PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-CommercevulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerce
CVE Watch363,254 in full archive

Vulnerabilities exploitable today

363,254in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610

Distribution · last window

  • Critical
    2,888
  • High
    12,346
  • Medium
    7,598
  • Low
    718
Filters

Window

Severity

Flags

Vulnerabilities42,001–42,040 · 363,254
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-2395
88.5%
27
CVE-2004-2574
88.5%
27
CVE-2017-10928
88.5%
27
CVE-2009-2797
88.4%
27
CVE-2015-5779
88.5%
27
CVE-2018-8153
88.5%
27
CVE-2021-1701
88.5%
27
CVE-2018-0229
88.4%
27
CVE-2021-46560
88.5%
27
CVE-2014-3210
88.5%
27
CVE-2013-0288
88.5%
27
CVE-2018-17997
88.5%
27
CVE-2018-11392
88.5%
27
CVE-2021-28576
88.5%
27
CVE-2017-14266
88.5%
27
CVE-2014-4979
88.5%
27
CVE-2026-107958.1 HIG
88.5%
27The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.28d
CVE-2004-1207
88.5%
27
CVE-2010-1642
88.5%
27
CVE-2012-0188
88.5%
27
CVE-2016-9397
88.5%
27
CVE-2026-336916.8 MED
88.5%
27The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.27d
CVE-2022-1531
88.5%
27
CVE-2018-17621
88.5%
27
CVE-2007-4947
88.5%
27
CVE-2017-9003
88.5%
27
CVE-2022-442909.8 CRI
88.5%
27webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.43d
CVE-2017-5400
88.5%
27
CVE-2018-0683
88.5%
27
CVE-2021-23338
88.5%
27
CVE-2012-3435
88.5%
27
CVE-2008-3538
88.4%
27
CVE-2022-30708
88.5%
27
CVE-2001-0217
88.5%
27
CVE-2021-345248.1 HIG
88.5%
27Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability10d
CVE-2019-8250
88.5%
27
CVE-2021-413514.3 MED
88.5%
27Microsoft Edge (Chrome based) Spoofing on IE Mode1d
CVE-2005-1228
88.5%
27
CVE-2015-7907
88.5%
27
CVE-2019-1971
88.5%
27