PULSE
LIVE71signals / 24h
FEED
ransomsilentransomgroup reclama a Riker Danzig Scherer Hyland & Perretti · Professional Servicesransomkairos reclama a Hightech Signs · US · Manufacturingransomsilentransomgroup reclama a Riker Danzig LLP · US · Professional Servicesransomincransom reclama a gamaus.com · US · Technologyransomblacknevas reclama a Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... · US · Agriculture and Food Productionransomblacknevas reclama a Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... · US · Healthcareransomblacknevas reclama a Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... · CA · Professional Servicesransomqilin reclama a United Association Local Union 345 · US · Otherransomincransom reclama a BEDC.COM.AU · AU · Energy & Utilitiesransomincransom reclama a diabetesandmetabolism.com · US · Healthcareransomclop reclama a AOL.COM · US · Technologyransomclop reclama a GATE7LLC.COMGBBEV.COM · GB · Not Foundransomclop reclama a ENTERATEK.MXESBERBEVERAGE.COM · MX · Agriculture and Food Productionransomclop reclama a NUVITIA.COM · FR · Technologyransomsilentransomgroup reclama a Riker Danzig Scherer Hyland & Perretti · Professional Servicesransomkairos reclama a Hightech Signs · US · Manufacturingransomsilentransomgroup reclama a Riker Danzig LLP · US · Professional Servicesransomincransom reclama a gamaus.com · US · Technologyransomblacknevas reclama a Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... · US · Agriculture and Food Productionransomblacknevas reclama a Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... · US · Healthcareransomblacknevas reclama a Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... · CA · Professional Servicesransomqilin reclama a United Association Local Union 345 · US · Otherransomincransom reclama a BEDC.COM.AU · AU · Energy & Utilitiesransomincransom reclama a diabetesandmetabolism.com · US · Healthcareransomclop reclama a AOL.COM · US · Technologyransomclop reclama a GATE7LLC.COMGBBEV.COM · GB · Not Foundransomclop reclama a ENTERATEK.MXESBERBEVERAGE.COM · MX · Agriculture and Food Productionransomclop reclama a NUVITIA.COM · FR · Technology
CVE Watch358,897 in full archive

Vulnerabilities exploitable today

358,897in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607

Distribution · last window

  • Critical
    2,708
  • High
    11,665
  • Medium
    7,438
  • Low
    683
Filters

Window

Severity

Flags

Vulnerabilities357,961–358,000 · 358,897
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-619216.5 MED
0Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.1d
CVE-2026-619206.6 MED
0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.11h
CVE-2026-619186.5 MED
0Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.11h
CVE-2026-613685.0 MED
0Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.9h
CVE-2026-613557.8 HIG
0Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.20h
CVE-2026-591386.5 MED
0Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.7h
CVE-2026-591375.5 MED
0Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.7h
CVE-2026-591365.5 MED
0Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.7h
CVE-2026-591355.5 MED
0Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.7h
CVE-2026-732238.1 HIG
0electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-controlled filename name used by editWithSystemEditor in src/client/components/sftp/file-item.jsx is interpolated into path.resolve without sanitization. This issue is fixed in version 3.15.120.2h
CVE-2026-613667.0 HIG
0Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.1d
CVE-2026-613677.8 HIG
0Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.20h
CVE-2026-613587.8 HIG
0Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.11h
CVE-2026-613577.8 HIG
0Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.9h
CVE-2026-591347.5 HIG
0Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.11h
CVE-2026-591338.8 HIG
0Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.20h
CVE-2026-691156.5 MED
0OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints by submitting POST requests with a regular user bearer token to /user/get_users, /user/get_all_users_uid, and /group/get_groups. Attackers can exploit the absent authverify.CheckAdmin() call in the GetPaginationUsers, GetAllUserID, and GetGroups handlers to enumerate all platform user accounts including userIDs, nicknames, and manager level flags, as well as all groups including private groups the user has never joined, exposing group names, owner IDs, and member counts.1d
CVE-2026-591315.6 MED
0No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.7h
CVE-2026-591305.6 MED
0No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.7h
CVE-2026-591285.5 MED
0Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.6h
CVE-2026-591267.0 HIG
0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.8h
CVE-2026-591257.0 HIG
0Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.6h
CVE-2026-591227.0 HIG
0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.8h
CVE-2026-591197.3 HIG
0Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.20h
CVE-2026-586517.8 HIG
0Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.20h
CVE-2026-586507.8 HIG
0Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.10h
CVE-2026-586417.8 HIG
0Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.11h
CVE-2026-591327.5 HIG
0Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.7h
CVE-2026-187096.4 MED
0An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.1d
CVE-2026-187086.4 MED
0An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results affecting other users and denial of service targeted at their operations on the same database. Impact is limited to the scripting engine's execution sandbox, which does not provide access to database, filesystem, or network resources.1d
CVE-2026-187074.3 MED
0An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.1d
CVE-2026-187066.6 MED
0An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.1d
CVE-2026-591249.8 CRI
0Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.11h
CVE-2026-591138.8 HIG
0Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.11h
CVE-2026-586396.5 MED
0Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.5h
CVE-2026-571058.0 HIG
0Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.20h
CVE-2026-561747.8 HIG
0Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.8h
CVE-2026-549847.8 HIG
0Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.7h
CVE-2026-549817.8 HIG
0Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.20h
CVE-2026-491798.8 HIG
0Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.20h