PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-CommercevulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerce
CVE Watch363,686 in full archive

Vulnerabilities exploitable today

363,686in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610

Distribution · last window

  • Critical
    2,949
  • High
    12,440
  • Medium
    7,643
  • Low
    714
Filters

Window

Severity

Flags

Vulnerabilities43,201–43,240 · 363,686
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-8114
88.1%
26
CVE-2020-9601
88.1%
26
CVE-2018-11779
88.1%
26
CVE-2018-13411
88.1%
26
CVE-2005-1463
88.1%
26
CVE-2019-11398
88.1%
26
CVE-1999-0943
88.1%
26
CVE-2022-250627.5 HIG
88.1%
26TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.43d
CVE-2012-4504
88.1%
26
CVE-2007-2507
88.1%
26
CVE-2004-0169
88.1%
26
CVE-2010-0391
88.1%
26
CVE-2009-1086
88.1%
26
CVE-2020-9717
88.1%
26
CVE-2021-34831
88.1%
26
CVE-2021-270587.8 HIG
88.1%
26Microsoft Office ClickToRun Remote Code Execution Vulnerability1d
CVE-2025-34029
88.1%
26
CVE-2008-5360
88.1%
26
CVE-2021-34848
88.1%
26
CVE-2002-0837
88.1%
26
CVE-2007-1784
88.1%
26
CVE-2006-1599
88.1%
26
CVE-2005-4836
88.1%
26
CVE-2009-3623
88.1%
26
CVE-2020-9625
88.1%
26
CVE-2019-10184
88.1%
26
CVE-2020-9627
88.1%
26
CVE-2025-7762
88.1%
26
CVE-2007-4463
88.1%
26
CVE-2017-6366
88.1%
26
CVE-2011-3557
88.1%
26
CVE-2019-6798
88.1%
26
CVE-2021-369267.5 HIG
88.1%
26Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability11d
CVE-2020-14503
88.1%
26
CVE-2022-3964
88.1%
26
CVE-2020-9719
88.1%
26
CVE-2021-22697
88.1%
26
CVE-2026-32969.8 CRI
88.1%
26The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restrictions.27d
CVE-2011-5173
88.1%
26
CVE-2009-3384
88.1%
26