Browse 9,944+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-49819🧪 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | seriousm4x | UpSnap | Critical | 9.8 | 2026-08-12 23:13:46 | Deep Dive |
| CVE-2026-49481🧪 | UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd | seriousm4x | UpSnap | Critical | 9.6 | 2026-08-12 23:08:45 | Deep Dive |
| CVE-2026-71193 | OpenStack Designate <22.0.1 跨租户 DNS 劫持漏洞 | OpenStack | Designate | Critical | 9.6 | 2026-08-12 22:17:13 | Deep Dive |
| CVE-2026-71471 | Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | Critical | 9.0 | 2026-08-12 21:40:12 | Deep Dive |
| CVE-2026-73501🧪 | kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default | getkin | kin-openapi | Critical | 9.1 | 2026-08-12 21:23:41 | Deep Dive |
| CVE-2024-27253 | IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request | IBM | DOORS Next | Critical | 10.0 | 2026-08-12 21:23:03 | Deep Dive |
| CVE-2026-73519🧪 | WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret | wolfsoftwaresystemsltd | WolfStack | Critical | 9.8 | 2026-08-12 21:15:33 | Deep Dive |
| CVE-2026-19001🧪 | MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names | MongoDB | BI Connector ODBC Driver | Critical | 9.8 | 2026-08-12 20:27:03 | Deep Dive |
| CVE-2026-66898🧪 | Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE | Canonical | LXD | Critical | 9.9 | 2026-08-12 20:07:33 | Deep Dive |
| CVE-2026-63293🧪 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | Canonical | LXD | Critical | 9.9 | 2026-08-12 20:00:09 | Deep Dive |
| CVE-2026-63294🧪 | Root RCE via image backup.yaml symlink | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:57:08 | Deep Dive |
| CVE-2026-73414🧪 | Shescape: Shell injection via unescaped parentheses on Windows with CMD | ericcornelissen | shescape | Critical | 9.2 | 2026-08-12 19:42:56 | Deep Dive |
| CVE-2026-72508 | Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | Critical | 9.9 | 2026-08-12 19:41:19 | Deep Dive |
| CVE-2026-17083 | IBM i is Affected By Multiple Vulnerabilities in the Debug Server | IBM | i | Critical | 9.8 | 2026-08-12 19:35:54 | Deep Dive |
| CVE-2026-63296🧪 | Project restriction bypass via instance migration config override | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:27:46 | Deep Dive |
| CVE-2026-63297🧪 | Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:25:24 | Deep Dive |
| CVE-2026-62420🧪 | Cross-project cluster migration bypasses project restrictions via cluster notification flag | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:12:28 | Deep Dive |
| CVE-2026-19656 | ScadaLTS Authenticated Remote Code Execution | SCADA-LTS | ScadaLTS | Critical | 9.9 | 2026-08-12 19:10:11 | Deep Dive |
| CVE-2026-73407🧪 | Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) | Budibase | budibase | Critical | 9.0 | 2026-08-12 19:09:56 | Deep Dive |
| CVE-2026-63300🧪 | Cross-project instance move bypasses all project restrictions allowing host command execution | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:09:04 | Deep Dive |