PULSE
LIVE24signals / 24h
FEED
ransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Foundransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Found
CVE Watch359,665 in full archive

Vulnerabilities exploitable today

359,665in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608

Distribution · last window

  • Critical
    2,517
  • High
    11,192
  • Medium
    7,126
  • Low
    650
Filters

Window

Severity

Flags

Vulnerabilities359,481–359,520 · 359,665
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-559842.7 LOW
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service8h
CVE-2026-559865.4 MED
Email Management API Bypasses ManageCredentials Feature Restrictions7h
CVE-2026-726777.3 HIG
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.1d
CVE-2026-559878.1 HIG
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)6h
CVE-2026-564439.6 CRI
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #371186h
CVE-2026-566549.8 CRI
Privilege Escalation via Access Token Scope Escalation in API6h
CVE-2026-567509.1 CRI
Gitea Remember-Me Token Theft Not Invalidating Attacker Session6h
CVE-2026-578865.9 MED
Cross-repository issue/comment attachment re-linking can expose private attachment content8h
CVE-2026-578948.5 HIG
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration8h
CVE-2026-726766.5 MED
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restricting it to safe characters. That identifier is later placed into a server-side script that Fleet Server builds as part of routine agent policy processing, so script syntax embedded in the identifier became part of the script that was executed rather than being treated as data.1d
CVE-2026-583147.7 HIG
Two SSRF findings in Gitea 1.26.28h
CVE-2026-584177.5 HIG
REST API exposes organization membership of private organizations to public8h
CVE-2026-584204.4 MED
Local File Inclusion via file:// URI in Migration Restore8h
CVE-2026-584254.3 MED
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)8h
CVE-2026-584277.5 HIG
Private org member list leaked via /members API endpoint — incomplete fix for PR #381458h
CVE-2026-584286.5 MED
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)8h
CVE-2026-584294.9 MED
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints8h
CVE-2026-584314.3 MED
Public-only API token restriction is not enforced on team API routes8h
CVE-2026-584325.9 MED
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea6h
CVE-2026-584339.1 CRI
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting6h
CVE-2026-584347.5 HIG
Private Repository Metadata Remains Accessible After Access Revocation8h
CVE-2026-584355.4 MED
Gitea LFS Deploy-Key Privilege Escalation8h
CVE-2026-584367.5 HIG
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests8h
CVE-2026-584377.1 HIG
Repository Visibility Manipulation via Git Push Options7h
CVE-2026-584387.5 HIG
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access6h
CVE-2026-584398.1 HIG
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag6h
CVE-2026-584406.8 MED
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6h
CVE-2026-584416.3 MED
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6h
CVE-2026-584426.5 MED
Repository migration SSRF via multi-answer DNS allow-list bypass6h
CVE-2026-584439.1 CRI
Public-only repository tokens can update private PR head branches6h
CVE-2026-584444.3 MED
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents7h
CVE-2026-584452.7 LOW
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API7h
CVE-2026-585075.3 MED
Private Repository Existence Disclosure via go-get Meta Endpoint7h
CVE-2026-585089.1 CRI
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)7h
CVE-2026-591098.8 HIG
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.8h
CVE-2026-597657.5 HIG
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7h
CVE-2026-732667.1 HIG
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.8h
CVE-2026-726757.1 HIG
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.1d
CVE-2019-257657.5 HIG
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).7h
CVE-2026-197304.2 MED
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker. The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).8h