Search the world's CVEslive from our database
101.7K+ CVEs enriched with EPSS, CISA KEV, CERT-FR, MSRC, GHSA, Exploit-DB, and Nuclei. Public REST API, free tier available.
NVD-backed, continuously synced
CISA KEV catalog ∪ SSVC=active
Severity = CRITICAL, published in window
FIRST exploit-prediction probability
refreshed every 30 min · source: production PostgreSQL
Hot CVEs right now
Recent high-severity CVEs straight from our PostgreSQL catalog — with KEV, EPSS, and exploitation flags inline.
CVE-2026-76990
A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launch…
CVE-2026-76833
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied…
CVE-2026-76635
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence u…
CVE-2026-76633
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusi…
CVE-2026-15706
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Manageme…
CVE-2026-76987
A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Att…
CVE-2026-74011
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
CVE-2026-28164
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
CVE-2026-66605
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
Three lenses on the catalog
Same database, different cuts. Each list is a real query against cveCatalog at request time.
- medium severityCVE-2026-65400EPSS 0 %An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
- high severityCVE-2026-59310EPSS 1 %VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
- high severityCVE-2026-55040EPSS 1 %Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- high severityCVE-2024-27198EPSS 95 %In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- medium severityCVE-2023-23752EPSS 95 %An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- medium severityCVE-2024-27199EPSS 94 %In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
No unauthenticated RCEs flagged yet.
What we enrich every CVE with
Nine upstream sources, one normalized record per CVE.
Base CVE record + CVSS v3 scores and vectors
Known Exploited Vulnerabilities catalog with due dates
FIRST exploit-prediction score and percentile
French national CSIRT advisories with severity
Microsoft Security Response Center title + KB articles
GitHub Security Advisories cross-references
Public proof-of-concept and exploit identifiers
Detection-template availability flag
Change-log titles and history counts
What teams use it for
Vulnerability management
Continuous CPE-based monitoring with KEV / EPSS prioritization for the products you actually run.
Patch prioritization
Combine CVSS, EPSS, and KEV signals to rank which CVEs deserve emergency change windows.
CI/CD gating
Block pull requests when a dependency surfaces a high-EPSS or KEV-flagged CVE in the bulk API.
Compliance reporting
Export filtered CVE lists with CERT-FR / KEV / GHSA links for audit packets.
High-priority CVE advisory index
Stable public pages for CVEs with exploitation, KEV, EPSS, or severity signals useful during vendor and patch-risk research.
Frequently asked questions
How many CVEs are in the catalog?
The full NVD CVE catalog from 1999 to present is ingested with continuous backfill, and the count above reflects the live row count in our PostgreSQL store. We enrich each record with CISA KEV, EPSS, CERT-FR, MSRC, GHSA, Exploit-DB, Nuclei template availability, and OpenCVE change history when available.
How fresh is the data?
Daily NVD sync plus EPSS daily snapshots, CISA KEV refresh, and external enrichment cron jobs. The most recent CVEs typically land within a few hours of NVD publication.
What does "actively exploited" mean?
A CVE is shown as actively exploited when at least one of these is true: it appears in the CISA KEV catalog, FIRST has classified its SSVC exploitation level as "active", or our GCVE (Google CVE) enrichment has confirmed in-the-wild exploitation evidence.
How does EPSS differ from CVSS?
CVSS measures intrinsic severity (impact × exploitability). EPSS measures the empirical probability that a CVE will be exploited in the wild within the next 30 days, based on global telemetry. We surface both — most teams prioritize on EPSS × KEV first, then CVSS for ties.
Is CVE search included on the free tier?
Yes. The Free plan (€0, no credit card) includes 30 reputation/CVE checks per month with rate-limited API access. Pro (€99/mo) raises that to 10,000 and includes bulk, downloadable blocklists, AI-generated assessment, the SSE stream, webhooks, and STIX/TAXII.
Can I subscribe to alerts when new CVEs match my stack?
Yes — that is what CVE Watch is for. You define perimeters of CPE strings (the products and versions you run) and we continuously match new CVEs to those perimeters. Alerts are delivered via dashboard, email, webhook, or the SSE stream.
Is the API public?
The /api/cve and /api/cve/recent endpoints are publicly accessible (rate-limited) so you can integrate without an API key for low-volume usage. Higher-volume access requires registration and a free or paid plan.
How do I cite or link to a single CVE?
Every CVE in the catalog gets a stable canonical page at https://ismalicious.com/cve/CVE-YYYY-NNNNN with full metadata, JSON-LD, and links to the original NVD/KEV/CERT-FR/MSRC/GHSA references.
Wire CVE intel into your stack
Free API key, 30 checks/month, no credit card. Bulk and stream endpoints available on Pro.
No credit card required · 30 free checks/month