Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-49292Low· 0.0Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…
CVE-2026-55630Low· 0.0Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Officia…
CVE-2026-54724Medium· 6.1Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redire…
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-33977High· 8.1PoCkiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
CVE-2023-30544None· 0.0kiwi TCMS has possibility for user to update email address to unverified one
CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
CVE-2023-25156High· 7.5No protection against brute-force attacks on login page
CVE-2022-4105Medium· 5.4Cross-site Scripting in kiwitcms
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.