PULSE
LIVE73signals / 24h
FEED
ransomakira reclama a Basic Grain Products · Agriculture and Food Productionransomakira reclama a Pharma Test Apparatebau AG · CH · Manufacturingransomorova reclama a First Baptist Church of Belleview · US · Otherransomorova reclama a Hilliard's Air Conditioning & Heating Inc · US · Professional Servicesransomorova reclama a Gemstone UK · US · Otherransomdragonforce reclama a EduSpa · Hospitalityransomcry0 reclama a Hope's Windows · US · Retail & E-Commerceransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcareransomakira reclama a Basic Grain Products · Agriculture and Food Productionransomakira reclama a Pharma Test Apparatebau AG · CH · Manufacturingransomorova reclama a First Baptist Church of Belleview · US · Otherransomorova reclama a Hilliard's Air Conditioning & Heating Inc · US · Professional Servicesransomorova reclama a Gemstone UK · US · Otherransomdragonforce reclama a EduSpa · Hospitalityransomcry0 reclama a Hope's Windows · US · Retail & E-Commerceransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcare
CVE Watch356,018 in full archive

Vulnerabilities exploitable today

356,018in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603

Distribution · last window

  • Critical
    2,767
  • High
    11,084
  • Medium
    7,344
  • Low
    701
Filters

Window

Severity

Flags

Vulnerabilities355,961–356,000 · 356,018
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-16339
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8d
CVE-2026-62169
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61430. Reason: This candidate is a duplicate of CVE-2026-61430. Notes: All CVE users should reference CVE-2026-61430 instead of this candidate.22d
CVE-2026-18060
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.8d
CVE-2026-712404.3 MED
0DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely verifies the target host matches the current site's domain (blocking only cross-domain redirects) while allowing any same-site path with no authentication required to reach the view. This enables unauthenticated phishing redirects and referrer-based token leakage via redirect chains.1d
CVE-2026-61839
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61451. Reason: This candidate is a duplicate of CVE-2026-61451. Notes: All CVE users should reference CVE-2026-61451 instead of this candidate.22d
CVE-2026-17578
0Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages. New versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.1d
CVE-2026-712389.1 CRI
0DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover. The repository also ships with DEBUG=True as the default, causing error pages to leak database credentials, email credentials, OAuth data, and internal file paths.1d
CVE-2026-11740
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2026-712446.5 MED
0Paperless-ngx's MailAccountViewSet.test() action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap_security in the same request. The test connection then authenticates to the caller-specified server using the real stored credentials. A user holding only object-level change_mailaccount permission on the target account (not full admin) can redirect the test connection to an attacker-controlled IMAP host, causing the real stored IMAP password or OAuth token to be sent to that host.1d
CVE-2026-0931
0Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart.1d
CVE-2022-42770
0.0%
0
CVE-2026-14286
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.27d
CVE-2026-213705.3 MED
0.0%
0Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.30d
CVE-2026-61829
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61452. Reason: This candidate is a duplicate of CVE-2026-61452. Notes: All CVE users should reference CVE-2026-61452 instead of this candidate.22d
CVE-2022-20243
0.0%
0
CVE-2026-252607.8 HIG
0.0%
0Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.15d
CVE-2026-51386
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate of CVE-2026-46409. Notes: All CVE users should reference CVE-2026-46409 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.17d
CVE-2026-158115.8 MED
0.0%
0A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.14d
CVE-2026-14170
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.9d
CVE-2026-50268
0.0%
0
CVE-2026-14253
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2026-61841
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61449. Reason: This candidate is a duplicate of CVE-2026-61449. Notes: All CVE users should reference CVE-2026-61449 instead of this candidate.22d
CVE-2026-8281
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.22d
CVE-2023-20827
0.0%
0
CVE-2022-42771
0.0%
0
CVE-2026-0112
0.0%
0
CVE-2026-62180
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61440. Reason: This candidate is a duplicate of CVE-2026-61440. Notes: All CVE users should reference CVE-2026-61440 instead of this candidate.22d
CVE-2026-51255
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.6d
CVE-2026-257037.3 HIG
0NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.1d
CVE-2026-51289
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.6d
CVE-2026-201577.5 HIG
0.0%
0As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.22d
CVE-2026-6890
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.6d
CVE-2026-68577
0Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.6d
CVE-2025-62310
0.0%
0
CVE-2026-213845.3 MED
0.0%
0Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.30d
CVE-2026-61692
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61454. Reason: This candidate is a duplicate of CVE-2026-61454. Notes: All CVE users should reference CVE-2026-61454 instead of this candidate.24d
CVE-2026-68576
0Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.6d
CVE-2026-252717.8 HIG
0.0%
0Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.30d
CVE-2025-36916
0.0%
0
CVE-2026-58125
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.28d