Every CVE of the last six months, updated daily.
Published vulnerabilities straight from the National Vulnerability Database, with severity, CWE class and affected products. Search it, filter it, and see what landed today.
- 454 published in the last 24 hours
- 2,409 in the last 7 days
- 58,761 in the last six months
Source: NVD (National Vulnerability Database) · Updated Sep 24, 2026
Showing 3 of 3
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assum
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representation
CWE-27splunk splunkThe security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache K
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.