🔥 Top Trending S1 CVEsCritical Priority
Actively exploited vulnerabilities trending in threat feeds
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
A critical path traversal vulnerability exists in the GitLab repository commits API. The flaw is caused by improper path confinement and a lack of authentication enforcement, which allows unauthenticated attackers to read arbitrary files from the affected server under certain conditions.
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Latest Emerging CVEs
Real-time vulnerability intelligence from multiple sources
Log in to view the latest CVEs
Access real-time vulnerability intelligence and prioritized risk scoring
Recently Updated CVEs
Vulnerabilities with recent updates or new threat intelligence
Log in to view the latest CVEs
Access real-time vulnerability intelligence and prioritized risk scoring
How It Works
From raw data feeds to actionable intelligence in seconds
Why Security Teams Choose CVEScope
Consolidated intelligence from trusted sources, delivered in a format that accelerates your response.
Emerging Detection
Detect new CVE IDs shortly after first public mention across 100+ monitored sources (including NVD, CIRCL, vendor advisories, and curated RSS feeds).
Exploit Awareness
Flag CVEs listed in CISA's Known Exploited Vulnerabilities (KEV) catalogue to highlight known exploited risk.
Operational Severity
An environment-agnostic severity rating that blends CVSS impact, EPSS likelihood, trend momentum, and KEV status to indicate urgency.
References & Freshness
See attributable reference links and 'first seen / last seen' timestamps. Some inputs are grouped as aggregated signals.
Auto Normalisation
Deduplicates and correlates CVEs across overlapping sources so each issue appears once.
Integration Access
Programmatic access is available for approved workflows (bulk CSV export isn't enabled by default).