Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-75926 Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-73073 Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgre... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75914 CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading f... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75915 CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process en... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75913 CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The mode... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75912 CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by in... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75911 CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to en... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75904 libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sam... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75859 CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on t... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75858 CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval too... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75857 CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirem... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75856 CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-u... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-62357 Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75890 Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment. | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-74015 Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-74009 Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-74007 Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-74006 Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-74012 Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection.
This issue affects TaxoPress: from n/a through 3.51.0. | HIGH | ????? | ????? | NVD | 2 days ago |