Know the exploit before it knows you.
Search real CVEs and public exploits, each scored by a local AI model for exploitability, blast radius, and remediation. Free, no signup, no external providers.
500
CVEs indexed
303
AI-analysed
61
Critical
254
With public exploit
Search the live archive
Full search & filters →500 of 500 CVEs match.
- CVE-2026-134774.7 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-127625.3 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-127303.8 LOW
AI analysis pending — metadata only.
- CVE-2026-100258.2 HIGH
The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.
xxexml-injectioninfo-leakpatch-required - CVE-2026-54876exploit7.5 HIGH
The flaw allows a malicious TLS server to cause a memory leak in a client that checks OCSP responses, potentially leading to Denial of Service.
memory-leakdostlsocsp - CVE-2026-17613exploit7.5 HIGH
The flaw allows any authenticated user to overwrite files and subscribe to WebSocket events, enabling data exfiltration and poisoning.
auth-bypassdata-exfiltrationwebsocketsfile-overwrite - CVE-2026-161028.1 HIGH
The flaw in Keycloak's Dynamic Client Registration component allows attackers to write values to sensitive claim locations, potentially forging administrative roles and gaining full control over the realm.
auth-bypassmisconfigurationidentity-managementkeycloak - CVE-2026-161006.5 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-160715.4 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-155738.1 HIGH
The flaw in Keycloak's PathMatcher allows attackers to bypass security policies by manipulating URLs, granting unauthorized access.
auth-bypasswebsecurity-policy - CVE-2026-124107.8 HIGH
This vulnerability allows a low-privileged user to escalate privileges by creating symlinks during CCleaner uninstallation, potentially gaining SYSTEM access. It matters because it can lead to unauthorized system control.
privilege-escalationlocal-attackuninstaller - CVE-2026-75297.5 HIGH
The flaw allows unauthenticated attackers to modify and disclose data through REST API endpoints due to lack of proper permission checks.
auth-bypasswebwp
Data: NVD. Analysis: a local $0 model — 303 of 500 entries carry a model-written read; the rest ship metadata only and are labelled as such.
What the AI read looks like
- Summary
- The flaw allows unauthenticated users to delete arbitrary files, leading to potential full site takeover.
- Exploitability
- Exploitation is relatively easy as no authentication is required; attackers need only upload a malicious file path.
- Blast radius
- If exploited, the impact could be severe, potentially compromising the entire website and data.
- Remediation
- Update to Custom Fields WordPress plugin version 1.5.1 or later immediately.
Generated locally by qwen2.5:7b-instruct. No external provider saw this query.
Unified CVE + exploit search
One query across the CVE corpus and public proof-of-concept exploits — no more tab-hopping between six databases.
AI risk analysis
Analysed entries carry a model-generated read: exploitability, prerequisites, likely blast radius, and a prioritized remediation note.
Free API & feed
Every entry is also a static JSON endpoint, plus an RSS feed — no key, no rate limit. Read the docs.
Pricing
Search, the archive, the API and the feed are free today. Prices below are founding-member preview pricing for the paid tier and may change at launch.
Free
$0
- ✓Full CVE & exploit search
- ✓AI risk analysis on analysed entries
- ✓JSON API & RSS feed
Pro
$29/mo
- ✓Watchlists & change alerts
- ✓Analysis on every entry, on ingest
- ✓Bulk export
- ✓Priority intel updates
Team
Contact us
- ✓Everything in Pro
- ✓Shared watchlists & seats
- ✓SSO & audit log
- ✓Dedicated support
Want Pro when it lands?
Search and the API stay free. Join the waitlist for founding-member pricing on watchlists, alerts, and full-archive analysis.