Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-43667 A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-42163 Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain ci... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-28984 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web conte... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-10080 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an a... | MEDIUM | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-54148 ### Impact
An issue in `DigestAuthProvider.verify`:
The `uri` parameter in the client's `Authorization: Digest …` response was not checked ag... | HIGH | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-54147 ### Impact
An issue in `DigestAuthProvider.verify`:
**Algorithm silently forced to MD5.** The configured `algorithm` parameter was ignored — ever... | MEDIUM | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-53752 ### Summary
docx4j's `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without c... | HIGH | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-53659 ### Impact
`ServerFilters.GZip` and `RequestFilters.GunZip` (and the underlying `Gzip` functions used to decompress request bodies) did not impose an... | HIGH | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-11817 This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-or... | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-73560 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/proce... | MEDIUM | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-73410 Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a N... | HIGH | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-65976 Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk message... | MEDIUM | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-67965 An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-67926 An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-67967 Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-4486... | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-67966 Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access... | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-67925 Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-67917 zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comman... | UNKNOWN | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-66795 A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs... | CRITICAL | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-65832 Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions ... | HIGH | ????? | ????? | NVD | 4 hours ago |