Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-44541Highethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
CVE-2026-42303MediumEthyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2025-57766Medium· 4.8Fides' Admin UI User Password Change Does Not Invalidate Current Session
CVE-2025-57817High· 7.2Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
CVE-2025-57816High· 7.5Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
CVE-2025-57815Medium· 6.5Fides has a Lack of Brute-Force Protections on Authentication Endpoints
CVE-2024-52008Medium· 5.7Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API
CVE-2024-45053Critical· 9.1Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
CVE-2024-45052LowTiming-Based Username Enumeration Vulnerability in Fides Webserver Authentication
CVE-2024-31223Medium· 5.3PoCInformation Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
CVE-2024-38537None· 0.0PoCInclusion of Untrusted polyfill.io Code Vulnerability in fides.js
CVE-2024-35189Medium· 6.5Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints
CVE-2024-34715Low· 2.3Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability
CVE-2023-48224High· 8.2Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification
CVE-2023-47114Medium· 4.3Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
CVE-2023-46125Medium· 6.5Fides Information Disclosure Vulnerability in Config API Endpoint
CVE-2023-46124High· 8.2Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
CVE-2023-46126Low· 3.9Fides JavaScript Injection Vulnerability in Privacy Center URL
CVE-2023-41319High· 8.8Remote Code Execution in Custom Integration Upload
CVE-2023-37480Low· 2.7Fides Webserver Vulnerable to Zip Bomb File Uploads
CVE-2023-37481Low· 2.7Fides Webserver Vulnerable to SVG Bomb File Uploads
CVE-2023-36827High· 7.5ethyca-fides Webserver API Path Traversal vulnerability
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.