Logic Encoder

CVE Watch — Exploited & Fresh Critical Vulnerabilities

Updated Sep 15, 2026

Newly exploited and freshly published critical vulnerabilities, updated several times a day from the CISA KEV catalog and the NVD feed. KEV entries are being exploited in the wild — patch those first.

CVE Watch — exploited & fresh critical vulnerabilities
KEV catalog size: 1,710 updated 2026-09-15 08:49:11 UTC
CVESrcCVSSDateAffectedSummary
CVE-2026-76461NVD9.82026-09-14CVE-2026-76461A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an …
CVE-2026-76443NVD9.82026-09-14CVE-2026-76443As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew…
CVE-2026-76441NVD9.82026-09-14CVE-2026-76441As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew…
CVE-2026-76440NVD9.82026-09-14CVE-2026-76440As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew…
CVE-2026-61701NVD8.82026-09-14CVE-2026-61701Laravel MagicLink creates links for authentication without a password or for accessing private content. From …
CVE-2026-55416NVD8.82026-09-14CVE-2026-55416Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an …
CVE-2026-55072NVD8.52026-09-14CVE-2026-55072Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user wit…
CVE-2026-54155NVD7.72026-09-14CVE-2026-54155node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToke…
CVE-2026-20353NVD9.82026-09-14CVE-2026-20353As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatew…
CVE-2026-47701NVD7.72026-09-14CVE-2026-47701The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/ot…
CVE-2026-82438NVD8.12026-09-14CVE-2026-82438DescriptionThree separate mechanisms allowed a web page on an unrelated origin to read responses that Storm…
CVE-2026-82432NVD8.12026-09-14CVE-2026-82432DescriptionNimbus validated `topology.blobstore.map` against the calling subject at submission time only. T…
CVE-2026-82435NVD9.82026-09-14CVE-2026-82435DescriptionThe worker's Netty message decoder is installed ahead of the SASL authentication handlers in the…
CVE-2026-82431NVD9.82026-09-14CVE-2026-82431Description`SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users…
CVE-2026-82430NVD7.82026-09-14CVE-2026-82430DescriptionWhen launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership…
CVE-2026-82429NVD7.82026-09-14CVE-2026-82429DescriptionThe setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories…
CVE-2026-82427NVD7.82026-09-14CVE-2026-82427DescriptionA topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that …
CVE-2026-82428NVD8.82026-09-14CVE-2026-82428DescriptionDependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived …
CVE-2026-59569NVD8.12026-09-14CVE-2026-59569An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an atta…
CVE-2026-82441NVD9.12026-09-14CVE-2026-82441DescriptionA submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_arti…
CVE-2026-82439NVD9.82026-09-14CVE-2026-82439DescriptionThe DRPC server kept a map from function name to request queue and created an entry the first ti…
CVE-2026-73370NVD9.82026-09-14CVE-2026-73370Incorrect Authorization vulnerability in Apache Syncope.Delegated administration security checks performe…
CVE-2026-73236NVD7.52026-09-14CVE-2026-73236Incorrect Authorization vulnerability in Apache Syncope.Delegated administration security checks are base…
CVE-2026-90938NVD8.62026-09-14CVE-2026-90938LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0…
CVE-2026-90937NVD9.92026-09-14CVE-2026-90937froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authen…
CVE-2026-78336NVD7.52026-09-14CVE-2026-78336Insertion of sensitive information into sent data vulnerability in Apache Syncope.Any authenticated user …
CVE-2026-78330NVD9.82026-09-14CVE-2026-78330Incorrect privilege assignment vulnerability in Apache Syncope.When the configured JWKS settings for intern…
CVE-2026-77181NVD9.82026-09-14CVE-2026-77181Incorrect Authorization vulnerability in Apache Syncope.An administrator with ClientApp's update entitlem…
CVE-2026-77051NVD9.82026-09-14CVE-2026-77051Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache …
CVE-2026-73178NVD7.52026-09-14CVE-2026-73178Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope.An administrator…
CVE-2026-75030NVD9.82026-09-14CVE-2026-75030Missing Authorization vulnerability in Apache Syncope.An administrator with task execution entitlements m…
CVE-2026-73668NVD9.82026-09-14CVE-2026-73668Incorrect Authorization vulnerability in Apache Syncope.An administrator with adequate entitlements in …
CVE-2026-73579NVD9.82026-09-14CVE-2026-73579Incorrect Authorization vulnerability in Apache Syncope.Any search requests are transformed into SQL, Neo…
CVE-2026-73470NVD9.82026-09-14CVE-2026-73470Improper Privilege Management vulnerability in Apache Syncope.Delegations can be created or updated wit…
CVE-2026-87779NVD7.52026-09-14CVE-2026-87779Insertion of sensitive information into log file vulnerability in Apache Syncope.When AES key of non-stan…
CVE-2026-87802NVD9.12026-09-14CVE-2026-87802Improper verification of cryptographic signature vulnerability in Apache Syncope.When SRA is configured f…
CVE-2026-87785NVD9.12026-09-14CVE-2026-87785Authentication bypass by spoofing vulnerability in Apache Syncope.When the configured JWKS settings for i…
CVE-2026-86460NVD9.82026-09-14CVE-2026-86460Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.…
CVE-2026-82232NVD9.82026-09-14CVE-2026-82232Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache …
CVE-2026-72524NVD8.82026-09-14CVE-2026-72524Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks…
CVE-2026-68955NVD7.82026-09-14CVE-2026-68955The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries.…
CVE-2023-50462NVD5.32026-09-14CVE-2023-50462An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fa…
