 · 9138 vulnerabilities
new today
NVD · Ubuntu · Debian · CISA KEV · OSS-Security · OpenStack · Kubernetes · Exploit-DB · Red Hat · GitHub · OSV
Today (live)
🚫 Patch now
⚠ 0-days
📅 New this week
📈 Trending
Stats
🔍 Search
Archive
🛡 How to scan
📊 Grafana
⚡ n8n
🤖 Agents
🔔 Subscribe
▸ RSS
API
{ } JSON
📧 Weekly digest
Dismiss
Clear reviewed
Browse by product
Kubernetes
38
nginx
13
OpenSSL
43
OpenSSH
15
Linux Kernel
36
Docker
22
OpenStack
4
Redis
11
PostgreSQL
26
Flask
1
Log4j
4
Spring Framework
9
Grafana
1
HashiCorp Vault
6
Traefik
1
Cilium
1
containerd
15
curl
29
Ansible
5
GitLab
14
Cisco
1
Arista
2
Microsoft
7001
Windows
1380
VMware
6
F5
48
Browse by weakness
SQL Injection
112
Cross-Site Scripting (XSS)
130
OS Command Injection
75
Path Traversal
99
Out-of-bounds Write
64
Out-of-bounds Read
108
Use After Free
575
Code Injection
41
Deserialization
19
XML External Entity (XXE)
7
Server-Side Request Forgery (SSRF)
70
Cross-Site Request Forgery (CSRF)
29
Integer Overflow
128
NULL Pointer Dereference
77
Privilege Escalation
63
Missing Authentication
34
Improper Input Validation
126
Buffer Overflow
208
Hardcoded Credentials
17
Unrestricted File Upload
20
★ Watchlist keywords:
Add
Show only
Vulnerabilities — last 14 days
Clear
All Severity
Critical
High
Medium
Low
Unknown
All Sources
NVD
Ubuntu
Debian
CISA KEV
OSS-Security
OpenStack
Kubernetes
Exploit-DB
Red Hat
GitHub
OSV
Cisco
Arista
Microsoft
Fortinet
Juniper
Period:
All time
Last 24h
Last 7 days
Last 30 days
Last year
New since yesterday
★ Watchlist
Sort:
Severity
Newest first
Score
EPSS
Showing
0
of
9138
— Press
Esc
to clear
Vulnerabilities
Security News
0
↓ CSV
🔗 Share
🔔 Get notified about critical CVEs
📧 Email digest
🔔 Push (ntfy.sh)
▸ RSS
All options →
✕
Loading vulnerabilities…
No results
Try a different keyword or clear the filters.
×
📧
Weekly Digest
Top CVEs every Monday. No spam, unsubscribe anytime.
Topics — leave blank for everything
Kubernetes
Windows
Linux Kernel
Ubuntu
Debian
OpenStack
Cisco
Fortinet
VMware
macOS
Android
nginx
Subscribe
✓ Subscribed — see you Monday!
Recent Critical & High-Severity CVEs
CVE-2026-16498
: The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue
[CRITICAL 10.0]
CVE-2026-65883
: Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guar
[CRITICAL 10.0]
CVE-2026-65884
: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method
[CRITICAL 10.0]
CVE-2026-65887
: Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The
[CRITICAL 10.0]
CVE-2026-65888
: Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogi
[CRITICAL 10.0]
CVE-2026-54735
: Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Pr
[CRITICAL 10.0]
CVE-2026-16326
: In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless
[CRITICAL 10.0]
CVE-2026-67429
: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.dow
[CRITICAL 10.0]
CVE-2026-48449
: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu
[CRITICAL 10.0]
CVE-2026-66803
: Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a ne
[CRITICAL 10.0]
CVE-2026-18452
: DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauth
[CRITICAL 10.0]
CVE-2026-33591
: A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker
[CRITICAL 10.0]
CVE-2026-48323
: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a
[CRITICAL 10.0]
CVE-2026-48330
: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a
[CRITICAL 10.0]
CVE-2026-48331
: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that
[CRITICAL 10.0]
CVE-2026-52887
: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
[CRITICAL 10.0]
CVE-2026-56163
: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-56191
: Microsoft Exchange Online Tampering Vulnerability
[CRITICAL 10.0]
CVE-2026-57106
: Data Quality Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-62825
: Azure Key Vault Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-58630
: Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-58275
: Azure DNS Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-33819
: Microsoft Bing Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-32186
: Microsoft Bing Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-33107
: Azure Databricks Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-35431
: Microsoft Entra ID Entitlement Management Spoofing Vulnerability
[CRITICAL 10.0]
CVE-2026-32213
: Azure AI Foundry Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-33105
: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-40175
: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
[CRITICAL 10.0]
CVE-2026-42960
: Possible cache poisoning via promiscuous records for the authority section
[CRITICAL 10.0]
CVE-2026-46595
: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
[CRITICAL 10.0]
CVE-2026-39821
: Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
[CRITICAL 10.0]
CVE-2026-40412
: Azure Orbital Spatio Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-23652
: Microsoft Power Pages Remote Code Execution Vulnerability
[CRITICAL 10.0]
CVE-2026-47280
: Azure Resource Manager Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-42822
: Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-42826
: Azure DevOps Information Disclosure Vulnerability
[CRITICAL 10.0]
CVE-2026-41104
: Microsoft Planetary Computer Pro Information Disclosure Vulnerability
[CRITICAL 10.0]
CVE-2026-42901
: Microsoft Entra ID Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-55241
: Azure Entra ID Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-54914
: Azure Networking Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-45480
: Azure Active Directory Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2026-48567
: Azure HorizonDB Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2025-29813
: Azure DevOps Elevation of Privilege Vulnerability
[CRITICAL 10.0]
CVE-2024-24576
: Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
[CRITICAL 10.0]
CVE-2026-63227
: An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module desig
[CRITICAL 9.9]
CVE-2026-63232
: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated att
[CRITICAL 9.9]
CVE-2026-63233
: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated att
[CRITICAL 9.9]
CVE-2026-63234
: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated att
[CRITICAL 9.9]
CVE-2026-54680
: Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior t
[CRITICAL 9.9]