Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-73053 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outpu... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73052 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the ... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73050 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throug... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73047 siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation featur... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73046 SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73045 SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that all... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73044 SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attribut... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73043 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templ... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73042 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open g... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-73041 SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject mal... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor pa... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-18855 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields f... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19906 A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProf... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19905 A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx.... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19598 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19904 A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=si... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19903 A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19901 A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulat... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19900 A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19899 A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_... | HIGH | ????? | ????? | NVD | 5 days ago |