Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-55158 ### Impact
Versions of conflibot before `1.2.1` build `git` commands by string interpolation and run them through a shell. Several of the interpolate... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-40345 ### Summary
`deepmerge()` and `deepmergeInto()` can be crashed with a crafted recursive object graph. When both merged values contain self-references... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75010 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75007 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75006 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75004 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75003 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image block... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75002 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75000 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remo... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74999 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74998 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74997 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via craft... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-70412 Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerab... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16467 Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs.
Th... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-14564 Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve E... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16471 Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs.
This... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-18674 On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPl... | UNKNOWN | ????? | ????? | NVD | 1 day ago |
| CVE-2026-40126 OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the up... | UNKNOWN | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74843 A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-74901 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to u... | CRITICAL | ????? | ????? | NVD | 1 day ago |