Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 20 hours ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 20 hours ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 4 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 7 days ago |
| CVE-2026-14494 The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submis... | CRITICAL | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-82449 Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verificatio... | MEDIUM | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-82448 Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrar... | CRITICAL | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-82447 Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environme... | HIGH | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-82364 A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-80725 In the Linux kernel, the following vulnerability has been resolved:
net: gro: properly validate BIG TCP aggregation criteria
When GRO attempts to ag... | UNKNOWN | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-81346 The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenti... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-81342 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before u... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-81200 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with t... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-81026 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notificatio... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-80488 The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL state... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-80311 The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the reques... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-77786 The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself ... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-77704 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before lettin... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-77012 The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-77010 The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-77008 The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when sav... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-77007 The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API ... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-76586 The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the serv... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-76548 The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitor... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |