Continuously updated from 100+ sources

Unified CVE Intelligence,
Powered by AI

Track emerging, exploited, and high-risk vulnerabilities with CVSS, EPSS, and KEV context — continuously refreshed as new signals are observed.

100+
Data Sources
24/7
Monitoring

🔥 Top Trending S1 CVEsCritical Priority

Actively exploited vulnerabilities trending in threat feeds

Updated just now
CVE-2026-76460

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVSS:10.0
EPSS:0.9%
Sep 16, 2026
Login to view details
CVE-2026-58704

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS:8.0
EPSS:0.2%
Sep 15, 2026
Login to view details
CVE-2026-76461

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

CVSS:9.8
EPSS:2.0%
Sep 14, 2026
Login to view details
CVE-2026-85706

A critical path traversal vulnerability exists in the GitLab repository commits API. The flaw is caused by improper path confinement and a lack of authentication enforcement, which allows unauthenticated attackers to read arbitrary files from the affected server under certain conditions.

CVSS:10.0
EPSS:12.0%
Sep 12, 2026
Login to view details
CVE-2026-87491

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS:8.8
EPSS:1.0%
Sep 9, 2026
Login to view details
CVE-2026-85880

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVSS:7.8
EPSS:0.6%
Sep 8, 2026
Login to view details

Latest Emerging CVEs

Real-time vulnerability intelligence from multiple sources

Log in to view the latest CVEs

Access real-time vulnerability intelligence and prioritized risk scoring

Recently Updated CVEs

Vulnerabilities with recent updates or new threat intelligence

Log in to view the latest CVEs

Access real-time vulnerability intelligence and prioritized risk scoring

How It Works

From raw data feeds to actionable intelligence in seconds

FetchPull from 100+ sources
NormaliseStandardise formats
CorrelateMerge by CVE ID
ScoreCalculate risk
VisualiseDisplay insights

Why Security Teams Choose CVEScope

Consolidated intelligence from trusted sources, delivered in a format that accelerates your response.

Emerging Detection

Detect new CVE IDs shortly after first public mention across 100+ monitored sources (including NVD, CIRCL, vendor advisories, and curated RSS feeds).

Exploit Awareness

Flag CVEs listed in CISA's Known Exploited Vulnerabilities (KEV) catalogue to highlight known exploited risk.

Operational Severity

An environment-agnostic severity rating that blends CVSS impact, EPSS likelihood, trend momentum, and KEV status to indicate urgency.

References & Freshness

See attributable reference links and 'first seen / last seen' timestamps. Some inputs are grouped as aggregated signals.

Auto Normalisation

Deduplicates and correlates CVEs across overlapping sources so each issue appears once.

Integration Access

Programmatic access is available for approved workflows (bulk CSV export isn't enabled by default).

CVEScope

Unified CVE intelligence, refreshed automatically. Track emerging, exploited, and high-risk vulnerabilities with contextual scoring.

All systems operational

© 2026 CVEScope. All rights reserved.

CVEScope is not affiliated with or endorsed by the CVE Program or The MITRE Corporation. CVE is a trademark of The MITRE Corporation.

Legal Information