PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
CVE Watch366,836 in full archive

Vulnerabilities exploitable today

366,836in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629

Distribution · last window

  • Critical
    2,360
  • High
    9,604
  • Medium
    5,458
  • Low
    531
Filters

Window

Severity

Flags

Vulnerabilities308,881–308,920 · 366,836
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64814
15.5%
5
CVE-2025-12058
15.5%
5
CVE-2025-64607
15.5%
5
CVE-2025-64626
15.5%
5
CVE-2024-45465
15.5%
5
CVE-2024-45466
15.5%
5
CVE-2025-47886
15.5%
5
CVE-2025-64597
15.5%
5
CVE-2025-64564
15.5%
5
CVE-2026-73492
15.5%
5Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as &#58, &#9, &#10, or &#13. CGI.unescapeHTML leaves these references encoded, so allowed_uri? reports the URL safe even though a browser decodes an encoded colon or strips encoded whitespace and executes the resulting URI scheme. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.14d
CVE-2025-64581
15.5%
5
CVE-2025-64623
15.5%
5
CVE-2025-64599
15.5%
5
CVE-2025-64585
15.5%
5
CVE-2025-64620
15.5%
5
CVE-2025-64792
15.5%
5
CVE-2026-164734.3 MED
15.5%
5A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.30d
CVE-2025-64554
15.5%
5
CVE-2025-64614
15.5%
5
CVE-2025-64801
15.5%
5
CVE-2025-64555
15.5%
5
CVE-2025-64803
15.5%
5
CVE-2024-45470
15.5%
5
CVE-2025-64580
15.5%
5
CVE-2023-32376
15.5%
5
CVE-2025-44110
15.5%
5
CVE-2026-34336
15.5%
5
CVE-2024-23299
15.5%
5
CVE-2026-4572
15.5%
5
CVE-2025-64594
15.5%
5
CVE-2024-47355
15.5%
5
CVE-2025-64578
15.5%
5
CVE-2025-64804
15.5%
5
CVE-2025-64603
15.5%
5
CVE-2025-64627
15.5%
5
CVE-2025-64543
15.5%
5
CVE-2025-48753
15.5%
5
CVE-2025-64802
15.5%
5
CVE-2025-64821
15.5%
5
CVE-2026-796715.5 MED
15.5%
5Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169.254.169.254.nip.io). An attacker with admin privileges can create a webhook with such a hostname to bypass validation and cause the server to make requests to internal services, cloud metadata endpoints, and private network resources. The issue is fixed in 4.4.3.2d