CVE Find - Vulnerabilities Database

CVE Find is a real-time vulnerability database indexing 382 178 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3550 new CVEs were published in the last 7 days.

Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).

CVE Find
With CVE Find, explore the world's largest database of vulnerabilities.

382 178 vulnerabilities

Last update : 2026-08-24 21h11 +00:00
Common Vulnerabilities and Exposures (CVE), is a list of publicly disclosed computer security flaws.
View CVE 2025
0
Created 7 days ago
0
Updated 7 days ago
0
Created 30 days ago
0
Updated 30 days ago

Free CVE Email Notifications

Get free real-time alerts on new vulnerabilities with CVE Find.
Stay protected and informed instantly !

The last 10 High CVE

Total 382 178 CVE in Datadase
CVE ID Published Description Score Severity

CVE-2026-78555

2026-08-24
19h38 +00:00
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administ...
9.4
Critical

CVE-2026-40877

2026-08-24
19h16 +00:00
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP ob...
Code Injection
8.7
High

CVE-2026-30864

2026-08-24
19h16 +00:00
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflec...
Cross-site Scripting
8.9
High

CVE-2026-76838

2026-08-24
18h17 +00:00
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInter...
Server-Side Request Forgery - SSRF
8.5
High

CVE-2026-76836

2026-08-24
18h17 +00:00
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not requi...
Code InjectionAuthorization problems
8.8
High

CVE-2026-76835

2026-08-24
18h17 +00:00
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk...
9.1
Critical

CVE-2026-76073

2026-08-24
18h17 +00:00
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. An...
Authorization problems
8.8
High

CVE-2026-71933

2026-08-24
18h17 +00:00
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo...
Authorization problems
9.1
Critical

CVE-2026-71921

2026-08-24
18h17 +00:00
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in ...
OS Command Injection
9.8
Critical

CVE-2026-71914

2026-08-24
18h17 +00:00
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component....
OS Command Injection
9.8
Critical

Distribution by CVSS scores


CVE created per quarter since 1999

Frequently asked questions about CVE Find

CVE Find is a cybersecurity vulnerability search engine that aggregates and indexes CVE (Common Vulnerabilities and Exposures), CWE, CAPEC and CPE data from MITRE, NVD and CISA. It allows you to search, filter and monitor security flaws via configurable real-time alerts.

A CVE (Common Vulnerability and Exposure) is a unique identifier assigned to a publicly disclosed computer security flaw. Each CVE is managed by MITRE Corporation and referenced in the NIST National Vulnerability Database (NVD) with a CVSS score evaluating its severity from 0 to 10.

CVSS (Common Vulnerability Scoring System) is an international standard that evaluates the severity of a vulnerability on a scale of 0 to 10. A score of 9 to 10 is rated Critical, 7 to 8.9 High, 4 to 6.9 Medium, and 0.1 to 3.9 Low.

CISA KEV (Known Exploited Vulnerabilities) is a catalog maintained by the US Cybersecurity Agency (CISA) listing CVE vulnerabilities actively exploited in real cyberattacks. US federal organizations are required to remediate them within a mandated deadline.

CVE Find offers a free alert system: create an account, then configure alerts by keyword, by vendor/product (CPE), by CWE category, by CVSS score or based on the CISA KEV list. Notifications are sent by email as soon as a new CVE matches your criteria.