New MCP server — Bring vulnerability intelligence into your AI
Live vulnerability intelligence

Vulnerability Intelligence Center

Track, prioritise and act on the vulnerabilities that actually threaten your external attack surface — CVEs, exploits, EPSS, CISA KEV and trending attacks, unified in one continuously updated feed.

Try , or .

Live feed

0 CVE available

Streaming live from the Patrowl Intelligence API.

CVE-2026-77115
yesterday

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

0.0
CVE-2026-14853
yesterday

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.

0.0
CVE-2026-77003
yesterday

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.

0.0
CVE-2026-77116
yesterday

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.

0.0
CVE-2026-13598
yesterday

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

0.0
CVE-2026-78062
yesterday

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

4.8
CVE-2026-78063
yesterday

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

3.1
CVE-2026-78060
yesterday

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

3.1
CVE-2026-78061
yesterday

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.

4.7
CVE-2026-78059
yesterday

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

3.1

Discover

Map your entire external attack surface automatically — domains, IPs, services and shadow IT.

Detect

Continuously match exposures against new CVEs, public exploits and CISA KEV entries.

Remediate

Prioritise with the Patrowl EASM risk score and act on what truly matters first.

Monitor

Stay ahead with real-time alerts the moment a threat starts trending.

The platform

Continuously protect what you expose on the Internet

Patrowl turns raw vulnerability data into prioritised, actionable intelligence — so your team spends time fixing what attackers will actually use.

0M

Assets monitored

0M

Vulnerabilities analysed

0x

Faster remediation

Built for Claude · Open source

Turn Claude into a vulnerability analyst

patrowl-cve-analyst pulls correlated CVE, CVSS, EPSS, CISA KEV, public-exploit and trending-attack data from Patrowl Intelligence — and produces decision-grade risk briefs in seconds.

  • One prompt, full picture — CVSS, EPSS, KEV, public exploits and trending attacks correlated in a single call.
  • Decision-grade output. A risk verdict and remediation window, not raw JSON to parse.
  • Works in Claude Code, Claude Desktop or any Claude app — drop the skill in and prompt.
~/patrowl-cve-analyst
$ claude
> Use the patrowl-cve-analyst skill —
  brief me on CVE-2025-41115

┌─ Patrowl risk brief ───────────────────────┐
  EASM score   8.7 / 10   high              
  CVSS v4.0    9.1        v3.1   8.7      
  EPSS         12.4%      KEV    no       
  Public PoCs  2          Remote yes      
                                            
  Verdict Patch within 7 days. Trending     
          exploitation observed in the wild. 
└────────────────────────────────────────────┘

More than 100 companies trust us

European Investment BankMGEN SolutionForvis MazarsColasHeetchXplorEuropean Investment BankMGEN SolutionForvis MazarsColasHeetchXplor

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot