PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
CVE Watch367,144 in full archive

Vulnerabilities exploitable today

367,144in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629

Distribution · last window

  • Critical
    2,256
  • High
    9,258
  • Medium
    5,266
  • Low
    507
Filters

Window

Severity

Flags

Vulnerabilities366,921–366,960 · 367,144
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-54373
0Rejected reason: This CVE ID has been rejected.20d
CVE-2026-24508
0.0%
0
CVE-2026-828579.8 CRI
0hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.4h
CVE-2026-828686.1 MED
0@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates.2h
CVE-2026-828755.5 MED
0ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.4h
CVE-2026-490039.6 CRI
0Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileges to steal configuration passwords such as SNMP, thereby tampering with critical system parameters and triggering abnormal operation of the entire power system.2h
CVE-2026-826772.4 LOW
0A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.3h
CVE-2026-51255
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.31d
CVE-2026-8254210.0 CRI
0A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.1d
CVE-2026-81322
0Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts. AshCloak.Transformers.SetUpEncryption removes each cloaked attribute from the action's accept list and adds an action argument that carries the plaintext into the encryption change. That argument is built with sensitive?: attr.sensitive?, inheriting the flag from the source attribute, so a cloaked attribute declared without sensitive? true produces a non-sensitive argument. It is the only place the cleartext value lives, and the one place Ash will not redact: it appears verbatim in inspect(changeset), Ash.Error.Invalid and validation error messages, telemetry, :sys dumps, and error-tracker payloads. The generated encrypted attribute and decrypt calculation are already hardcoded sensitive. This issue affects ash_cloak: from 0.1.0 before 0.4.0.19h
CVE-2026-54709
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-54637. Reason: This candidate is a duplicate of CVE-2026-54637. Notes: All CVE users should reference CVE-2026-54637 instead of this candidate.56d
CVE-2024-583795.3 MED
0nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny service.4h
CVE-2026-826808.8 HIG
0A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.2h
CVE-2026-51258
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.31d
CVE-2026-35005
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2026-826889.1 CRI
0A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.2h
CVE-2022-51004
0Rejected reason: This CVE ID has been rejected.4d
CVE-2026-9012
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.10d
CVE-2026-73111
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.13d
CVE-2026-56875
0Rejected reason: reserved but not needed10d
CVE-2026-35026
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2025-27076
0.0%
0
CVE-2026-20415
0.0%
0
CVE-2023-40157
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused4d
CVE-2026-00947.8 HIG
0.0%
0In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.40d
CVE-2025-24837
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused19d
CVE-2026-51288
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.31d
CVE-2026-51242
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.31d
CVE-2021-4475
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.10d
CVE-2026-28534
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2026-29012
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2023-47208
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused4d
CVE-2026-70624
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.24d
CVE-2023-43483
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused4d
CVE-2026-15799
0Rejected reason: This is a duplicate.35d
CVE-2026-26348
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.21d
CVE-2026-2345
0.0%
0
CVE-2025-32087
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused19d
CVE-2023-24462
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused4d
CVE-2023-24541
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused4d