SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 3,932 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 3,932 new IOCs ingested in last 24h
⚡

Vulnerability Intelligence

Comprehensive CVE database enriched with CVSS scores, EPSS exploit probability, CISA KEV status, and ransomware association flags. Prioritize patch management with actionable vulnerability intelligence for security teams and SOC analysts.

Global Database
216,864
1,726 in CISA KEV
High EPSS (≥50%)
4,332
across full database
Ransomware-Linked
361
across full database
EPSS vs CVSS1,500 CVEs
Critical / Ransomware
High
Medium / KEV
Low
600 / 1,500 CVEs
🔍
CVSS ≥
EPSS ≥
CVE IDVendor / ProductCVSSEPSSKEVModifiedDue DateFlags
CVE-2026-100865Heym before 0.0.53 contains multiple independent vulner…8.8——2026-09-27—
CVE-2026-100864heym before 0.0.91 contains a sandbox escape vulnerabil…8.8——2026-09-27—
CVE-2026-100863Heym versions 0.0.90 and earlier contain two server-sid…5.0——2026-09-27—
CVE-2026-100862heym, a workflow automation platform, stores and return…4.9——2026-09-27—
CVE-2026-100861heym before 0.0.105 fails to apply egress guards to int…5.0——2026-09-27—
CVE-2026-100860heym before 0.0.105 does not act on the result of the c…5.5——2026-09-27—
CVE-2026-100859Heym before 0.0.106 contains a credential exfiltration …6.5——2026-09-27—
CVE-2026-100858heym before 0.0.109 contains a server-side request forg…6.8——2026-09-27—
CVE-2026-100857AzuraCast before 0.23.4 contains a code injection vulne…8.0——2026-09-27—
CVE-2026-100856AzuraCast before 0.23.6 contains a code injection vulne…8.8——2026-09-27—
CVE-2026-100855AzuraCast before 0.23.6 contains a missing permission c…6.5——2026-09-27—
CVE-2026-100854AzuraCast before 0.23.6 lacks RequireInternalConnection…6.3——2026-09-27—
CVE-2026-100853In AzuraCast before 0.23.8, the public On-Demand downlo…5.9——2026-09-27—
CVE-2026-100852AzuraCast through 0.23.x contains a command injection v…8.8——2026-09-27—
CVE-2026-100851AzuraCast before 0.23.8 contains a broken access contro…7.6——2026-09-27—
CVE-2026-100850AzuraCast before 0.23.8 contains a server-side request …7.7——2026-09-27—
CVE-2026-100849AzuraCast is a self-hosted web radio management suite. …7.1——2026-09-27—
CVE-2026-100848AzuraCast (Composer package azuracast/azuracast) before…7.1——2026-09-27—
CVE-2026-100847AzuraCast before 0.23.8 contains a DQL injection vulner…7.5——2026-09-27—
CVE-2026-100846MONAI before 1.5.2 contains a deserialization of untrus…7.6——2026-09-27—
CVE-2026-100845MONAI before 1.6.0 contains an unsafe deserialization v…7.8——2026-09-27—
CVE-2026-100844MONAI before 1.6.0 is vulnerable to OS command injectio…8.4——2026-09-27—
CVE-2026-100843MONAI versions before 1.6.0 contain a remote code execu…7.8——2026-09-27—
CVE-2026-100842MONAI through 1.6.0 contains an eval injection vulnerab…7.0——2026-09-27—
CVE-2026-100841In MONAI 1.6.0, PersistentDataset (monai/data/dataset.p…7.8——2026-09-27—
CVE-2026-100840MONAI through 1.6.0 contains a remote code execution vu…7.8——2026-09-27—
CVE-2026-100839Contrast is a confidential-computing runtime for Kubern…8.4——2026-09-27—
CVE-2026-100838Contrast is a confidential-computing runtime for Kubern…8.1——2026-09-27—
CVE-2026-100837Contrast (Edgeless Systems) through 1.20.0 performs una…3.7——2026-09-27—
CVE-2026-100836Contrast through 1.20.0 contains a panic vulnerability …4.3——2026-09-27—
Page 1 / 7,229216,864 Records globally