PULSE
LIVE73signals / 24h
FEED
ransomakira reclama a Basic Grain Products · Agriculture and Food Productionransomakira reclama a Pharma Test Apparatebau AG · CH · Manufacturingransomorova reclama a First Baptist Church of Belleview · US · Otherransomorova reclama a Hilliard's Air Conditioning & Heating Inc · US · Professional Servicesransomorova reclama a Gemstone UK · US · Otherransomdragonforce reclama a EduSpa · Hospitalityransomcry0 reclama a Hope's Windows · US · Retail & E-Commerceransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcareransomakira reclama a Basic Grain Products · Agriculture and Food Productionransomakira reclama a Pharma Test Apparatebau AG · CH · Manufacturingransomorova reclama a First Baptist Church of Belleview · US · Otherransomorova reclama a Hilliard's Air Conditioning & Heating Inc · US · Professional Servicesransomorova reclama a Gemstone UK · US · Otherransomdragonforce reclama a EduSpa · Hospitalityransomcry0 reclama a Hope's Windows · US · Retail & E-Commerceransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcare
CVE Watch356,018 in full archive

Vulnerabilities exploitable today

356,018in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603

Distribution · last window

  • Critical
    2,766
  • High
    11,084
  • Medium
    7,344
  • Low
    701
Filters

Window

Severity

Flags

Vulnerabilities25,961–26,000 · 356,018
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-1357
92.8%
28
CVE-2015-5243
92.8%
28
CVE-2020-27159
92.8%
28
CVE-2015-8641
92.8%
28
CVE-2013-0744
92.8%
28
CVE-2021-4473
92.8%
28
CVE-2013-4954
92.8%
28
CVE-2024-24328
92.8%
28
CVE-1999-0175
92.8%
28
CVE-2015-7651
92.8%
28
CVE-2004-1301
92.8%
28
CVE-2000-0828
92.8%
28
CVE-2018-5474
92.8%
28
CVE-2015-7654
92.8%
28
CVE-2005-2367
92.8%
28
CVE-2009-4025
92.8%
28
CVE-2022-4047
92.8%
28
CVE-2021-44140
92.8%
28
CVE-2012-3412
92.8%
28
CVE-2008-3635
92.8%
28
CVE-2015-7659
92.8%
28
CVE-2017-14474
92.8%
28
CVE-2003-0544
92.8%
28
CVE-2024-6779
92.8%
28
CVE-2014-0358
92.8%
28
CVE-2015-8042
92.8%
28
CVE-2026-3345310.0 CRI
92.8%
28Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec) The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy.   Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all. As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer's behavior. In the case of camel-exec, the CamelExecCommandExecutable and CamelExecCommandArgs headers override the executable and arguments configured on the endpoint, resulting in arbitrary OS command execution under the privileges of the Camel process. The producer's output is written back to the Exchange body and returned in the CoAP response payload by CamelCoapResource, giving the attacker an interactive RCE channel without any need for out-of-band exfiltration.                                                                                                                                                                         Exploitation prerequisites are minimal: a single unauthenticated UDP datagram to the CoAP port (default 5683). CoAP (RFC 7252) has no built-in authentication, and DTLS is optional and disabled by default. Because the protocol is UDP-based, HTTP-layer WAF/IDS controls do not apply. This issue affects Apache Camel: from 4.14.0 through 4.14.5, from 4.18.0 before 4.18.1, 4.19.0. Users are recommended to upgrade to version 4.18.1 or 4.19.0, fixing the issue.23d
CVE-2012-3535
92.8%
28
CVE-2008-2407
92.8%
28
CVE-2010-3070
92.8%
28
CVE-2015-7653
92.8%
28
CVE-2007-0466
92.8%
28
CVE-2017-11144
92.8%
28
CVE-2015-7658
92.8%
28
CVE-2020-29495
92.8%
28
CVE-2006-1858
92.8%
28
CVE-2016-4483
92.8%
28
CVE-2012-5838
92.8%
28
CVE-2011-4431
92.8%
28
CVE-2007-2474
92.8%
28