CVE-2023-46035NVD5.92026-09-14CVE-2023-46035The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
CVE-2023-32803NVD7.52026-09-14CVE-2023-32803The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly re…
CVE-2026-33964NVD6.42026-09-14CVE-2026-33964An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dere…
CVE-2026-33963NVD7.52026-09-14CVE-2026-33963An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600…
CVE-2026-31278NVD7.72026-09-14CVE-2026-31278An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X…
CVE-2026-23789NVD7.82026-09-14CVE-2026-23789An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 128…
CVE-2025-63842NVD5.42026-09-14CVE-2025-63842A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allow…
CVE-2024-53922NVD5.72026-09-14CVE-2024-53922An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, …
CVE-2026-76461KEV2026-09-14Cisco Secure Email GatewayCisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could…
CVE-2026-90600NVD6.32026-09-13CVE-2026-90600A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown functi…
CVE-2026-90597NVD6.32026-09-13CVE-2026-90597A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected eleme…
CVE-2026-89050NVD4.32026-09-13CVE-2026-89050The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion wit…
CVE-2026-88802NVD7.52026-09-13CVE-2026-88802The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin thro…
CVE-2026-88793NVD8.82026-09-13CVE-2026-88793The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its A…
CVE-2026-85129NVD8.82026-09-13CVE-2026-85129The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its i…
CVE-2026-36989NVD5.82026-09-13CVE-2026-36989A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.
CVE-2026-37008NVD8.12026-09-13CVE-2026-37008CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a d…
CVE-2026-74933NVD8.82026-09-13CVE-2026-74933The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST …
CVE-2026-81648NVD10.02026-09-13CVE-2026-81648The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one o…
CVE-2026-90583NVD4.32026-09-13CVE-2026-90583A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. Th…
CVE-2026-90581NVD6.32026-09-13CVE-2026-90581A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainControl…
CVE-2026-90580NVD6.32026-09-13CVE-2026-90580A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.pos…
CVE-2026-29811NVD7.72026-09-13CVE-2026-29811CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same cont…
CVE-2020-15875NVD5.02026-09-13CVE-2020-15875An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract …
CVE-2026-90574NVD6.32026-09-13CVE-2026-90574A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown f…
CVE-2026-90565NVD5.32026-09-13CVE-2026-90565A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9e…
CVE-2026-90566NVD7.32026-09-13CVE-2026-90566A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c7…
CVE-2026-90525NVD6.32026-09-13CVE-2026-90525A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown functi…
CVE-2026-90526NVD7.32026-09-13CVE-2026-90526A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This imp…
CVE-2026-90783NVD7.82026-09-13CVE-2026-90783MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex pars…
CVE-2026-90519NVD6.32026-09-13CVE-2026-90519A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown functi…
CVE-2026-90517NVD5.32026-09-13CVE-2026-90517A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown funct…
CVE-2026-90518NVD6.32026-09-13CVE-2026-90518A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown …
CVE-2026-90775NVD6.52026-09-13CVE-2026-90775PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules …
CVE-2026-90776NVD7.52026-09-13CVE-2026-90776Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addresspars…
CVE-2026-90516NVD7.32026-09-13CVE-2026-90516A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is a…
CVE-2026-90515NVD7.32026-09-13CVE-2026-90515A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element…
CVE-2026-90774NVD7.52026-09-13CVE-2026-90774rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP hea…
CVE-2026-90514NVD7.32026-09-13CVE-2026-90514A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unkno…
CVE-2026-85706KEV2026-09-11GitLab Community Edition and Enterprise EditionGitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauth…
CVE-2026-42018KEV2026-09-11JFrog ArtifactoryJFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-u…
CVE-2026-42016KEV2026-09-11JFrog ArtifactoryJFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation…
CVE-2026-84869KEV2026-09-11ConnectWise ScreenConnectConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerabil…
CVE-2026-67277KEV2026-09-10MikroTik RouterOSMikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel me…
CVE-2026-86060KEV2026-09-10MikroTik RouterOSMikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which…
CVE-2026-20079KEV2026-09-09Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Manage…
CVE-2026-87491KEV2026-09-09Google Chromium V8Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arb…
CVE-2025-25249KEV2026-09-09Fortinet Multiple ProductsFortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that a…
CVE-2026-19490KEV2026-09-09Citrix NetScalerCitrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an altern…
CVE-2026-85880KEV2026-09-08Microsoft WindowsMicrosoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allo…
CVE-2026-86218KEV2026-09-08N-able N-centralN-able N-central contains a static code injection vulnerability that could allow for pre-authentication remot…
CVE-2026-81963KEV2026-09-08Microsoft WindowsMicrosoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escala…
CVE-2026-75650KEV2026-09-08Adobe Commerce and MagentoAdobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a templ…
