First AI-powered CVE platform
thanks to artificial intelligence
Describe what you're looking for in natural language. AI identifies the exact product, targets relevant CVEs and monitors your assets 24/7.
Without AI
cpe:2.3:o:fortinet:fortios:7.4.10:*:*:*:*:*:*:*With cveo.tech
Fortinet firewall critical 2024
From one-off lookups to continuous monitoring of your IT assets.
Describe in natural language — AI identifies the product and targets relevant CVEs automatically.
Register your equipment with its version and get relevant CVEs with one click.
Receive an email notification whenever a new critical CVE affects your assets.
CVSS v2, v3.0 and v3.1 scores with detailed attack vector for each vulnerability.
Results cached for 6h for ultra-fast searches without depending on NVD rate limits.
Data directly from the NIST National Vulnerability Database. Reliable and up to date.
CVE-2026-78006 and CVE-2026-78159 (CVSS 9.8): unauthenticated code execution in the WordPress plugin The Events Calendar, through a comment awaiting moderation. Immediate mitigation.
Eleven CVSS 9.1 to 9.9 CVEs across D-Link DIR-823G / DIR-878 / DWR-M921, Totolink A3002MU, Netis NX10 and WAVLINK WN535M. Public exploits, and a web server abandoned in 2005 behind several of them.
CVE-2026-66384, 82329, 42016 and 42018: four JFrog Artifactory vulnerabilities added to CISA KEV between August 27 and September 11, 2026. Three of the four are authentication failures.
Start for free. Upgrade to Pro when you need it.
🎁 7-day Enterprise free trial
Get automatic email alerts, unlimited assets and CSV export. No commitment, cancel anytime.
CVE-2026-12944
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns "validated": true, providing a false security signal.
CVE-2026-90945
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
CVE-2026-76441
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.