Skip to content
CORVASEC CORVASEC
Sign In Join Now
CORVASEC INTELLIGENCE ENGINE

Vulnerability Explorer

Search synchronized vulnerability intelligence, CVE records, CISA Known Exploited Vulnerabilities, and MITRE ATT&CK techniques. Investigate affected products, severity, exploitation activity, and adversary behavior from one centralized intelligence workspace.

▤
Vulnerability records3,039Total synchronized records
⬡
Critical severity136CVEs with critical severity
⚑
CISA KEV flagged1,730Known exploited vulnerabilities
♧
MITRE ATT&CK mapped697Imported ATT&CK techniques
▤

Vulnerability Intelligence Directory

Explore and search through 3,039 vulnerability records.

1–12 of 3,039 records
!CVE-2026-54645MEDIUM 4.8

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only scri...

▢  Published Sep 17, 2026 ↻  Updated Sep 22, 2026
View details  →
!CVE-2026-54633MEDIUM 6.9

PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine in s...

▢  Published Sep 17, 2026 ↻  Updated Sep 22, 2026
View details  →
!CVE-2026-54613MEDIUM 5.4

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme pa...

▢  Published Sep 17, 2026 ↻  Updated Sep 22, 2026
View details  →

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, dele...

▢  Published Sep 17, 2026 ↻  Updated Sep 22, 2026
View details  →

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. Thi...

▢  Published Sep 17, 2026 ↻  Updated Sep 22, 2026
View details  →

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted thro...

▢  Published Sep 17, 2026 ↻  Updated Sep 22, 2026
View details  →
!CVE-2026-94493CRITICAL 9.3

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentica...

▢  Published Sep 22, 2026 ↻  Updated Sep 22, 2026
View details  →

A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument ope...

▢  Published Sep 22, 2026 ↻  Updated Sep 22, 2026
View details  →
!CVE-2026-94491MEDIUM 5.5

A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch...

▢  Published Sep 22, 2026 ↻  Updated Sep 22, 2026
View details  →

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative...

▢  Published Sep 22, 2026 ↻  Updated Sep 22, 2026
View details  →

Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore re...

▢  Published Sep 22, 2026 ↻  Updated Sep 22, 2026
View details  →

Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A hook that dies fires core.app.hook_exception, then calls cle...

▢  Published Sep 22, 2026 ↻  Updated Sep 22, 2026
View details  →

Catalog counts represent locally imported records and depend on the most recent successful synchronization.