Vulnerability Intelligence
at Your Fingertips

Aggregate CVE data from NVD, CISA KEV, EPSS, GitHub, and EUVD — all in one place.

1,709
CISA KEV Entries
5+
Data Sources
Live
Real-time Data

Trending Vulnerabilities

Recent CISA KEV Additions

CVE-2026-84869

ScreenConnect – ConnectWise

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

KEV
2026-09-11
CVE-2026-42016

Artifactory – JFrog

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

KEV
2026-09-11
CVE-2026-42018

Artifactory – JFrog

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

KEV
2026-09-11
CVE-2026-85706

Community Edition and Enterprise Edition – GitLab

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

KEV
2026-09-11
CVE-2026-86060

RouterOS – MikroTik

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

KEV
2026-09-10
CVE-2026-67277

RouterOS – MikroTik

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

KEV
2026-09-10
CVE-2026-19490

NetScaler – Citrix

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

KEV
2026-09-09
CVE-2025-25249

Multiple Products – Fortinet

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

KEV
2026-09-09
View full dashboard →