Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-75529 Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpo... | UNKNOWN | ????? | ????? | NVD | 3 days ago |
| CVE-2026-68765 hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-40506 OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without ... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75483 powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject... | LOW | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75482 SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory director... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75481 SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75480 OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users t... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75479 JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enu... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75111 Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arb... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75110 MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, de... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75109 Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75108 Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe a... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75106 OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attacke... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75105 phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/inde... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75104 Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model di... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-75103 Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71486 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender end... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-68004 An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-l... | UNKNOWN | ????? | ????? | NVD | 3 days ago |
| CVE-2026-67678 File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-68005 An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_requ... | HIGH | ????? | ????? | NVD | 3 days ago |