PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional ServicesvulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Services
CVE Watch363,765 in full archive

Vulnerabilities exploitable today

363,765in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611

Distribution · last window

  • Critical
    2,906
  • High
    12,010
  • Medium
    7,334
  • Low
    675
Filters

Window

Severity

Flags

Vulnerabilities316,361–316,400 · 363,765
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-7276
12.8%
4
CVE-2025-26554
12.8%
4
CVE-2019-14055
12.8%
4
CVE-2025-26548
12.8%
4
CVE-2021-3141
12.8%
4
CVE-2025-7234
12.8%
4
CVE-2025-7263
12.8%
4
CVE-2025-7266
12.8%
4
CVE-2025-7982
12.8%
4
CVE-2025-7278
12.8%
4
CVE-2025-26774
12.8%
4
CVE-2025-7283
12.8%
4
CVE-2026-36947
12.8%
4
CVE-2025-7260
12.8%
4
CVE-2025-7255
12.8%
4
CVE-2026-328617.8 HIG
12.8%
4There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvclass file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.28d
CVE-2019-10607
12.8%
4
CVE-2025-7564
12.8%
4
CVE-2019-10605
12.8%
4
CVE-2024-40969
12.8%
4
CVE-2025-7282
12.8%
4
CVE-2026-40923
12.8%
4
CVE-2025-7280
12.8%
4
CVE-2025-7254
12.8%
4
CVE-2025-7286
12.8%
4
CVE-2019-10536
12.8%
4
CVE-2024-31068
12.8%
4
CVE-2020-3665
12.8%
4
CVE-2024-45181
12.8%
4
CVE-2025-7240
12.8%
4
CVE-2023-23940
12.8%
4
CVE-2025-34450
12.8%
4
CVE-2025-52599
12.8%
4
CVE-2025-7977
12.8%
4
CVE-2026-181089.8 CRI
12.8%
4Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object. An SP's encryption certificate is published in its SAML metadata so the IdP can encrypt to it, so any party can encrypt an unsigned assertion to that certificate, wrap it in a samlp:Response, and post it to the assertion consumer service. Any caller that configures a decryption key_file, and so accepts EncryptedAssertions, takes identity fields from an assertion that no trust anchor covers, and an unauthenticated party can authenticate as an arbitrary user. Callers with no key_file configured do not decrypt and are unaffected.15d
CVE-2025-7248
12.8%
4
CVE-2025-26555
12.8%
4
CVE-2024-31113
12.8%
4
CVE-2025-7242
12.8%
4
CVE-2025-7275
12.8%
4