PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional ServicesvulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Services
CVE Watch363,980 in full archive

Vulnerabilities exploitable today

363,980in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611

Distribution · last window

  • Critical
    2,856
  • High
    11,759
  • Medium
    7,145
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities315,681–315,720 · 363,980
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-394817.8 HIG
13.0%
4In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start The graph walk tries to follow all links, even if they are not between pads. This causes a crash with, e.g. a MEDIA_LNK_FL_ANCILLARY_LINK link. Fix this by allowing the walk to proceed only for MEDIA_LNK_FL_DATA_LINK links.18d
CVE-2019-5309
13.0%
4
CVE-2024-57795
13.0%
4
CVE-2021-26332
13.0%
4
CVE-2024-39479
13.0%
4
CVE-2026-560007.8 HIG
13.0%
4Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.43d
CVE-2025-59842
13.0%
4
CVE-2020-37164
13.0%
4
CVE-2026-27027
13.0%
4
CVE-2025-48145
13.0%
4
CVE-2026-113327.8 HIG
13.0%
4A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.1d
CVE-2026-167794.3 MED
13.0%
4The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite front-page configuration options (show_on_front, page_on_front, and page_for_posts), rewrite primary navigation menu items, replace template parts, and overwrite the Kubio global-data post. Although a nonce check via check_ajax_referer() is present, the nonce is unconditionally emitted into window.kubioUtilsData for every user who can load the block editor, making it harvestable by any Contributor and therefore an ineffective authorization barrier.2d
CVE-2026-147944.3 MED
13.0%
4A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried out remotely. Upgrading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is suggested to upgrade the affected component.46d
CVE-2025-68518
13.0%
4
CVE-2025-47749
13.0%
4
CVE-2025-55039
13.0%
4
CVE-2025-47754
13.0%
4
CVE-2023-53850
13.0%
4
CVE-2024-49621
13.0%
4
CVE-2025-54272
13.0%
4
CVE-2026-162244.3 MED
13.0%
4A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.32d
CVE-2025-21866
13.0%
4
CVE-2021-46949
13.0%
4
CVE-2025-47756
13.0%
4
CVE-2022-50657
13.0%
4
CVE-2021-26370
13.0%
4
CVE-2020-9202
13.0%
4
CVE-2024-53196
13.0%
4
CVE-2026-153754.3 MED
13.0%
4A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.39d
CVE-2025-31993
13.0%
4
CVE-2023-41082
13.0%
4
CVE-2025-20382
13.0%
4
CVE-2025-68866
13.0%
4
CVE-2025-64685
13.0%
4
CVE-2025-47755
13.0%
4
CVE-2025-47753
13.0%
4
CVE-2025-62028
13.0%
4
CVE-2025-81144.7 MED
13.0%
4A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.13h
CVE-2025-42988
13.0%
4
CVE-2025-61797
13.0%
4