New MCP server — Bring vulnerability intelligence into your AI
Live vulnerability intelligence

Vulnerability Intelligence Center

Track, prioritise and act on the vulnerabilities that actually threaten your external attack surface — CVEs, exploits, EPSS, CISA KEV and trending attacks, unified in one continuously updated feed.

Try , or .

Live feed

0 CVE available

Streaming live from the Patrowl Intelligence API.

CVE-2026-101003
today

A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b4232b9cfd4c16869e71. Upgrading the affected component is advised.

4.8
CVE-2026-101004
today

A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 - 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 - 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.

5.5
CVE-2026-101002
today

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

6.3
CVE-2026-100907
today

A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used.

4.8
CVE-2026-100909
today

A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded.

4.8
CVE-2026-87723
today

In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user running the fuse-archive process. The issue was partially mitigated in version 1.22 and fully resolved in 1.24 via refined selective PATH filtering.

2.7
CVE-2026-101000
today

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

6.7
CVE-2026-101001
today

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

6.7
CVE-2026-100908
today

A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

5.8
CVE-2026-100903
today

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

4.8

Discover

Map your entire external attack surface automatically — domains, IPs, services and shadow IT.

Detect

Continuously match exposures against new CVEs, public exploits and CISA KEV entries.

Remediate

Prioritise with the Patrowl EASM risk score and act on what truly matters first.

Monitor

Stay ahead with real-time alerts the moment a threat starts trending.

The platform

Continuously protect what you expose on the Internet

Patrowl turns raw vulnerability data into prioritised, actionable intelligence — so your team spends time fixing what attackers will actually use.

0M

Assets monitored

0M

Vulnerabilities analysed

0x

Faster remediation

Built for Claude · Open source

Turn Claude into a vulnerability analyst

patrowl-cve-analyst pulls correlated CVE, CVSS, EPSS, CISA KEV, public-exploit and trending-attack data from Patrowl Intelligence — and produces decision-grade risk briefs in seconds.

  • One prompt, full picture — CVSS, EPSS, KEV, public exploits and trending attacks correlated in a single call.
  • Decision-grade output. A risk verdict and remediation window, not raw JSON to parse.
  • Works in Claude Code, Claude Desktop or any Claude app — drop the skill in and prompt.
~/patrowl-cve-analyst
$ claude
> Use the patrowl-cve-analyst skill —
  brief me on CVE-2025-41115

┌─ Patrowl risk brief ───────────────────────┐
│  EASM score   8.7 / 10   high              │
│  CVSS v4.0    9.1        v3.1   8.7      │
│  EPSS         12.4%      KEV    no       │
│  Public PoCs  2          Remote yes      │
│                                            │
│  Verdict Patch within 7 days. Trending     │
│          exploitation observed in the wild. │
└────────────────────────────────────────────┘

More than 100 companies trust us

European Investment BankMGEN SolutionForvis MazarsColasHeetchXplorEuropean Investment BankMGEN SolutionForvis MazarsColasHeetchXplor

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot