PULSE
LIVE0signals / 24h
FEED
ransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Foundransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Found
CVE Watch360,756 in full archive

Vulnerabilities exploitable today

360,756in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608

Distribution · last window

  • Critical
    2,494
  • High
    11,027
  • Medium
    7,023
  • Low
    632
Filters

Window

Severity

Flags

Vulnerabilities317,321–317,360 · 360,756
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-36479
11.9%
4
CVE-2024-32449
11.9%
4
CVE-2024-57884
11.9%
4
CVE-2024-32668
11.9%
4
CVE-2025-21078
11.9%
4
CVE-2026-28800
11.9%
4
CVE-2024-52586
11.9%
4
CVE-2026-579566.4 MED
11.9%
4SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.27d
CVE-2025-21643
11.9%
4
CVE-2025-24087
11.9%
4
CVE-2026-25532
11.9%
4
CVE-2026-9241
11.9%
4
CVE-2025-21991
11.9%
4
CVE-2026-440634.2 MED
11.9%
4An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP entries via crafted filter input.24d
CVE-2024-39470
11.9%
4
CVE-2025-36326
11.9%
4
CVE-2025-53121
11.9%
4
CVE-2025-63543
11.9%
4
CVE-2024-53212
11.9%
4
CVE-2018-11289
11.9%
4
CVE-2026-35461
11.9%
4
CVE-2025-1383
11.9%
4
CVE-2024-11922
11.9%
4
CVE-2024-33850
11.9%
4
CVE-2025-52361
11.9%
4
CVE-2025-36020
11.9%
4
CVE-2024-531077.8 HIG
11.9%
4In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args() The "arg->vec_len" variable is a u64 that comes from the user at the start of the function. The "arg->vec_len * sizeof(struct page_region))" multiplication can lead to integer wrapping. Use size_mul() to avoid that. Also the size_add/mul() functions work on unsigned long so for 32bit systems we need to ensure that "arg->vec_len" fits in an unsigned long.13d
CVE-2023-42834
11.9%
4
CVE-2021-421936.1 MED
11.9%
4nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.42d
CVE-2026-156417.1 HIG
11.9%
4Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.17d
CVE-2026-34261
11.9%
4
CVE-2023-25505
11.9%
4
CVE-2025-23106
11.9%
4
CVE-2025-6703
11.9%
4
CVE-2025-60452
11.9%
4
CVE-2025-60451
11.9%
4
CVE-2023-534548.8 HIG
11.9%
4In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing the input_dev would lead to a use-after-free when the input_dev was unregistered and subsequently fires a uevent that depends on the name. At the point of firing the uevent, the name would be freed by devres management. Use devm_kasprintf to simplify the logic for allocating memory and formatting the input_dev name string.13d
CVE-2024-25571
11.9%
4
CVE-2024-56699
11.9%
4
CVE-2024-468697.8 HIG
11.9%
4In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver private data Fix driver not allocating memory for struct btintel_data which is used to store internal data.13d