CVE Database
Browse 57,566 vulnerability records with severity scores, exploit predictions, and KEV status.
Known Exploited Vulnerabilities
CISA KEVIn the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on th
An authenticated user may write data outside the intended Docker cache path under specific remote-re
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or errone
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusi
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the o
Recent Vulnerabilities
View all 2026 →A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker t
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a
Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sa
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affe
A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--
Detect CVEs Automatically
CyberStrike scans your infrastructure and detects known vulnerabilities in real time.
Get Started