Vulnerability Intelligence

Search every CVE — across OS, package, application, and exploit sources.

172,370
CVEs tracked
49
Active sources
last pull + run counts
1,694
KEV entries
CISA known-exploited
21 min ago
Last ingest
401
Published today
last 24 hours
2,136
Published this week
last 7 days
273
Critical (7d)
new critical this week
8,822
With public exploit
Exploit-DB / Metasploit

Recent critical CVEs See all critical →

CVE Severity CVSS Risk Published Description Impact
CVE-2026-85696 critical 9.8 9.8 33 min ago SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. …
CVE-2026-85695 critical 9.4 9.4 33 min ago FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform …
CVE-2026-85688 critical 9.8 9.8 33 min ago TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT req…
CVE-2026-85684 critical 9.1 9.1 33 min ago marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers ca…
CVE-2026-85672 critical 9.8 9.8 33 min ago zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitize…
CVE-2026-85667 critical 9.1 9.1 33 min ago xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agen…
CVE-2026-85663 critical 9.8 9.8 33 min ago Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can regis…
CVE-2026-85661 critical 9.8 9.8 33 min ago excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply u…
CVE-2026-85184 critical 9.1 9.1 6h ago @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an ab…
CVE-2026-82923 critical 9.8 9.8 6h ago The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to instal…

ubuntu Ubuntu (5,995 total)

CVESeverityPublished
CVE-2026-61547 unknown 1d ago
CVE-2026-59986 unknown 1d ago
CVE-2026-22891 unknown 2d ago
CVE-2026-20777 unknown 2d ago
CVE-2026-27171 unknown 4d ago

debian Debian (60,952 total)

CVESeverityPublished
CVE-2026-85509 critical 11h ago
CVE-2026-85508 critical 11h ago
CVE-2026-85507 critical 11h ago
CVE-2026-85506 critical 11h ago
CVE-2026-85505 high 11h ago

redhat Red Hat / RHEL (11,418 total)

CVESeverityPublished
CVE-2026-82343 medium 7d ago
CVE-2026-82330 medium 7d ago
CVE-2026-82328 medium 7d ago
CVE-2026-82324 medium 7d ago
CVE-2026-79902 medium 9d ago

windows Windows (9,123 total)

CVESeverityPublished
CVE-2026-83711 critical 17h ago
CVE-2026-80098 critical 17h ago
CVE-2026-70352 critical 17h ago
CVE-2026-70178 high 17h ago
CVE-2026-69857 high 17h ago

Top vendors this week