PULSE
LIVE21signals / 24h
FEED
ransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransombraincipher reclama a windiam.com · Technologyransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkrybit reclama a Vibonum Technologies Private Limited · IN · Technologyransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransombraincipher reclama a windiam.com · Technologyransomqilin reclama a Primeline Logistics · IE · Transportation/Logisticsransomqilin reclama a Recsa · CR · Not Foundransomqilin reclama a Salida Union School District · US · Educationransomchaos reclama a neopharmlabs.com · US · Healthcareransomqilin reclama a Cpcg · BR · Not Foundransomqilin reclama a EFU Life Assurance · PK · Financial Servicesransomqilin reclama a Infina Health · Healthcareransomm3rx reclama a ubfreight.com · Transportation/Logisticsransomkrybit reclama a dhli.in · IN · Not Foundransomkrybit reclama a Vibonum Technologies Private Limited · IN · Technology
CVE Watch351,837 in full archive

Vulnerabilities exploitable today

351,837in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587

Distribution · last window

  • Critical
    1,811
  • High
    5,855
  • Medium
    4,717
  • Low
    452
Filters

Window

Severity

Flags

Vulnerabilities5,201–5,240 · 351,837
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-1000811
98.7%
30
CVE-2013-2143
98.7%
30
CVE-2022-20828
98.7%
30
CVE-2022-3736
98.7%
30
CVE-2024-39363
98.7%
30
CVE-2025-154678.8 HIG
98.7%
30Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.2d
CVE-2022-36067
98.7%
30
CVE-2018-20841
98.7%
30
CVE-2019-0768
98.7%
30
CVE-2015-3089
98.7%
30
CVE-2019-14234
98.7%
30
CVE-2005-1990
98.7%
30
CVE-2013-3563
98.7%
30
CVE-2012-3569
98.7%
30
CVE-2017-7581
98.7%
30
CVE-2020-8010
98.7%
30
CVE-2021-27964
98.7%
30
CVE-2006-0025
98.7%
30
CVE-2017-17420
98.7%
30
CVE-2022-250609.8 CRI
98.7%
30TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.14d
CVE-2019-1009
98.7%
30
CVE-2026-49160
98.7%
30
CVE-2005-0063
98.7%
30
CVE-2022-46768
98.7%
30
CVE-2006-2382
98.7%
30
CVE-2023-33919
98.7%
30
CVE-2018-4019
98.7%
30
CVE-2017-0141
98.7%
30
CVE-2007-0015
98.7%
30
CVE-2000-0098
98.7%
30
CVE-2006-3281
98.7%
30
CVE-2020-13933
98.7%
30
CVE-2022-0679
98.7%
30
CVE-2024-25065
98.7%
30
CVE-2017-9232
98.7%
30
CVE-2012-2110
98.7%
30
CVE-2014-9013
98.7%
30
CVE-2018-10860
98.7%
30
CVE-2008-0116
98.7%
30
CVE-2019-17181
98.7%
30