PULSE
LIVE71signals / 24h
FEED
ransomsilentransomgroup reclama a Riker Danzig Scherer Hyland & Perretti · Professional Servicesransomkairos reclama a Hightech Signs · US · Manufacturingransomsilentransomgroup reclama a Riker Danzig LLP · US · Professional Servicesransomincransom reclama a gamaus.com · US · Technologyransomblacknevas reclama a Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... · US · Agriculture and Food Productionransomblacknevas reclama a Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... · US · Healthcareransomblacknevas reclama a Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... · CA · Professional Servicesransomqilin reclama a United Association Local Union 345 · US · Otherransomincransom reclama a BEDC.COM.AU · AU · Energy & Utilitiesransomincransom reclama a diabetesandmetabolism.com · US · Healthcareransomclop reclama a AOL.COM · US · Technologyransomclop reclama a GATE7LLC.COMGBBEV.COM · GB · Not Foundransomclop reclama a ENTERATEK.MXESBERBEVERAGE.COM · MX · Agriculture and Food Productionransomclop reclama a NUVITIA.COM · FR · Technologyransomsilentransomgroup reclama a Riker Danzig Scherer Hyland & Perretti · Professional Servicesransomkairos reclama a Hightech Signs · US · Manufacturingransomsilentransomgroup reclama a Riker Danzig LLP · US · Professional Servicesransomincransom reclama a gamaus.com · US · Technologyransomblacknevas reclama a Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... · US · Agriculture and Food Productionransomblacknevas reclama a Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... · US · Healthcareransomblacknevas reclama a Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... · CA · Professional Servicesransomqilin reclama a United Association Local Union 345 · US · Otherransomincransom reclama a BEDC.COM.AU · AU · Energy & Utilitiesransomincransom reclama a diabetesandmetabolism.com · US · Healthcareransomclop reclama a AOL.COM · US · Technologyransomclop reclama a GATE7LLC.COMGBBEV.COM · GB · Not Foundransomclop reclama a ENTERATEK.MXESBERBEVERAGE.COM · MX · Agriculture and Food Productionransomclop reclama a NUVITIA.COM · FR · Technology
CVE Watch358,897 in full archive

Vulnerabilities exploitable today

358,897in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607

Distribution · last window

  • Critical
    2,708
  • High
    11,665
  • Medium
    7,438
  • Low
    683
Filters

Window

Severity

Flags

Vulnerabilities358,001–358,040 · 358,897
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-727126.5 MED
0Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.1d
CVE-2026-72773
0n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the tool to return the names and contents of arbitrary local files readable by the daemon's OS user. Any deployment where an actor can influence the tool's search input is affected.1d
CVE-2026-72774
0n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pre-execution permission check compares the unresolved expression instead of the resolved credential type, the ownership check is skipped and the credential is loaded at execution time, allowing the member to use or exfiltrate a credential they were not granted. Exploitation requires knowing the target credential's identifier.1d
CVE-2026-727806.5 MED
0Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.1d
CVE-2026-4805610.0 CRI
0Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.1d
CVE-2026-515838.5 HIG
0An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.5h
CVE-2026-515849.8 CRI
0An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.5h
CVE-2023-54370
0Rejected reason: This CVE ID has been rejected.1d
CVE-2023-54371
0Rejected reason: This CVE ID has been rejected.1d
CVE-2023-54372
0Rejected reason: This CVE ID has been rejected.1d
CVE-2023-54373
0Rejected reason: This CVE ID has been rejected.1d
CVE-2023-54374
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37257
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37258
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37260
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37261
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37263
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37265
0Rejected reason: This CVE ID has been rejected.1d
CVE-2021-47988
0Rejected reason: This CVE ID has been rejected.1d
CVE-2026-1706110.0 CRI
0A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.1d
CVE-2021-47989
0Rejected reason: This CVE ID has been rejected.1d
CVE-2021-47990
0Rejected reason: This CVE ID has been rejected.1d
CVE-2020-37264
0Rejected reason: This CVE ID has been rejected.1d
CVE-2026-188608.7 HIG
0Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org. This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.1d
CVE-2021-47991
0Rejected reason: This CVE ID has been rejected.1d
CVE-2021-47994
0Rejected reason: This CVE ID has been rejected.1d
CVE-2026-628867.8 HIG
0Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.10h
CVE-2026-628857.8 HIG
0Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.19h
CVE-2021-47995
0Rejected reason: This CVE ID has been rejected.1d
CVE-2026-628836.7 MED
0Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.19h
CVE-2026-628816.7 MED
0Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.19h
CVE-2026-628807.8 HIG
0Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.10h
CVE-2026-628789.8 CRI
0Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.9h
CVE-2026-628278.8 HIG
0Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.10h
CVE-2026-628248.8 HIG
0Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.10h
CVE-2026-627997.8 HIG
0Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627977.8 HIG
0Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627877.5 HIG
0Use after free in Windows DNS allows an authorized attacker to execute code over a network.10h
CVE-2026-727137.5 HIG
0XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an account without email verification, then submit crafted `file_name` values such as parent-directory traversal sequences to the `/workspace/file` handler to read host files including application secrets, database credentials, and system files outside the Docker sandbox.1d
CVE-2026-730909.3 CRI
0PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a malicious federated server to rewrite another server's video metadata, visibility, media file, and HLS URLs. This issue is fixed in version 8.2.2.1d