CVE Find - Vulnerabilities Database

CVE Find is a real-time vulnerability database indexing 350 083 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2173 new CVEs were published in the last 7 days.

Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).

CVE Find
With CVE Find, explore the world's largest database of vulnerabilities.

350 083 vulnerabilities

Last update : 2026-05-13 09h18 +00:00
Common Vulnerabilities and Exposures (CVE), is a list of publicly disclosed computer security flaws.
View CVE 2025
0
Created 7 days ago
0
Updated 7 days ago
0
Created 30 days ago
0
Updated 30 days ago

Free CVE Email Notifications

Get free real-time alerts on new vulnerabilities with CVE Find.
Stay protected and informed instantly !

The last 10 High CVE

Total 350 083 CVE in Datadase
CVE ID Published Description Score Severity

CVE-2026-44547

2026-05-12
23h16 +00:00
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058...
Authorization problems
9.6
Critical

CVE-2026-42289

2026-05-12
23h16 +00:00
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user ...
Improper Privilege ManagementAuthorization problemsCross-Site Request Forgery - CSRF
8.8
High

CVE-2026-42288

2026-05-12
23h16 +00:00
ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is ...
Code Injection
10
Critical

CVE-2026-41901

2026-05-12
23h16 +00:00
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5....
9
Critical

CVE-2026-8449

2026-05-12
22h16 +00:00
Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allow...
Overflow
8.8
High

CVE-2026-45227

2026-05-12
22h16 +00:00
Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that a...
8.8
High

CVE-2026-44262

2026-05-12
22h16 +00:00
Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when docume...
Code Injection
9.4
Critical

CVE-2026-44015

2026-05-12
22h16 +00:00
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated us...
Server-Side Request Forgery - SSRF
8.5
High

CVE-2026-43948

2026-05-12
22h16 +00:00
wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and g...
Authorization problems
9.9
Critical

CVE-2026-42854

2026-05-12
22h16 +00:00
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 ...
9.8
Critical

Distribution by CVSS scores


CVE created per quarter since 1999

Frequently asked questions about CVE Find

CVE Find is a cybersecurity vulnerability search engine that aggregates and indexes CVE (Common Vulnerabilities and Exposures), CWE, CAPEC and CPE data from MITRE, NVD and CISA. It allows you to search, filter and monitor security flaws via configurable real-time alerts.

A CVE (Common Vulnerability and Exposure) is a unique identifier assigned to a publicly disclosed computer security flaw. Each CVE is managed by MITRE Corporation and referenced in the NIST National Vulnerability Database (NVD) with a CVSS score evaluating its severity from 0 to 10.

CVSS (Common Vulnerability Scoring System) is an international standard that evaluates the severity of a vulnerability on a scale of 0 to 10. A score of 9 to 10 is rated Critical, 7 to 8.9 High, 4 to 6.9 Medium, and 0.1 to 3.9 Low.

CISA KEV (Known Exploited Vulnerabilities) is a catalog maintained by the US Cybersecurity Agency (CISA) listing CVE vulnerabilities actively exploited in real cyberattacks. US federal organizations are required to remediate them within a mandated deadline.

CVE Find offers a free alert system: create an account, then configure alerts by keyword, by vendor/product (CPE), by CWE category, by CVSS score or based on the CISA KEV list. Notifications are sent by email as soon as a new CVE matches your criteria.