radar.cysentrix

Vulnerability signals

CVEs connected to the stories shaping the security landscape.

Repeated headlines are collapsed into one signal, ranked by CISA KEV status, EPSS exploitation probability, and breadth of coverage.

150 tracked in this window 12 actively exploited 2 with multiple stories

Vendor exposure

Distinct CVEs inferred from vendor and product names in the retained 30-day coverage.

Bars show distinct CVEs · orange marks KEV share
Microsoft 49 CVEs · 50 mentions
F5 3 CVEs · 3 mentions
Fortinet 3 CVEs · 3 mentions
Google 2 CVEs · 2 mentions
Cisco 1 CVE · 2 mentions
Linux 1 CVE · 1 mentions
Palo Alto Networks 1 CVE · 1 mentions
Splunk 1 CVE · 1 mentions

Showing 150 vulnerability signals

CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API.

1 story 1 source Latest 2w ago
View related coverage

CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.

1 story 1 source Latest 2w ago
View related coverage

CVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

1 story 1 source Latest 2w ago
View related coverage

CVE-2026-47783 In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

1 story 1 source Latest 4w ago
View related coverage

CVE-2025-51480 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.

1 story 1 source Latest 3w ago
View related coverage