Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-75106 OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attacke... | CRITICAL | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-75105 phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/inde... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-75104 Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model di... | MEDIUM | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-75103 Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-71486 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender end... | MEDIUM | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-68004 An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-l... | UNKNOWN | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-67678 File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | UNKNOWN | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-68005 An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_requ... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-71472 A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource ... | CRITICAL | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-70495 A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users a... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-63670 ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packa... | MEDIUM | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-57233 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo ... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-54758 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDia... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-57485 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData end... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-63669 ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the desti... | MEDIUM | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-63667 ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip... | MEDIUM | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-19650 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 befo... | HIGH | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-19478 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 befo... | CRITICAL | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-52886 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::ws... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |
| CVE-2026-71858 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC valida... | UNKNOWN | ????? | ????? | NVD | 7 hours ago |