Synchronized NVD + CISA KEV records
CVE Database
Search medium-to-critical vulnerability records by CVE ID, title, product, severity, year, or known-exploited status.
- Catalog records
- 296,062
- medium through critical
- Critical
- 45,909
- highest-impact records
- CISA KEV
- 1,498
- known exploited
- Agent-ready
- 296,062
- bounded composed plans
- CVE-2026-105484A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116CriticalCVSS 10Open remediation record
- CVE-2026-105763Twenty is an open-source CRM (customer relationship management) platformCriticalCVSS 9.6Open remediation record
- CVE-2026-105786Joplin is an open source note-taking and to-do application that organises notes and lists into notebooksHighCVSS 8.5Open remediation record
- CVE-2026-105762Dify is an open-source LLM app development platformHighCVSS 8.3Open remediation record
- CVE-2026-105783Joplin is an open source note-taking and to-do application that organises notes and lists into notebooksHighCVSS 8Open remediation record
- CVE-2026-105764Immich is a high-performance self-hosted photo and video management solutionHighCVSS 7.7Open remediation record
- CVE-2026-39723Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versionsHighCVSS 7.5Open remediation record
- CVE-2026-39789Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versionsHighCVSS 7.5Open remediation record
- CVE-2026-41558Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versionsHighCVSS 7.5Open remediation record
- CVE-2026-41563Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versionsHighCVSS 7.5Open remediation record
No JavaScript? Browse the plain-HTML CVE archive by publication year: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2018. Ready to act on a finding? Use the AI vulnerability remediation playbooks, vulnerable dependency workflow, or CVE intelligence intake gate.
Fast lanes
Start with the queue that matters.
Each link opens a shareable filter. Refine by publication year, title, product, or an exact CVE ID in the catalog.