Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-75835 Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75834 Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). A... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75833 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakn... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75832 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerab... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75831 Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement meth... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75830 grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController:... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75829 grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission t... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75828 Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75827 Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denyl... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75107 Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option lab... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74908 Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', a... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74907 Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of dir... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74906 SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vis... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74905 SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDi... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74904 SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockEx... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74903 SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which is guarded only by CheckAuth ... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-74902 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-19447 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade I... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-19608 A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. Th... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75774 A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts ... | LOW | ????? | ????? | NVD | 3 days ago |