Première plateforme CVE augmentée par l'IA
grâce à l'intelligence artificielle
Décrivez ce que vous cherchez en langage naturel. L'IA identifie le produit exact, cible les CVE pertinentes et surveille votre parc 24h/24.
Sans l'IA
cpe:2.3:o:fortinet:fortios:7.4.10:*:*:*:*:*:*:*Avec cveo.tech
Fortinet firewall critique 2024
De la recherche ponctuelle à la surveillance continue de votre parc IT.
Décrivez en langage naturel — l'IA identifie le produit et cible les CVE pertinentes automatiquement.
Enregistrez vos équipements avec leur version et obtenez les CVE les concernant en un clic.
Recevez une notification par email dès qu'une nouvelle CVE critique affecte votre parc.
Scores CVSS v2, v3.0 et v3.1 avec vecteur d'attaque détaillé pour chaque vulnérabilité.
Résultats mis en cache 6h pour des recherches ultrarapides sans dépendre du débit NVD.
Données directement depuis le NIST National Vulnerability Database. Fiables et à jour.
CVE-2026-5430 (10.0) sur WSO2 API Manager : la CISA décrit une traversée de chemin, NVD une confusion d'algorithme JWT. Que faire quand même.
CVE-2026-71362 (Magento, CISA KEV) et le lot Adobe du 22 septembre : 7 CVE sur Campaign Classic 7.4.x dont deux RCE 10.0, AEM Forms JEE 10.0, deux XSS Connect.
CVE-2026-28324 (9.8) : RCE sans authentification sur SolarWinds Observability Self-Hosted, en configuration non par défaut. Vérifier la sienne.
Commencez gratuitement. Passez à Pro quand vous en avez besoin.
🎁 Essai Enterprise 7 jours gratuits
Alertes email automatiques, équipements illimités, export CSV. Aucun engagement, annulation en un clic.
CVE-2026-9209
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.
CVE-2026-14992
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
CVE-2026-14502
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.