PULSE
LIVE0signals / 24h
FEED
ransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Foundransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Found
CVE Watch359,691 in full archive

Vulnerabilities exploitable today

359,691in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608

Distribution · last window

  • Critical
    2,519
  • High
    11,197
  • Medium
    7,130
  • Low
    645
Filters

Window

Severity

Flags

Vulnerabilities318,481–318,520 · 359,691
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53982
11.2%
3
CVE-2025-54006
11.2%
3
CVE-2025-41077
11.2%
3
CVE-2022-23087
11.2%
3
CVE-2026-23035
11.2%
3
CVE-2026-47170
11.2%
3
CVE-2024-24488
11.2%
3
CVE-2026-36759
11.2%
3
CVE-2023-42848
11.2%
3
CVE-2025-31997
11.2%
3
CVE-2026-33014
11.2%
3
CVE-2024-4382
11.2%
3
CVE-2025-41078
11.2%
3
CVE-2025-69024
11.2%
3
CVE-2026-6709
11.2%
3
CVE-2025-48295
11.2%
3
CVE-2025-48946
11.2%
3
CVE-2026-712086.5 MED
11.2%
3KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254).5d
CVE-2025-53989
11.2%
3
CVE-2024-22038
11.2%
3
CVE-2025-59567
11.2%
3
CVE-2026-659256.5 MED
11.2%
3A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.16d
CVE-2026-538238.1 HIG
11.2%
3OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.23d
CVE-2025-47598
11.2%
3
CVE-2024-9017
11.2%
3
CVE-2025-46233
11.2%
3
CVE-2025-57877
11.2%
3
CVE-2025-57874
11.2%
3
CVE-2022-48895
11.2%
3
CVE-2025-53991
11.2%
3
CVE-2026-41905
11.2%
3
CVE-2024-46672
11.2%
3
CVE-2021-0256
11.2%
3
CVE-2022-50819
11.2%
3
CVE-2026-44547
11.2%
3
CVE-2026-3293
11.2%
3
CVE-2026-149326.5 MED
11.2%
3In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.9d
CVE-2025-30313
11.2%
3
CVE-2026-465566.5 MED
11.2%
3FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services. This is a blind SSRF with confirmed internal port scanning and internal API triggering capabilities. Version 2.2.1 patches the issue.23d
CVE-2023-24518
11.2%
3