PULSE
LIVE25signals / 24h
FEED
ransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomqilin reclama a The Saturday Evening Post · US · Otherransomqilin reclama a Commercial Furniture Interiors · US · Retail & E-Commerceransomqilin reclama a Dienst Pack Systems · DE · Manufacturingransomqilin reclama a Ceragres · CA · Manufacturingransomqilin reclama a Pointe Property Group · US · Otherransomqilin reclama a Schreiner Trockenbau GmbH · AT · Manufacturingransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Co) · SA · Otherransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Company) · SA · Professional Servicesransomcoinbasecartel reclama a CEN and Cenelec · BE · Otherransomcoinbasecartel reclama a MIM Fertility · GB · Healthcareransomcoinbasecartel reclama a M. B. Kahn Construction Co. · US · Manufacturingransomcoinbasecartel reclama a Xs Cad · Technologyransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomqilin reclama a The Saturday Evening Post · US · Otherransomqilin reclama a Commercial Furniture Interiors · US · Retail & E-Commerceransomqilin reclama a Dienst Pack Systems · DE · Manufacturingransomqilin reclama a Ceragres · CA · Manufacturingransomqilin reclama a Pointe Property Group · US · Otherransomqilin reclama a Schreiner Trockenbau GmbH · AT · Manufacturingransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Co) · SA · Otherransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Company) · SA · Professional Servicesransomcoinbasecartel reclama a CEN and Cenelec · BE · Otherransomcoinbasecartel reclama a MIM Fertility · GB · Healthcareransomcoinbasecartel reclama a M. B. Kahn Construction Co. · US · Manufacturingransomcoinbasecartel reclama a Xs Cad · Technology
CVE Watch354,825 in full archive

Vulnerabilities exploitable today

354,825in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,590
  • High
    9,226
  • Medium
    7,480
  • Low
    695
Filters

Window

Severity

Flags

Vulnerabilities19,681–19,720 · 354,825
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-8224
94.6%
28
CVE-2015-1351
94.6%
28
CVE-2004-2760
94.6%
28
CVE-2005-1112
94.6%
28
CVE-2008-3159
94.6%
28
CVE-2008-4473
94.6%
28
CVE-2008-4216
94.6%
28
CVE-2020-0832
94.6%
28
CVE-2019-7842
94.6%
28
CVE-2008-0418
94.6%
28
CVE-2018-3714
94.6%
28
CVE-2008-4343
94.6%
28
CVE-2009-2688
94.6%
28
CVE-2017-2991
94.6%
28
CVE-2012-0406
94.6%
28
CVE-2010-2307
94.5%
28
CVE-2009-1549
94.5%
28
CVE-2017-1000471
94.5%
28
CVE-2023-33145
94.5%
28
CVE-2003-0143
94.5%
28
CVE-2012-3263
94.5%
28
CVE-2012-3262
94.5%
28
CVE-2007-2776
94.5%
28
CVE-2005-4559
94.5%
28
CVE-2026-1560
94.5%
28
CVE-2018-1172
94.5%
28
CVE-2012-2441
94.5%
28
CVE-2009-1861
94.5%
28
CVE-2012-1530
94.5%
28
CVE-2018-11717
94.5%
28
CVE-2019-7826
94.5%
28
CVE-2006-4823
94.5%
28
CVE-2023-27290
94.5%
28
CVE-2016-4360
94.5%
28
CVE-2008-4323
94.5%
28
CVE-2026-5016010.0 CRI
94.5%
28Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe is configured without whitelist: true, so extra properties on the request body that are not declared in SaveOnboardingConfigRequest are not stripped and are iterated in the service layer as if they were legitimate InfraConfig entries. Because keys such as JWT_SECRET and SESSION_SECRET are valid InfraConfigEnum values and are not explicitly rejected during validation, an unauthenticated attacker who can reach a fresh instance before onboarding completes (or when no users exist) can overwrite these values in the database. Overwriting JWT_SECRET gives the attacker control of the JWT signing key, allowing them to forge tokens for any user, including administrators, and results in full server compromise. The issue is fixed in hoppscotch 2026.5.0.30d
CVE-2020-10564
94.5%
28
CVE-2008-7124
94.5%
28
CVE-2012-4185
94.5%
28
CVE-2020-22210
94.5%
28