Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23983LowApache Superset allows authenticated users to view sensitive data without explicit permissions
CVE-2026-23980MediumPoCApache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2025-55675MediumApache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
CVE-2025-55674MediumApache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
CVE-2025-55672MediumApache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
CVE-2025-55673MediumApache Superset data query improperly discloses database schema information to low-privileged guest user
CVE-2025-48912HighApache Superset: Improper authorization bypass on row level security via SQL Injection
CVE-2025-27696High· 8.8Apache Superset Allows Ownership Takeover
CVE-2024-55633Medium· 6.5Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-53947Critical· 9.8Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
CVE-2024-53949Medium· 6.5Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
CVE-2024-53948Medium· 5.3Apache Superset: Error verbosity exposes metadata in analytics databases
CVE-2024-39887Medium· 4.3PoCApache Superset vulnerable to improper SQL authorization
CVE-2024-34693Medium· 6.8PoCApache Superset server arbitrary file read
CVE-2024-28148Medium· 4.3Apache Superset Incorrect Authorization vulnerability
CVE-2024-24779Medium· 5.0Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-24772Medium· 4.3Apache Superset: Improper Neutralization of custom SQL on embedded context
CVE-2024-27315Medium· 4.3Apache Superset: Improper error handling on alerts
CVE-2024-24773Medium· 4.9Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-26016Medium· 4.3Apache Superset: Improper authorization validation on dashboards and charts import
CVE-2023-49736Medium· 6.5Apache Superset SQL injection vulnerability
CVE-2023-49734High· 7.7Apache Superset incorrect write permissions vulnerability
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.