PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / Libuser
CVE Watch368,208 in full archive

Vulnerabilities exploitable today

368,208in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631

Distribution · last window

  • Critical
    2,146
  • High
    7,677
  • Medium
    5,510
  • Low
    543
Filters

Window

Severity

Flags

Vulnerabilities297,161–297,200 · 368,208
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-355275.0 MED
19.1%
6Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be rejected by policy. Although the actual image download is blocked by the project restriction, an authenticated user can coerce the daemon into making blind HEAD requests to arbitrary destinations. These requests include server metadata in custom headers (Incus-Server-Architectures, Incus-Server-Version), which discloses information about the host environment to the attacker-controlled endpoint. This blind SSRF primitive can be used to probe internal services, unroutable address space, or cloud metadata endpoints reachable from the host. This vulnerability pattern is similar to CVE-2026-24767. This issue has been fixed in version 7.0.0.41d
CVE-2014-5947
19.1%
6
CVE-2014-5942
19.1%
6
CVE-2014-5697
19.1%
6
CVE-2014-5788
19.1%
6
CVE-2014-5952
19.1%
6
CVE-2024-41141
19.1%
6
CVE-2014-5766
19.1%
6
CVE-2014-5956
19.1%
6
CVE-2014-5897
19.1%
6
CVE-2014-5829
19.1%
6
CVE-2014-5893
19.1%
6
CVE-2014-5693
19.1%
6
CVE-2014-5950
19.1%
6
CVE-2014-5815
19.1%
6
CVE-2014-5671
19.1%
6
CVE-2024-40998
19.1%
6
CVE-2014-5813
19.1%
6
CVE-2014-5703
19.1%
6
CVE-2014-5965
19.1%
6
CVE-2014-5935
19.1%
6
CVE-2014-5702
19.1%
6
CVE-2014-5701
19.1%
6
CVE-2026-44311
19.1%
6
CVE-2014-5909
19.1%
6
CVE-2014-5936
19.1%
6
CVE-2025-9676
19.1%
6
CVE-2025-9674
19.1%
6
CVE-2014-5907
19.1%
6
CVE-2014-5945
19.1%
6
CVE-2024-3579
19.1%
6
CVE-2014-5876
19.1%
6
CVE-2014-5669
19.1%
6
CVE-2014-5966
19.1%
6
CVE-2014-5960
19.1%
6
CVE-2014-5765
19.1%
6
CVE-2014-6023
19.1%
6
CVE-2014-6022
19.1%
6
CVE-2014-5714
19.1%
6
CVE-2014-5988
19.1%
6