PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch369,220 in full archive

Vulnerabilities exploitable today

369,220in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636

Distribution · last window

  • Critical
    2,184
  • High
    7,857
  • Medium
    5,748
  • Low
    554
Filters

Window

Severity

Flags

Vulnerabilities368,841–368,880 · 369,220
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-19561
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.17d
CVE-2026-18862
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.17d
CVE-2023-32631
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused9d
CVE-2026-855786.5 MED
0SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.1d
CVE-2023-20835
0.0%
0
CVE-2026-856156.4 MED
0Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts and configurations or delete dashboard grid arrangements across tenants.1d
CVE-2026-856097.5 HIG
0Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parameter to fetchWithRedirects() and performs server-side HTTP requests to arbitrary URLs without any SSRF/IP validation. An unauthenticated remote attacker can access cloud instance metadata endpoints, probe internal services, scan internal network ports, and read returned content (status code, page size, timing, and parsed HTML metadata), and leak internal IP addresses (via getIPInfo() to a third party).23h
CVE-2026-85588
0phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.1d
CVE-2026-190517.1 HIG
0Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448.23h
CVE-2026-46533
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.16d
CVE-2026-9244
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.15d
CVE-2026-46534
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.16d
CVE-2026-62173
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61433. Reason: This candidate is a duplicate of CVE-2026-61433. Notes: All CVE users should reference CVE-2026-61433 instead of this candidate.52d
CVE-2026-6260
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.16d
CVE-2026-85591
0phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to the user data update endpoint with only a CSRF token to silently change any user's password, including administrators, causing irreversible account takeover and victim lockout.1d
CVE-2026-856138.2 HIG
0OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints.1d
CVE-2026-85590
0phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP without requiring password re-entry or a current TOTP code. The same downgrade is also reachable inline via PUT /api/user/data/update, which accepts a plain twofactor_enabled form field under the same session+CSRF-only guard. An attacker who has hijacked a user's session can silently strip two-factor protection from any account, including administrator accounts, after which password-only authentication succeeds.22h
CVE-2021-48000
0Rejected reason: This CVE ID has been rejected.9d
CVE-2026-855817.5 HIG
0SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.1d
CVE-2026-4644
0A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.21h
CVE-2021-47999
0Rejected reason: This CVE ID has been rejected.9d
CVE-2026-79707
0A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.21h
CVE-2026-190807.5 HIG
0Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.23h
CVE-2022-50974
0Rejected reason: This CVE ID has been rejected.25d
CVE-2026-0057
0.0%
0
CVE-2022-51003
0Rejected reason: This CVE ID has been rejected.9d
CVE-2026-29012
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.26d
CVE-2023-46709
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused9d
CVE-2026-68769
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.14d
CVE-2026-51280
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.36d
CVE-2026-20438
0.0%
0
CVE-2026-72858
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.16d
CVE-2026-17592
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.36d
CVE-2025-2795
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.15d
CVE-2026-51240
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.36d
CVE-2025-3127
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.15d
CVE-2026-11950
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.66d
CVE-2026-76831
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.12d
CVE-2026-8055
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All CVE users should reference CVE-2026-48866 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.52d
CVE-2026-5723
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.14d