Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-1199 Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counte... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75778 A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-23922 The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token en... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-75855 ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands,... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75854 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75853 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but perform... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75852 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers ca... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75851 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command w... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75850 ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is ... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75846 ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFun... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75845 ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettin... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75844 ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolv... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75843 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated r... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75842 ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75841 ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server hea... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75840 ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped reg... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75839 ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerability in the Raft cluster-inf... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75838 DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached... | UNKNOWN | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75837 Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75836 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement ... | HIGH | ????? | ????? | NVD | 3 days ago |