CVE & exploit intelligence
Every entry is a real CVE from the NVD, scored by a local $0 AI model for exploitability, blast radius, and a prioritized remediation — no external providers, no fabricated entries.
500
CVEs indexed
303
AI-analysed
61
Critical
254
With public exploit
500 of 500 CVEs match.
- CVE-2026-134774.7 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-127625.3 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-127303.8 LOW
AI analysis pending — metadata only.
- CVE-2026-100258.2 HIGH
The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.
xxexml-injectioninfo-leakpatch-required - CVE-2026-54876exploit7.5 HIGH
The flaw allows a malicious TLS server to cause a memory leak in a client that checks OCSP responses, potentially leading to Denial of Service.
memory-leakdostlsocsp - CVE-2026-17613exploit7.5 HIGH
The flaw allows any authenticated user to overwrite files and subscribe to WebSocket events, enabling data exfiltration and poisoning.
auth-bypassdata-exfiltrationwebsocketsfile-overwrite - CVE-2026-161028.1 HIGH
The flaw in Keycloak's Dynamic Client Registration component allows attackers to write values to sensitive claim locations, potentially forging administrative roles and gaining full control over the realm.
auth-bypassmisconfigurationidentity-managementkeycloak - CVE-2026-161006.5 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-160715.4 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-155738.1 HIGH
The flaw in Keycloak's PathMatcher allows attackers to bypass security policies by manipulating URLs, granting unauthorized access.
auth-bypasswebsecurity-policy - CVE-2026-124107.8 HIGH
This vulnerability allows a low-privileged user to escalate privileges by creating symlinks during CCleaner uninstallation, potentially gaining SYSTEM access. It matters because it can lead to unauthorized system control.
privilege-escalationlocal-attackuninstaller - CVE-2026-75297.5 HIGH
The flaw allows unauthenticated attackers to modify and disclose data through REST API endpoints due to lack of proper permission checks.
auth-bypasswebwp - CVE-2026-74566.5 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-67623exploit8.8 HIGH
Mistral Vibe before 2.23.3 allows attackers to execute arbitrary commands via a malicious .git/config file, posing a significant security risk.
rcegitrepositoryupdate - CVE-2026-175067.2 HIGH
The flaw allows unauthenticated attackers to inject arbitrary scripts via the 404 not_found_url parameter, leading to cross-site scripting (XSS). This matters because it can be exploited to steal user data or manipulate web pages.
xsswpunauthhtml-injection - CVE-2026-164437.4 HIGH
The flaw in Keycloak's SAML metadata import functionality allows unauthenticated attackers to forge SAML responses and gain unauthorized access by exploiting missing usage attributes for keys.
auth-bypasssamlkeycloakredhat - CVE-2026-159798.1 HIGH
The flaw allows authenticated attackers with author-level access to delete arbitrary files via path traversal, potentially leading to remote code execution.
rceauth-bypasswebfile-deletionwordpress - CVE-2025-70962exploit7.5 HIGH
The flaw allows network attackers to access hardcoded credentials in RTSP authentication, enabling unauthorized viewing of camera footage.
auth-bypassvideo-streamingnetwork-security - CVE-2026-71294exploit7.6 HIGH
The flaw allows deserialization of untrusted data, leading to potential code execution or data manipulation by authenticated users.
rcedeserializationwebauth-required - CVE-2026-71293exploit6.2 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-71292exploit7.2 HIGH
The flaw allows for SQL injection by misusing request parameters in Subrion CMS, enabling attackers to execute arbitrary SQL commands.
sql-injectionwebcmssecurity-update - CVE-2026-71291exploit8.8 HIGH
The flaw allows untrusted content to be executed as Twig templates without sandboxing, enabling Remote Code Execution (RCE).
rcewebcmssecurity - CVE-2026-71289exploit9.8 CRITICAL
The flaw allows direct access to the amp-manager REST API without going through the CAM gateway, enabling unauthorized access and potential full system compromise.
auth-bypassrceapidocker - CVE-2026-71288exploit8.8 HIGH
The flaw allows SQL injection by directly concatenating unvalidated input into an SQL ORDER BY clause without proper allowlisting or validation, leading to potential data manipulation and theft.
sql-injectionrcewebdatabase - CVE-2026-71287exploit8.8 HIGH
The flaw allows SQL injection by not properly sanitizing ORDER BY column names, enabling attackers to execute arbitrary SQL commands.
rcesql-injectionwebsanitization - CVE-2026-71286exploit6.1 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-71285exploit8.1 HIGH
The flaw allows unauthenticated visitors to execute arbitrary JavaScript due to improper handling of user input in Matomo analytics integration, leading to potential session theft and full page takeover.
rcewebjs-injectionsession-theft - CVE-2026-71284exploit7.2 HIGH
The flaw allows an admin to execute arbitrary OS commands by crafting a backup archive, leading to Remote Code Execution (RCE).
rceos-command-injectionbackup - CVE-2026-71283exploit4.9 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-71282exploit6.5 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-71281exploit8.8 HIGH
The flaw allows attackers to execute arbitrary code by providing malicious cache/covariance files, as the torch.load function is called without weights_only=True, bypassing safety checks.
rcecode-executiontorchsecurity - CVE-2026-71280exploit8.5 HIGH
The flaw allows an attacker to potentially manipulate or exploit a caller-supplied bookmark URL due to lack of validation checks, leading to potential security risks.
url-validationhttp-clientsecurity-riskinput-sanitization - CVE-2026-71279exploit8 HIGH
The flaw allows an attacker to execute arbitrary code by manipulating a file path parameter, leading to remote code execution.
rcemqttcode-execution - CVE-2026-71278exploit9.8 CRITICAL
The flaw allows creating a 'calc rule' without authentication, enabling unauthorized access and potential manipulation of critical data.
auth-bypassrcewebapi - CVE-2026-71277exploit9.1 CRITICAL
The flaw allows an attacker to bypass authentication by sending any non-empty Authorization header, granting unauthorized access to protected endpoints.
auth-bypasswebsecurity - CVE-2026-71276exploit7.1 HIGH
The flaw allows SQL injection by authenticated users due to direct interpolation of unvalidated HTTP query string values into raw SQL queries.
rcesql-injectionwebauth-required - CVE-2026-71275exploit5.4 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-71274exploit8.5 HIGH
The flaw allows injection of malicious HTML content due to lack of sanitization and encoding, enabling cross-site scripting (XSS) attacks.
xsshtml-injectionsanitizationrenderingmqtt - CVE-2026-71273exploit6.5 MEDIUM
AI analysis pending — metadata only.
- CVE-2026-71272exploit8.5 HIGH
The flaw allows attackers to manipulate hostname resolution and potentially execute code by exploiting DNS rebinding or similar techniques.
rcedns-rebindingwebhooknetwork