PULSE
LIVE71signals / 24h
FEED
ransomsilentransomgroup reclama a Riker Danzig Scherer Hyland & Perretti · Professional Servicesransomkairos reclama a Hightech Signs · US · Manufacturingransomsilentransomgroup reclama a Riker Danzig LLP · US · Professional Servicesransomincransom reclama a gamaus.com · US · Technologyransomblacknevas reclama a Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... · US · Agriculture and Food Productionransomblacknevas reclama a Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... · US · Healthcareransomblacknevas reclama a Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... · CA · Professional Servicesransomqilin reclama a United Association Local Union 345 · US · Otherransomincransom reclama a BEDC.COM.AU · AU · Energy & Utilitiesransomincransom reclama a diabetesandmetabolism.com · US · Healthcareransomclop reclama a AOL.COM · US · Technologyransomclop reclama a GATE7LLC.COMGBBEV.COM · GB · Not Foundransomclop reclama a ENTERATEK.MXESBERBEVERAGE.COM · MX · Agriculture and Food Productionransomclop reclama a NUVITIA.COM · FR · Technologyransomsilentransomgroup reclama a Riker Danzig Scherer Hyland & Perretti · Professional Servicesransomkairos reclama a Hightech Signs · US · Manufacturingransomsilentransomgroup reclama a Riker Danzig LLP · US · Professional Servicesransomincransom reclama a gamaus.com · US · Technologyransomblacknevas reclama a Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... · US · Agriculture and Food Productionransomblacknevas reclama a Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... · US · Healthcareransomblacknevas reclama a Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... · CA · Professional Servicesransomqilin reclama a United Association Local Union 345 · US · Otherransomincransom reclama a BEDC.COM.AU · AU · Energy & Utilitiesransomincransom reclama a diabetesandmetabolism.com · US · Healthcareransomclop reclama a AOL.COM · US · Technologyransomclop reclama a GATE7LLC.COMGBBEV.COM · GB · Not Foundransomclop reclama a ENTERATEK.MXESBERBEVERAGE.COM · MX · Agriculture and Food Productionransomclop reclama a NUVITIA.COM · FR · Technology
CVE Watch358,897 in full archive

Vulnerabilities exploitable today

358,897in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607

Distribution · last window

  • Critical
    2,708
  • High
    11,665
  • Medium
    7,438
  • Low
    683
Filters

Window

Severity

Flags

Vulnerabilities358,041–358,080 · 358,897
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-73212
0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms, allowing an authenticated RFC 6062 TCP CONNECT relay client to bypass an IPv4 denied-peer-ip range when the Coturn host has a useful translation route. This issue is fixed in version 4.13.1.1d
CVE-2026-627865.5 MED
0Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.8h
CVE-2026-73066
0Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.1d
CVE-2026-628824.3 MED
0Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.7h
CVE-2026-628294.6 MED
0Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.1d
CVE-2026-627985.5 MED
0Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.1d
CVE-2026-627965.5 MED
0Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.1d
CVE-2026-627755.5 MED
0Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.1d
CVE-2026-73213
0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.1d
CVE-2026-627747.0 HIG
0Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.1d
CVE-2026-627737.0 HIG
0Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627707.8 HIG
0Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.19h
CVE-2026-73215
0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request with reservation bit R=0 even though no RTCP socket will release it, allowing an authenticated client to permanently exhaust the relay port pool and cause subsequent allocations to fail with STUN error 508. This issue is fixed in version 4.17.0.1d
CVE-2026-73214
0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0.49m
CVE-2026-627527.8 HIG
0Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.19h
CVE-2026-627517.8 HIG
0Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.19h
CVE-2026-627357.8 HIG
0Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.19h
CVE-2026-627347.0 HIG
0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.10h
CVE-2026-732166.5 MED
0Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation while preserving the allocation, relay socket, session, and mobility ticket, allowing an authenticated client to bypass --user-quota and --total-quota and exhaust relay ports. This issue is fixed in version 4.17.0.1d
CVE-2026-73217
0Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the sandbox, allowing arbitrary host commands with the user's privileges, including modifying files outside the workspace and launching applications. This issue is fixed in version 3.1.2.1d
CVE-2026-73218
0Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.1d
CVE-2026-627337.8 HIG
0Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.19h
CVE-2026-627727.8 HIG
0Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627717.8 HIG
0Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627696.7 MED
0Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.19h
CVE-2026-627687.8 HIG
0Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627547.8 HIG
0Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627537.0 HIG
0Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.10h
CVE-2026-11733
0A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.16h
CVE-2026-627227.8 HIG
0Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627217.8 HIG
0Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627206.5 MED
0Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.8h
CVE-2026-627107.8 HIG
0Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.10h
CVE-2026-627095.5 MED
0Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.1d
CVE-2026-627026.8 MED
0Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.1d
CVE-2026-627017.8 HIG
0Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.19h
CVE-2026-11736
0A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.16h
CVE-2026-619277.0 HIG
0Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.19h
CVE-2026-619237.8 HIG
0Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.1d
CVE-2026-619216.5 MED
0Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.1d