Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-19693 extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so a... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16139 In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validat... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16138 In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with wri... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16137 In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uploa... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-15218 A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permi... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-53728 ## Summary
The external identity provider callback at `GET /auth/external` accepts attacker-controlled redirect URIs that only need to start with a r... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-55158 ### Impact
Versions of conflibot before `1.2.1` build `git` commands by string interpolation and run them through a shell. Several of the interpolate... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-40345 ### Summary
`deepmerge()` and `deepmergeInto()` can be crashed with a crafted recursive object graph. When both merged values contain self-references... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75010 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75007 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75006 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75004 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75003 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image block... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75002 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75000 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remo... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74999 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74998 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74997 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via craft... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-70412 Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerab... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16467 Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs.
Th... | HIGH | ????? | ????? | NVD | 1 day ago |