CVE Intelligence
Real-time vulnerability intelligence from dbcve.org — all severity levels, KEV, vendors, and search.
Live API
10,000
Total CVE
in database
10,000
Critical
severity=CRITICAL
1,690
KEV
actively exploited
3,657
Last 7 Days
published this week
CRITICAL
10,000
HIGH
10,000
MEDIUM
10,000
LOW
0
Latest CVE
7-day window · highest severity
CVE-2026-76460
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attac...
cisco
CRITICAL
10
CVE-2026-85706
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19....
gitlab
CRITICAL
10
CVE-2026-93740
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt o...
CRITICAL
10
CVE-2026-10747
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary c...
CRITICAL
10
CVE-2025-15399
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnera...
CRITICAL
10
Known Exploited (KEV)
CISA — actively exploited in the wild
Critical CVE
severity = CRITICAL · CVSS 9.0–10.0
CVE-2026-92229
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable...
CRITICAL
9.1
CVE-2026-89274
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to,...
CRITICAL
9.1
CVE-2026-84434
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and inclu...
CRITICAL
9.8
CVE-2026-93740
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt o...
CRITICAL
10
CVE-2026-93739
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of th...
CRITICAL
9.9
High CVE
severity = HIGH · CVSS 7.0–8.9
CVE-2026-92807
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all ...
HIGH
8.8
CVE-2026-87909
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wp...
HIGH
7.5
CVE-2026-13354
The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Co...
HIGH
7.2
CVE-2026-93923
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, a...
HIGH
8.8
CVE-2026-93922
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allo...
HIGH
8.8
Medium CVE
severity = MEDIUM · CVSS 4.0–6.9
CVE-2026-92967
The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter i...
MEDIUM
6.1
CVE-2026-89334
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerab...
MEDIUM
6.5
CVE-2026-89333
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Obj...
MEDIUM
6.5
CVE-2026-89093
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerab...
MEDIUM
5.3
CVE-2026-89081
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Sit...
MEDIUM
6.1
Low CVE
severity = LOW · CVSS 0.1–3.9
No data available.
Published This Week
7 hari terakhir
CVE-2026-92967
The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter i...
MEDIUM
6.1
CVE-2026-92807
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all ...
HIGH
8.8
CVE-2026-92229
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable...
CRITICAL
9.1
CVE-2026-89334
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerab...
MEDIUM
6.5
CVE-2026-89333
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Obj...
MEDIUM
6.5
Ethical Use Only
All CVE data is for educational purposes and authorized security testing only.
Real-time API
Data fetched live from dbcve.org with 1-hour cache. Base data from NVD (public domain).
Always Updated
CVE landscape evolves fast. KEV dan enrichment dbcve.org diperbarui harian.
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.