CVE-2026-85046KEV2026-09-04Google Chromium V8Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary…
CVE-2026-83549KEV2026-09-02SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authen…
CVE-2026-83548KEV2026-09-02SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote u…
CVE-2026-9586KEV2026-09-02Sangoma SwitchvoxSangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to e…
CVE-2026-82329KEV2026-09-02JFrog ArtifactoryJFrog Artifactory contains an improper authentication vulnerability that under default configuration can allo…
CVE-2026-49869KEV2026-09-02Kestra Kestra OSSKestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker…
CVE-2026-48710KEV2026-09-02Kludex StarletteKludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to injec…
CVE-2026-59822KEV2026-09-02BerriAI LiteLLMBerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that co…
CVE-2026-81578KEV2026-08-31PaperCut NG/MFPaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthen…
CVE-2026-82078KEV2026-08-31PaperCut NG/MFPaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system confi…
CVE-2026-66384KEV2026-08-27JFrog ArtifactoryJFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This…
CVE-2026-53362KEV2026-08-27Linux KernelLinux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networkin…
CVE-2023-49105KEV2026-08-27ownCloud ownCloudownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or dele…
CVE-2019-1068KEV2026-08-26Microsoft SQL ServerMicrosoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute c…
CVE-2026-8452KEV2026-08-26Citrix NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of…
CVE-2022-0995KEV2026-08-26Linux KernelLinux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain priv…
CVE-2015-5287KEV2026-08-26Red Hat Automatic Bug Reporting ToolRed Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow lo…
CVE-2015-3246KEV2026-08-26Red Hat LibuserRed Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the …
CVE-2021-23758KEV2026-08-26Ajax.NET Professional Ajax.NET ProfessionalAjax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow f…
CVE-2026-60004KEV2026-08-25Gitea GiteaGitea contains a code injection vulnerability that allows an attacker with repository write access to send a …
CVE-2026-21962KEV2026-08-24Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inOracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability …
CVE-2026-73570KEV2026-08-21Synacor Zimbra Collaboration Suite (ZCS)Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthen…
CVE-2026-72529KEV2026-08-20TrueConf ServerTrueConf Server contains a missing authentication for critical function vulnerability which could allow a rem…
CVE-2026-72530KEV2026-08-20TrueConf ServerTrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with…
CVE-2026-64849KEV2026-08-19MLflow MLflowMLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or clo…
CVE-2026-65400KEV2026-08-18Apple macOSApple macOS contains an improper authentication vulnerability that could allow an attacker on the network to …
CVE-2026-55040KEV2026-08-18Microsoft SharePointMicrosoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to by…
CVE-2026-59310KEV2026-08-18Broadcom VMware vCenterBroadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network…
CVE-2026-33824KEV2026-08-18Microsoft Internet Key Exchange (IKE) Service ExtensionsMicrosoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enab…
CVE-2025-62593KEV2026-08-17Ray-Project RayRay-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers us…
CVE-2026-72898KEV2026-08-11Metabase MetabaseMetabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbi…
CVE-2026-68820KEV2026-08-11Microsoft Windows Ancillary Function Driver for WinSockMicrosoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows a…
CVE-2026-20349KEV2026-08-11Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a he…
CVE-2026-8037KEV2026-08-07Progress LoadMasterProgress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to ex…
CVE-2026-63077KEV2026-08-05JetBrains TeamCityJetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticate…
CVE-2026-9198KEV2026-08-04IBM LangflowLangflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote…
CVE-2026-34486KEV2026-08-04Apache TomcatApache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the Enc…
CVE-2026-18556KEV2026-08-04N-able N-centralN-able N-central contains an authentication bypass using an alternate path or channel that allows for authent…
CVE-2026-18577KEV2026-08-03N-able N-centralN-able N-central contains an authentication bypass using an alternate path or channel allows for authenticati…
CVE-2026-20316KEV2026-07-29Cisco Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of…
CVE-2026-16812KEV2026-07-27Arista VeloCloud OrchestratorArista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote …
CVE-2025-68686KEV2026-07-27Fortinet FortiOSFortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This m…
CVE-2026-50522KEV2026-07-22Microsoft SharePointMicrosoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthor…
CVE-2026-16232KEV2026-07-22Check Point SmartConsoleCheck Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticat…
CVE-2026-60137KEV2026-07-21WordPress CoreWordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the pa…
1 / 1

KEV = CISA Known Exploited Vulnerabilities (actively exploited in the wild — patch first). NVD = newly published CVEs relevant to common server/dev stacks, sorted by CVSS. Data updates several times a day from public feeds.

Sources: CISA Known Exploited Vulnerabilities catalog + NVD CVE feed, filtered to software stacks worth watching. Click a column header to sort; use the filter buttons to isolate KEV entries.