Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-74890 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verificat... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74889 openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and ... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74888 openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KD... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74887 openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/m... | NONE | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74886 openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74885 openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero re... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74884 openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitize... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74883 openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access method... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74882 openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProx... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74881 openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create ma... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74880 openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract to... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74879 openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception stri... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74878 openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on s... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74877 openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated client... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74876 openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without veri... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74875 openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata t... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74874 openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorando... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74873 openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Atta... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74872 openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patt... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74871 openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key gen... | MEDIUM | ????? | ????? | NVD | 1 day ago |