cisa-kev
CISA KEVExtracts: CVE id, vendor, due date · metadata or bounded excerpt
Retention: D1 event history with canonical source link and deduplication metadata.
Access basis: Public endpoint; no project credential required.
Last ingested: 2026-08-26 · run status: success with data
CVE: CVE-2021-27137 Vendor/project: DD-WRT Product: DD-WRT Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-121 DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP
CVE: CVE-2026-0770 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-829 Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary cod
CVE: CVE-2026-63030 Vendor/project: WordPress Product: Core Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-436 WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Exec
CVE: CVE-2026-60137 Vendor/project: WordPress Product: Core Known ransomware campaign use: Unknown Due date: 2026-08-04 CWE: CWE-89 WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chai