Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,192
- Medium7,126
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-559842.7 LOW—
———Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service8hCVE-2026-559865.4 MED—
———Email Management API Bypasses ManageCredentials Feature Restrictions7hCVE-2026-726777.3 HIG—
———Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.1dCVE-2026-559878.1 HIG—
———OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)6hCVE-2026-564439.6 CRI—
———Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #371186hCVE-2026-566549.8 CRI—
———Privilege Escalation via Access Token Scope Escalation in API6hCVE-2026-567509.1 CRI—
———Gitea Remember-Me Token Theft Not Invalidating Attacker Session6hCVE-2026-578865.9 MED—
———Cross-repository issue/comment attachment re-linking can expose private attachment content8hCVE-2026-578948.5 HIG—
———Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration8hCVE-2026-726766.5 MED—
———Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restricting it to safe characters. That identifier is later placed into a server-side script that Fleet Server builds as part of routine agent policy processing, so script syntax embedded in the identifier became part of the script that was executed rather than being treated as data.1dCVE-2026-583147.7 HIG—
———Two SSRF findings in Gitea 1.26.28hCVE-2026-584177.5 HIG—
———REST API exposes organization membership of private organizations to public8hCVE-2026-584204.4 MED—
———Local File Inclusion via file:// URI in Migration Restore8hCVE-2026-584254.3 MED—
———OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)8hCVE-2026-584277.5 HIG—
———Private org member list leaked via /members API endpoint — incomplete fix for PR #381458hCVE-2026-584286.5 MED—
———Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)8hCVE-2026-584294.9 MED—
———Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints8hCVE-2026-584314.3 MED—
———Public-only API token restriction is not enforced on team API routes8hCVE-2026-584325.9 MED—
———Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea6hCVE-2026-584339.1 CRI—
———Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting6hCVE-2026-584347.5 HIG—
———Private Repository Metadata Remains Accessible After Access Revocation8hCVE-2026-584355.4 MED—
———Gitea LFS Deploy-Key Privilege Escalation8hCVE-2026-584367.5 HIG—
———ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests8hCVE-2026-584377.1 HIG—
———Repository Visibility Manipulation via Git Push Options7hCVE-2026-584387.5 HIG—
———Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access6hCVE-2026-584398.1 HIG—
———Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag6hCVE-2026-584406.8 MED—
———Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6hCVE-2026-584416.3 MED—
———SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6hCVE-2026-584426.5 MED—
———Repository migration SSRF via multi-answer DNS allow-list bypass6hCVE-2026-584439.1 CRI—
———Public-only repository tokens can update private PR head branches6hCVE-2026-584444.3 MED—
———Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents7hCVE-2026-584452.7 LOW—
———Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API7hCVE-2026-585075.3 MED—
———Private Repository Existence Disclosure via go-get Meta Endpoint7hCVE-2026-585089.1 CRI—
———Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)7hCVE-2026-591098.8 HIG—
———SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis
concatenates partner-controlled values directly into SQL statement text using
string concatenation, with neither parameterised queries nor escaping. The
application's own escaping helper, Dazadi.sql_txt(),
is not invoked on these code paths, so a party that sends an invoice can break
out of the string literal and alter the query logic.
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.8hCVE-2026-597657.5 HIG—
———SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7hCVE-2026-732667.1 HIG—
———A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.8hCVE-2026-726757.1 HIG—
———Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.1dCVE-2019-257657.5 HIG—
———ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).7hCVE-2026-197304.2 MED—
———The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning.
There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker.
The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).8h