PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCenter
CVE Watch365,446 in full archive

Vulnerabilities exploitable today

365,446in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626

Distribution · last window

  • Critical
    2,325
  • High
    9,981
  • Medium
    4,918
  • Low
    460
Filters

Window

Severity

Flags

Vulnerabilities312,401–312,440 · 365,446
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-27693
14.4%
4
CVE-2024-13292
14.4%
4
CVE-2022-22668
14.4%
4
CVE-2026-6690
14.4%
4
CVE-2024-39637
14.4%
4
CVE-2024-43889
14.4%
4
CVE-2025-57886
14.4%
4
CVE-2022-50825
14.4%
4
CVE-2026-0913
14.4%
4
CVE-2026-325549.3 CRI
14.4%
4Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.2d
CVE-2021-47456
14.4%
4
CVE-2026-225547.8 HIG
14.4%
4MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability35d
CVE-2022-48724
14.4%
4
CVE-2026-25006
14.4%
4
CVE-2025-56648
14.4%
4
CVE-2025-1407
14.4%
4
CVE-2025-61826
14.4%
4
CVE-2024-438587.8 HIG
14.4%
4In the Linux kernel, the following vulnerability has been resolved: jfs: Fix array-index-out-of-bounds in diFree23d
CVE-2025-61836
14.4%
4
CVE-2026-24037
14.4%
4
CVE-2025-43226
14.4%
4
CVE-2020-35567
14.4%
4
CVE-2021-34864
14.4%
4
CVE-2024-53187
14.4%
4
CVE-2026-181444.3 MED
14.4%
4IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.10d
CVE-2026-733889.3 CRI
14.4%
4Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.7d
CVE-2021-47258
14.4%
4
CVE-2021-47250
14.4%
4
CVE-2023-6949
14.4%
4
CVE-2026-325559.3 CRI
14.4%
4Unauthenticated SQL Injection in Boost <= 2.0.4 versions.2d
CVE-2026-731839.3 CRI
14.4%
4Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.7d
CVE-2026-161437.2 HIG
14.4%
4The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.15d
CVE-2026-457764.3 MED
14.4%
4OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. If an installation of Open XDMoD includes the optional Job Performance (SUPReMM) module, an attacker could bypass intended data access restrictions and view other users' compute job efficiency metrics. All deployments of Open XDMoD prior to version 11.0.3 that contain the optional Job Performance (SUPReMM) module are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.35d
CVE-2023-40435
14.4%
4
CVE-2026-0916
14.4%
4
CVE-2021-47260
14.4%
4
CVE-2025-48086
14.4%
4
CVE-2025-35032
14.4%
4
CVE-2026-325519.3 CRI
14.4%
4Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.3d
CVE-2024-13388
14.4%
4