PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCenter
CVE Watch365,446 in full archive

Vulnerabilities exploitable today

365,446in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626

Distribution · last window

  • Critical
    2,325
  • High
    9,981
  • Medium
    4,918
  • Low
    460
Filters

Window

Severity

Flags

Vulnerabilities312,321–312,360 · 365,446
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-31068
14.5%
4
CVE-2020-12904
14.5%
4
CVE-2025-48488
14.5%
4
CVE-2025-257996.0 MED
14.5%
4SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.54d
CVE-2025-53237
14.5%
4
CVE-2026-22455
14.5%
4
CVE-2026-733607.1 HIG
14.5%
4Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.7d
CVE-2026-57283
14.5%
4
CVE-2024-43904
14.5%
4
CVE-2023-25508
14.5%
4
CVE-2025-20141
14.5%
4
CVE-2026-22491
14.5%
4
CVE-2023-39187
14.5%
4
CVE-2026-733937.1 HIG
14.5%
4Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.7d
CVE-2026-728005.8 MED
14.5%
4SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and getBlockRelevantIDs endpoints enumerate workspace-wide block IDs without publish scoping, enabling attackers to discover valid block identifiers across publish boundaries and access content from hidden or password-protected documents.22h
CVE-2022-48701
14.5%
4
CVE-2026-733587.1 HIG
14.5%
4Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.7d
CVE-2026-106636.1 MED
14.5%
4In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to tear down solely from ctx->root, checking only that it is non-NULL. Because UHC controller drivers (e.g. uhc_max3421e, uhc_mcux_common) synthesize UHC_EVT_DEV_REMOVED directly from physical bus line state with no debounce or state guard, an attacker with physical USB access (or a rogue device that bounces its connection) can deliver a second device-removed event after a root device disconnect. The handler then re-enters usbh_device_disconnect() with the dangling pointer, locking a mutex inside the freed object (use-after-free), removing the freed node from the device list, and calling k_mem_slab_free() on the already-freed block (double-free). If the slab block has been reissued to a newly attached device in between, this corrupts a live object. Impact is denial of service (crash) and memory corruption; the attack vector is physical/local. The flaw was introduced in v4.4.0 by the connect/disconnect refactor and is fixed by clearing ctx->root in usbh_device_disconnect() before freeing.42d
CVE-2011-1352
14.5%
4
CVE-2024-274037.8 HIG
14.5%
4In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: reset dst in route object after setting up flow dst is transferred to the flow object, route object does not own it anymore. Reset dst in route object, otherwise if flow_offload_add() fails, error path releases dst twice, leading to a refcount underflow.23d
CVE-2025-24503
14.5%
4
CVE-2025-6749
14.5%
4
CVE-2026-120266.5 MED
14.5%
4Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)58d
CVE-2026-25356
14.5%
4
CVE-2025-11270
14.5%
4
CVE-2025-48484
14.4%
4
CVE-2026-66955.5 MED
14.5%
4A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.8d
CVE-2026-65766
14.5%
4Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.31d
CVE-2025-6753
14.5%
4
CVE-2024-53208
14.5%
4
CVE-2023-39182
14.5%
4
CVE-2026-27524
14.5%
4
CVE-2020-35567
14.4%
4
CVE-2024-438587.8 HIG
14.4%
4In the Linux kernel, the following vulnerability has been resolved: jfs: Fix array-index-out-of-bounds in diFree23d
CVE-2025-61836
14.4%
4
CVE-2024-43889
14.4%
4
CVE-2025-1407
14.4%
4
CVE-2025-61826
14.4%
4
CVE-2026-24037
14.4%
4
CVE-2025-43226
14.4%
4