Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-68924 MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs ... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-68922 MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py us... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-67920 An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), ... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-67921 Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java compo... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-67846 Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the ... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-67262 Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-66780 A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exces... | CRITICAL | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-63640 MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in ... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-61696 Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitte... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-65959 Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-54570 AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/M... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-54552 sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. W... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-52608 An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExe... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-52609 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web b... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-52610 An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere o... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-52607 A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by... | UNKNOWN | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-50143 The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify ... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-49452 WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS... | MEDIUM | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-48508 Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_pr... | HIGH | ????? | ????? | NVD | 16 hours ago |
| CVE-2026-44472 Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as suffici... | HIGH | ????? | ????? | NVD | 16 hours ago |