Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | Severity | Vendor / product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-7531 | 9.8 | critical | wolfssl / wolfssl | Use-after-free in PQC hybrid key-share handling. | 72d ago |
| CVE-2026-4395 | 9.8 | critical | wolfssl / wolfssl | Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remo | 170d ago |
| CVE-2026-3849 | 9.8 | critical | wolfssl / wolfssl | Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. | 170d ago |
| CVE-2026-3549 | 9.8 | critical | wolfssl / wolfssl | Heap Overflow in TLS 1.3 ECH parsing. | 170d ago |
| CVE-2026-3548 | 9.8 | critical | wolfssl / wolfssl | Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer | 170d ago |
| CVE-2026-6094 | 9.1 | critical | wolfssl / wolfssl | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. | 72d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE) and CISA Known Exploited Vulnerabilities catalog (exploitation status). Both are United States government works in the public domain. Data refreshes daily; KEV hourly.