CVE Find - Vulnerabilities Database

CVE Find is a real-time vulnerability database indexing 346 657 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1518 new CVEs were published in the last 7 days.

Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).

CVE Find
With CVE Find, explore the world's largest database of vulnerabilities.

346 657 vulnerabilities

Last update : 2026-04-28 10h44 +00:00
Common Vulnerabilities and Exposures (CVE), is a list of publicly disclosed computer security flaws.
View CVE 2025
0
Created 7 days ago
0
Updated 7 days ago
0
Created 30 days ago
0
Updated 30 days ago

Free CVE Email Notifications

Get free real-time alerts on new vulnerabilities with CVE Find.
Stay protected and informed instantly !

The last 10 High CVE

Total 346 657 CVE in Datadase
CVE ID Published Description Score Severity

CVE-2026-7280

2026-04-28
09h46 +00:00
AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged...
8.4
High

CVE-2026-7248

2026-04-28
09h16 +00:00
A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the ...
Overflow
9.8
Critical

CVE-2026-7244

2026-04-28
09h16 +00:00
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
Command InjectionOS Command Injection
9.8
Critical

CVE-2026-7243

2026-04-28
09h16 +00:00
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the ...
Command InjectionOS Command Injection
9.8
Critical

CVE-2026-7242

2026-04-28
09h16 +00:00
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function set...
Command InjectionOS Command Injection
9.8
Critical

CVE-2026-7241

2026-04-28
09h16 +00:00
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function s...
Command InjectionOS Command Injection
9.8
Critical

CVE-2026-40978

2026-04-28
09h16 +00:00
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitra...
SQL Injection
8.8
High

CVE-2026-7240

2026-04-28
08h16 +00:00
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects t...
Command InjectionOS Command Injection
9.8
Critical

CVE-2026-40967

2026-04-28
07h16 +00:00
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object an...
Code Injection
8.6
High

CVE-2026-7204

2026-04-28
01h16 +00:00
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the funct...
Command InjectionOS Command Injection
9.8
Critical

Distribution by CVSS scores


CVE created per quarter since 1999

Frequently asked questions about CVE Find

CVE Find is a cybersecurity vulnerability search engine that aggregates and indexes CVE (Common Vulnerabilities and Exposures), CWE, CAPEC and CPE data from MITRE, NVD and CISA. It allows you to search, filter and monitor security flaws via configurable real-time alerts.

A CVE (Common Vulnerability and Exposure) is a unique identifier assigned to a publicly disclosed computer security flaw. Each CVE is managed by MITRE Corporation and referenced in the NIST National Vulnerability Database (NVD) with a CVSS score evaluating its severity from 0 to 10.

CVSS (Common Vulnerability Scoring System) is an international standard that evaluates the severity of a vulnerability on a scale of 0 to 10. A score of 9 to 10 is rated Critical, 7 to 8.9 High, 4 to 6.9 Medium, and 0.1 to 3.9 Low.

CISA KEV (Known Exploited Vulnerabilities) is a catalog maintained by the US Cybersecurity Agency (CISA) listing CVE vulnerabilities actively exploited in real cyberattacks. US federal organizations are required to remediate them within a mandated deadline.

CVE Find offers a free alert system: create an account, then configure alerts by keyword, by vendor/product (CPE), by CWE category, by CVSS score or based on the CISA KEV list. Notifications are sent by email as soon as a new CVE matches your criteria.