PULSE
LIVE0signals / 24h
FEED
ransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Foundransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Found
CVE Watch360,835 in full archive

Vulnerabilities exploitable today

360,835in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607

Distribution · last window

  • Critical
    2,641
  • High
    11,456
  • Medium
    7,085
  • Low
    644
Filters

Window

Severity

Flags

Vulnerabilities316,961–317,000 · 360,835
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-41852
12.1%
4
CVE-2025-48875
12.1%
4
CVE-2025-46525
12.1%
4
CVE-2023-3842
12.1%
4
CVE-2026-56026
12.1%
4
CVE-2026-648337.1 HIG
12.1%
4FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.6d
CVE-2024-23550
12.1%
4
CVE-2020-1795
12.1%
4
CVE-2023-46087
12.1%
4
CVE-2025-398648.8 HIG
12.1%
4In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix use-after-free in cmp_bss() Following bss_free() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), adjust cfg80211_update_known_bss() to free the last beacon frame elements only if they're not shared via the corresponding 'hidden_beacon_bss' pointer.19d
CVE-2023-41010
12.1%
4
CVE-2026-611436.4 MED
12.0%
4Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).19h
CVE-2024-51556
12.1%
4
CVE-2025-46521
12.1%
4
CVE-2026-581029.1 CRI
12.1%
4Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensions(), extensions_by_long_name(), extensions_by_oid(), or has_extension_oid()), the code passes OBJ_obj2txt()'s return value as the hash-key length; because that value is the OID's full text length rather than the bytes written to the fixed-size buffer (129 bytes), an OID whose text is longer than the 129-byte buffer causes a read past the allocation, exposing adjacent heap memory as the returned hash key. extensions_by_name() uses the static shortname path and is not affected.7d
CVE-2026-655975.4 MED
12.1%
4n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call authenticated APIs using the victim's session. An account with global:member privileges can exploit the issue.22d
CVE-2025-9636
12.1%
4
CVE-2023-45606
12.1%
4
CVE-2023-45753
12.1%
4
CVE-2023-45752
12.1%
4
CVE-2025-42939
12.0%
4
CVE-2025-46533
12.1%
4
CVE-2026-52698
12.1%
4
CVE-2023-41850
12.1%
4
CVE-2025-39562
12.1%
4
CVE-2021-1519
12.1%
4
CVE-2023-45639
12.1%
4
CVE-2023-5532
12.1%
4
CVE-2023-6503
12.1%
4
CVE-2017-1346
12.1%
4
CVE-2026-49355
12.1%
4
CVE-2025-31470
12.1%
4
CVE-2026-22348
12.1%
4
CVE-2025-46517
12.1%
4
CVE-2025-47725
12.1%
4
CVE-2025-47726
12.1%
4
CVE-2025-31627
12.1%
4
CVE-2026-654535.3 MED
12.1%
4Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.26d
CVE-2022-49793
12.1%
4
CVE-2025-46529
12.1%
4