Synchronization Manager

Orchestrate incremental ingests of NVD data. Define your paging windows, retry thresholds, and throttling limits.

Ingestion Strategy Configurations

Days in each request window (1-7).

Number of chunk intervals to fetch back (1-10).

NVD date range parameter to filter query.

Maximum items returned per API request.

Number of retries per chunk if NIST fails.

Wait time before triggering the next retry.

Delay before another API ingest/page (min 1s).

Last successful sync: 2026-07-20T19:41:50.114Z

Ingestion History Logs

2026-07-20T19:41:50.114Z Success

Completed NVD sync (3 chunks of 1 days using published dates). Total records: 846.

Weeks: 1Records Ingested: 846
2026-07-18T15:05:06.986Z Success

Completed NVD sync (2 chunks of 1 days using published dates). Total records: 511.

Weeks: 1Records Ingested: 511
2026-07-17T14:35:03.648Z Success

Completed NVD sync (4 chunks of 1 days using published dates). Total records: 1752.

Weeks: 1Records Ingested: 1752
2026-07-14T17:38:03.949Z Success

Completed NVD sync (1 chunks of 1 days using published dates). Total records: 449.

Weeks: 1Records Ingested: 449
2026-07-13T18:21:12.744Z Success

Completed NVD sync (1 chunks of 1 days using published dates). Total records: 270.

Weeks: 1Records Ingested: 270
2026-07-12T23:47:09.721Z Success

Completed NVD sync (1 chunks of 1 days using published dates). Total records: 61.

Weeks: 1Records Ingested: 61
2026-07-12T18:05:02.756Z Success

Completed NVD sync (5 chunks of 1 days using published dates). Total records: 1215.

Weeks: 1Records Ingested: 1215
2026-07-11T19:57:33.551Z Failed

Interval sync failed at chunk 1. can't access property "recordsFetched", r is undefined

Weeks: 30Records Ingested: 9826
2026-07-11T18:24:10.351Z Failed

Interval sync failed at chunk 1. Cannot read properties of undefined (reading 'recordsFetched')

Weeks: 43Records Ingested: 2666
2026-07-11T18:15:37.491Z Failed

Interval sync failed at chunk 1. Cannot read properties of undefined (reading 'recordsFetched')

Weeks: 43Records Ingested: 900
2026-07-11T18:12:45.800Z Failed

Interval sync failed at chunk 1. Failed query: insert into "cves" ("id", "description", "published_at", "last_modified_at", "score", "severity", "vendors", "products", "affected_versions", "links", "solution") values (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) on conflict ("cves"."id") do update set "description" = ?, "last_modified_at" = ?, "score" = ?, "severity" = ?, "vendors" = ?, "products" = ?, "affected_versions" = ?, "links" = ?, "solution" = coalesce(nullif(cves.solution, ''), ?) params: CVE-2026-6101,The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. This makes it possible for authenticated attackers, with Author-level access and above, and permissions granted by an Administrator, to write arbitrary files to the server in a web-accessible location, potentially leading to remote code execution on hosts that execute PHP files in the uploads directory.,2026-07-07T14:16:34.543,2026-07-07T15:16:49.807,7.5,HIGH,[],[],[],["https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/accelerated-moblie-pages.php#L1616","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/admin-config.php#L1700","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/redux-core/core/panel.php#L175","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/redux-core/framework.php#L2832","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/accelerated-moblie-pages.php#L1616","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/admin-config.php#L1700","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/redux-core/core/panel.php#L175","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/redux-core/framework.php#L2832","https://plugins.trac.wordpress.org/changeset/3512870/","https://www.wordfence.com/threat-intel/vulnerabilities/id/b594d0e9-d805-48b9-bfd4-4cc77dd3a70e?source=cve"],Update the affected packages to a secure version. Refer to vendor security advisories.,The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. This makes it possible for authenticated attackers, with Author-level access and above, and permissions granted by an Administrator, to write arbitrary files to the server in a web-accessible location, potentially leading to remote code execution on hosts that execute PHP files in the uploads directory.,2026-07-07T15:16:49.807,7.5,HIGH,[],[],[],["https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/accelerated-moblie-pages.php#L1616","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/admin-config.php#L1700","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/redux-core/core/panel.php#L175","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/tags/1.1.12/includes/options/redux-core/framework.php#L2832","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/accelerated-moblie-pages.php#L1616","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/admin-config.php#L1700","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/redux-core/core/panel.php#L175","https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/includes/options/redux-core/framework.php#L2832","https://plugins.trac.wordpress.org/changeset/3512870/","https://www.wordfence.com/threat-intel/vulnerabilities/id/b594d0e9-d805-48b9-bfd4-4cc77dd3a70e?source=cve"],Update the affected packages to a secure version. Refer to vendor security advisories.

Weeks: 43Records Ingested: 0
2026-07-11T17:09:30.886Z Success

Completed NVD sync (5 chunks of 1 days using published dates). Total records: 1341.

Weeks: 1Records Ingested: 1341
2026-07-11T17:05:50.751Z Failed

Interval sync failed at chunk 1. NetworkError when attempting to fetch resource.

Weeks: 1Records Ingested: 792
2026-07-11T17:01:22.102Z Failed

Interval sync failed at chunk 1. Failed query: insert into "cves" ("id", "description", "published_at", "last_modified_at", "score", "severity", "vendors", "products", "affected_versions", "links", "solution") values (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) on conflict ("cves"."id") do update set "description" = ?, "last_modified_at" = ?, "score" = ?, "severity" = ?, "vendors" = ?, "products" = ?, "affected_versions" = ?, "links" = ?, "solution" = coalesce(nullif(cves.solution, ''), ?) params: CVE-2026-42147,Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endpoint, allowing an authenticated user with storage management permissions to make Coolify request internal or metadata-service URLs. This issue is fixed in version 4.0.0-beta.474.,2026-07-07T04:17:51.760,2026-07-07T15:16:46.573,4.9,MEDIUM,[],[],[],["https://github.com/coollabsio/coolify/commit/297e9c41e19958f6237919794c28c3fb1d4cda32","https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474","https://github.com/coollabsio/coolify/security/advisories/GHSA-pwm4-w33c-wjf3","https://github.com/coollabsio/coolify/security/advisories/GHSA-pwm4-w33c-wjf3"],Update the affected packages to a secure version. Refer to vendor security advisories.,Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endpoint, allowing an authenticated user with storage management permissions to make Coolify request internal or metadata-service URLs. This issue is fixed in version 4.0.0-beta.474.,2026-07-07T15:16:46.573,4.9,MEDIUM,[],[],[],["https://github.com/coollabsio/coolify/commit/297e9c41e19958f6237919794c28c3fb1d4cda32","https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474","https://github.com/coollabsio/coolify/security/advisories/GHSA-pwm4-w33c-wjf3","https://github.com/coollabsio/coolify/security/advisories/GHSA-pwm4-w33c-wjf3"],Update the affected packages to a secure version. Refer to vendor security advisories.

Weeks: 43Records Ingested: 0