CVE Intelligence
Real-time vulnerability intelligence from dbcve.org — all severity levels, KEV, vendors, and search.
Live API
10,000
Total CVE
in database
10,000
Critical
severity=CRITICAL
1,687
KEV
actively exploited
3,576
Last 7 Days
published this week
CRITICAL
10,000
HIGH
10,000
MEDIUM
10,000
LOW
0
Latest CVE
7-day window · highest severity
CVE-2026-76460
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attac...
cisco
CRITICAL
10
CVE-2026-85706
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19....
gitlab
CRITICAL
10
CVE-2026-69843
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges ov...
CRITICAL
10
CVE-2026-62874
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate pri...
CRITICAL
10
CVE-2026-85889
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate pr...
CRITICAL
10
Known Exploited (KEV)
CISA — actively exploited in the wild
Critical CVE
severity = CRITICAL · CVSS 9.0–10.0
CVE-2026-93467
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers...
CRITICAL
9.8
CVE-2026-85878
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges ov...
CRITICAL
9.9
CVE-2026-69843
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges ov...
CRITICAL
10
CVE-2026-62874
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate pri...
CRITICAL
10
CVE-2026-87701
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Co...
CRITICAL
9.6
High CVE
severity = HIGH · CVSS 7.0–8.9
CVE-2026-17086
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PH...
HIGH
8.8
CVE-2026-93468
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can...
HIGH
7.5
CVE-2026-93371
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the f...
HIGH
8.3
CVE-2026-93456
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py,...
HIGH
8.2
CVE-2026-93331
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of...
HIGH
7.3
Medium CVE
severity = MEDIUM · CVSS 4.0–6.9
CVE-2026-92991
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API...
MEDIUM
5.4
CVE-2026-15650
The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cr...
MEDIUM
6.4
CVE-2026-14855
The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' paramet...
MEDIUM
6.4
CVE-2026-93455
django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any...
MEDIUM
6.5
CVE-2026-93314
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCode...
MEDIUM
6.3
Low CVE
severity = LOW · CVSS 0.1–3.9
No data available.
Published This Week
7 hari terakhir
CVE-2026-17086
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PH...
HIGH
8.8
CVE-2026-93468
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can...
HIGH
7.5
CVE-2026-93467
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers...
CRITICAL
9.8
CVE-2026-93371
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the f...
HIGH
8.3
CVE-2026-92991
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API...
MEDIUM
5.4
Ethical Use Only
All CVE data is for educational purposes and authorized security testing only.
Real-time API
Data fetched live from dbcve.org with 1-hour cache. Base data from NVD (public domain).
Always Updated
CVE landscape evolves fast. KEV dan enrichment dbcve.org diperbarui harian.
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.