PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCenter
CVE Watch366,194 in full archive

Vulnerabilities exploitable today

366,194in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626

Distribution · last window

  • Critical
    2,415
  • High
    10,330
  • Medium
    5,246
  • Low
    512
Filters

Window

Severity

Flags

Vulnerabilities365,921–365,960 · 366,194
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-816937.5 HIG
openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.5h
CVE-2026-815738.6 HIG
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.8h
CVE-2026-815727.8 HIG
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.8h
CVE-2026-812795.4 MED
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.8h
CVE-2026-812778.5 HIG
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.8h
CVE-2026-812765.3 MED
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.15h
CVE-2026-812745.3 MED
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.12h
CVE-2026-816943.3 LOW
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4.9 by routing drive-derived names through sanitize_for_display().8h
CVE-2026-812738.1 HIG
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.8h
CVE-2026-812724.9 MED
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.12h
CVE-2026-812718.8 HIG
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.8h
CVE-2026-804337.5 HIG
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.15h
CVE-2026-782937.1 HIG
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.12h
CVE-2026-782929.8 CRI
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.8h
CVE-2026-816953.3 LOW
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.5h
CVE-2026-782897.1 HIG
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.12h
CVE-2026-816963.3 LOW
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.5h
CVE-2026-782889.3 CRI
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.8h
CVE-2026-782869.8 CRI
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.15h
CVE-2026-782858.5 HIG
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.12h
CVE-2026-782837.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.8h
CVE-2026-782817.1 HIG
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.12h
CVE-2026-782767.2 HIG
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.8h
CVE-2026-782756.8 MED
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.15h
CVE-2026-782749.1 CRI
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.12h
CVE-2026-782736.5 MED
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.8h
CVE-2026-782717.2 HIG
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.12h
CVE-2026-782617.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.8h
CVE-2026-782609.3 CRI
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.15h
CVE-2026-782578.8 HIG
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.12h
CVE-2026-75020
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.12h
CVE-2026-75005
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.12h
CVE-2026-74848
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache APISIX: from 2.12.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.12h
CVE-2026-593556.1 MED
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.8h
CVE-2026-593549.6 CRI
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).8h
CVE-2026-325669.8 CRI
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.8h
CVE-2026-325648.5 HIG
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.12h
CVE-2026-325508.5 HIG
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.8h
CVE-2026-324799.3 CRI
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.15h
CVE-2026-273308.6 HIG
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.12h