Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-73652Highvantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…
GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2024-24769LowVantage6: No limit on emails sent for password/MFA reset
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
CVE-2026-54533Mediumvantage6 node has an Improper Access Control issue
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
CVE-2024-32969Low· 2.7vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2024-24770Medium· 5.3vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-23823Medium· 4.2vantage6's CORS settings overly permissive
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2024-21653Medium· 6.5vantage6 has insecure SSH configuration for node and server containers
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-28635Medium· 5.4Defining resource name as integer may give unintended access in vantage6
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
CVE-2022-39228Medium· 6.5vantage6 vulnerable to Observable Response Discrepancy
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.