Vulnerability Intelligence
at Your Fingertips

Aggregate CVE data from NVD, CISA KEV, EPSS, GitHub, and EUVD — all in one place.

1,674
CISA KEV Entries
5+
Data Sources
Live
Real-time Data

Trending Vulnerabilities

Recent CISA KEV Additions

CVE-2026-73570

Zimbra Collaboration Suite (ZCS) – Synacor

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

KEV
2026-08-21
CVE-2026-72530

Server – TrueConf

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

KEV
2026-08-20
CVE-2026-72529

Server – TrueConf

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

KEV
2026-08-20
CVE-2026-64849

MLflow – MLflow

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

KEV
2026-08-19
CVE-2026-33824

Internet Key Exchange (IKE) Service Extensions – Microsoft

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

KEV
2026-08-18
CVE-2026-59310

VMware vCenter – Broadcom

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

KEV
2026-08-18
CVE-2026-55040

SharePoint – Microsoft

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

KEV
2026-08-18
CVE-2026-65400

macOS – Apple

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

KEV
2026-08-18
View full dashboard →