New MCP server — Bring vulnerability intelligence into your AI
Live vulnerability intelligence

Vulnerability Intelligence Center

Track, prioritise and act on the vulnerabilities that actually threaten your external attack surface — CVEs, exploits, EPSS, CISA KEV and trending attacks, unified in one continuously updated feed.

Try , or .

Live feed

0 CVE available

Streaming live from the Patrowl Intelligence API.

CVE-2026-17528
today

Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.

4.7
CVE-2026-17524
today

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.

6.4
CVE-2026-65442
today

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

5.6
CVE-2026-65438
today

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

5.5
CVE-2026-65439
today

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

5.5
CVE-2026-66473
today

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

5.7
CVE-2026-65447
today

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

5.5
CVE-2026-65440
today

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

5.5
CVE-2026-65448
today

Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

5.3
CVE-2026-65446
today

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

5.5

Discover

Map your entire external attack surface automatically — domains, IPs, services and shadow IT.

Detect

Continuously match exposures against new CVEs, public exploits and CISA KEV entries.

Remediate

Prioritise with the Patrowl EASM risk score and act on what truly matters first.

Monitor

Stay ahead with real-time alerts the moment a threat starts trending.

The platform

Continuously protect what you expose on the Internet

Patrowl turns raw vulnerability data into prioritised, actionable intelligence — so your team spends time fixing what attackers will actually use.

0M

Assets monitored

0M

Vulnerabilities analysed

0x

Faster remediation

Built for Claude · Open source

Turn Claude into a vulnerability analyst

patrowl-cve-analyst pulls correlated CVE, CVSS, EPSS, CISA KEV, public-exploit and trending-attack data from Patrowl Intelligence — and produces decision-grade risk briefs in seconds.

  • One prompt, full picture — CVSS, EPSS, KEV, public exploits and trending attacks correlated in a single call.
  • Decision-grade output. A risk verdict and remediation window, not raw JSON to parse.
  • Works in Claude Code, Claude Desktop or any Claude app — drop the skill in and prompt.
~/patrowl-cve-analyst
$ claude
> Use the patrowl-cve-analyst skill —
  brief me on CVE-2025-41115

┌─ Patrowl risk brief ───────────────────────┐
  EASM score   8.7 / 10   high              
  CVSS v4.0    9.1        v3.1   8.7      
  EPSS         12.4%      KEV    no       
  Public PoCs  2          Remote yes      
                                            
  Verdict Patch within 7 days. Trending     
          exploitation observed in the wild. 
└────────────────────────────────────────────┘

More than 100 companies trust us

European Investment BankMGEN SolutionForvis MazarsColasHeetchXplorEuropean Investment BankMGEN SolutionForvis MazarsColasHeetchXplor

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot