Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-59940 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allo... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-63632 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-59825 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/co... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-56684 Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pe... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-50187 Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh p... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-45733 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #ico... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-48798 SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trust... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-50138 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-50139 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32553 Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32549 Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32547 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32474 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32481 Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32473 Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32472 Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-32470 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-18534 ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to im... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-63328 Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins with... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-68939 Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacter... | UNKNOWN | ????? | ????? | NVD | 2 days ago |