Search the world’s CVEslive from our database
122.2K+ CVEs enriched with EPSS, CISA KEV, CERT-FR, MSRC, GHSA, Exploit-DB, and Nuclei. Public REST API, free tier available.
NVD-backed, continuously synced
CISA KEV catalog ∪ SSVC=active
Severity = CRITICAL, published in window
FIRST exploit-prediction probability
refreshed every 30 min · source: production PostgreSQL
Hot CVEs right now
Recent high-severity CVEs straight from our PostgreSQL catalog — with KEV, EPSS, and exploitation flags inline.
CVE-2026-77226
Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the ca…
CVE-2026-105773
Canimaan Software ClamXAV local privilege escalation
Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary code…
CVE-2026-105741
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_…
CVE-2026-105740
Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The use…
CVE-2026-105697
Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3)…
CVE-2026-102262
Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's f…
CVE-2026-97257
WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
CVE-2026-93617
WordPress Sunshine Photo Cart plugin <= 3.7.1 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
CVE-2026-105691
Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec.…
Three lenses on the catalog
Same database, different cuts. Each list is a real query against cveCatalog at request time.
- medium severityCVE-2026-88779EPSS 1 %Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
- not applicableCVE-2026-102490EPSS 1 %All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
- not applicableCVE-2026-102489EPSS 1 %Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
- high severityCVE-2024-7593EPSS 100 %Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
- high severityCVE-2024-3400EPSS 100 %A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
- medium severityCVE-2024-21893EPSS 100 %A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
No unauthenticated RCEs flagged yet.
What we enrich every CVE with
Nine upstream sources, one normalized record per CVE.
Base CVE record + CVSS v3 scores and vectors
Known Exploited Vulnerabilities catalog with due dates
FIRST exploit-prediction score and percentile
French national CSIRT advisories with severity
Microsoft Security Response Center title + KB articles
GitHub Security Advisories cross-references
Public proof-of-concept and exploit identifiers
Detection-template availability flag
Change-log titles and history counts
What teams use it for
Vulnerability management
Continuous CPE-based monitoring with KEV / EPSS prioritization for the products you actually run.
Patch prioritization
Combine CVSS, EPSS, and KEV signals to rank which CVEs deserve emergency change windows.
CI/CD gating
Block pull requests when a dependency surfaces a high-EPSS or KEV-flagged CVE in the bulk API.
Compliance reporting
Export filtered CVE lists with CERT-FR / KEV / GHSA links for audit packets.
High-priority CVE advisory index
Stable public pages for CVEs with exploitation, KEV, EPSS, or severity signals useful during vendor and patch-risk research.
Frequently asked questions
How many CVEs are in the catalog?
The full NVD CVE catalog from 1999 to present is ingested with continuous backfill, and the count above reflects the live row count in our PostgreSQL store. We enrich each record with CISA KEV, EPSS, CERT-FR, MSRC, GHSA, Exploit-DB, Nuclei template availability, and OpenCVE change history when available.
How fresh is the data?
Daily NVD sync plus EPSS daily snapshots, CISA KEV refresh, and external enrichment cron jobs. The most recent CVEs typically land within a few hours of NVD publication.
What does "actively exploited" mean?
A CVE is shown as actively exploited when at least one of these is true: it appears in the CISA KEV catalog, FIRST has classified its SSVC exploitation level as "active", or our GCVE (Google CVE) enrichment has confirmed in-the-wild exploitation evidence.
How does EPSS differ from CVSS?
CVSS measures intrinsic severity (impact × exploitability). EPSS measures the empirical probability that a CVE will be exploited in the wild within the next 30 days, based on global telemetry. We surface both — most teams prioritize on EPSS × KEV first, then CVSS for ties.
Is CVE search included on the free tier?
Yes. The Free plan (€0, no credit card) includes 50 reputation/CVE checks per month with rate-limited API access, AI-generated assessment, batches of up to 10 indicators and a sample of the downloadable blocklists. Pro (€99/mo) raises that to 10,000 checks a month and adds larger batches, the full blocklists, the SSE stream, webhooks and STIX/TAXII.
Can I subscribe to alerts when new CVEs match my stack?
Yes — that is what CVE Watch is for. You define perimeters of CPE strings (the products and versions you run) and we continuously match new CVEs to those perimeters. Alerts are delivered via dashboard, email, webhook, or the SSE stream.
Is the API public?
No. The /api/cve and /api/cve/recent endpoints require an API key; a free key works (50 requests/month). The CVE pages on this site are public.
How do I cite or link to a single CVE?
Every CVE in the catalog gets a stable canonical page at https://ismalicious.com/cve/CVE-YYYY-NNNNN with full metadata, JSON-LD, and links to the original NVD/KEV/CERT-FR/MSRC/GHSA references.
Wire CVE intel into your stack
Free API key, 50 checks/month, no credit card. Bulk lookups on every plan, in larger batches on paid plans; the threat stream API needs Pro or Enterprise.
No credit card required · 50 free checks/month