PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not FoundvulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Found
CVE Watch364,588 in full archive

Vulnerabilities exploitable today

364,588in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620

Distribution · last window

  • Critical
    2,405
  • High
    10,150
  • Medium
    5,058
  • Low
    466
Filters

Window

Severity

Flags

Vulnerabilities313,761–313,800 · 364,588
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3175
13.8%
4
CVE-2022-50748
13.8%
4
CVE-2022-28196
13.8%
4
CVE-2026-6501
13.8%
4
CVE-2024-41043
13.8%
4
CVE-2026-1674
13.8%
4
CVE-2023-2863
13.8%
4
CVE-2024-12923
13.8%
4
CVE-2025-30109
13.8%
4
CVE-2024-31942
13.8%
4
CVE-2026-440937.8 HIG
13.8%
4A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.27d
CVE-2025-12437
13.8%
4
CVE-2026-44463
13.8%
4
CVE-2024-48426
13.8%
4
CVE-2025-24904
13.8%
4
CVE-2026-36097.8 HIG
13.8%
4Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.20d
CVE-2025-4220
13.8%
4
CVE-2021-36284
13.8%
4
CVE-2025-8737
13.8%
4
CVE-2022-28195
13.8%
4
CVE-2025-43781
13.8%
4
CVE-2024-29660
13.8%
4
CVE-2022-45415
13.8%
4
CVE-2022-31646
13.8%
4
CVE-2026-483747.8 HIG
13.8%
4Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.23d
CVE-2025-22788
13.8%
4
CVE-2026-538298.0 HIG
13.8%
4OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.34d
CVE-2025-8582
13.8%
4
CVE-2025-46721
13.8%
4
CVE-2025-4171
13.8%
4
CVE-2026-196807.1 HIG
13.8%
4A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.6d
CVE-2025-402777.8 HIG
13.8%
4In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.27d
CVE-2026-21294
13.8%
4
CVE-2026-441067.8 HIG
13.8%
4A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.25d
CVE-2025-5315
13.8%
4
CVE-2023-37605
13.8%
4
CVE-2023-38579
13.8%
4
CVE-2026-555936.5 MED
13.8%
4Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a valid session before routing state-changing requests. The editapikey action in Ajax::editApiKey updates allowed_from and valid_until without validating a CSRF token, while templates/Froxlor/assets/js/jquery/apikeys.js sends no token because the endpoint does not require one. An unauthenticated attacker can induce an authenticated administrator's browser to submit a forged request that adds an attacker-controlled address to an API key's allowed_from list or removes its expiration, weakening the key's security restrictions. This issue is fixed in version 2.3.8.6d
CVE-2025-6857
13.8%
4
CVE-2024-53543
13.8%
4