PULSE
LIVE24signals / 24h
FEED
ransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Foundransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerceransomshinyhunters reclama a Baxter International, Inc. · US · Healthcareransomthegentlemen reclama a Ollies Place Kidswear · AU · Retail & E-Commerceransomthegentlemen reclama a The Coffee Bean · MY · Retail & E-Commerceransomthegentlemen reclama a KFC Kosova · Hospitalityransomthegentlemen reclama a First Coast Heart Vascular Center · US · Healthcareransomthegentlemen reclama a Cityside Homes · GB · Not Found
CVE Watch359,665 in full archive

Vulnerabilities exploitable today

359,665in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608

Distribution · last window

  • Critical
    2,517
  • High
    11,192
  • Medium
    7,126
  • Low
    650
Filters

Window

Severity

Flags

Vulnerabilities319,601–319,640 · 359,665
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-0181
10.9%
3
CVE-2022-499507.8 HIG
10.9%
3In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix memory corruption on open The probe session-duplication overflow check incremented the session count also when there were no more available sessions so that memory beyond the fixed-size slab-allocated session array could be corrupted in fastrpc_session_alloc() on open().11d
CVE-2022-4127
10.9%
3
CVE-2025-38585
10.9%
3
CVE-2026-4577
10.9%
3
CVE-2025-68361
10.9%
3
CVE-2025-5647
10.9%
3
CVE-2026-113515.3 MED
10.9%
3The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.15d
CVE-2026-493688.7 HIG
10.9%
3In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible24d
CVE-2026-53947
10.9%
3
CVE-2026-142405.3 MED
10.9%
3The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export.8d
CVE-2018-25231
10.9%
3
CVE-2024-50070
10.9%
3
CVE-2023-47182
10.9%
3
CVE-2017-17293
10.9%
3
CVE-2026-69106.4 MED
10.9%
3The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.36d
CVE-2023-38021
10.9%
3
CVE-2025-68492
10.9%
3
CVE-2026-572046.5 MED
10.9%
3pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.39d
CVE-2025-58759
10.9%
3
CVE-2025-22844
10.9%
3
CVE-2022-50649
10.9%
3
CVE-2021-33638
10.9%
3
CVE-2026-32019
10.9%
3
CVE-2024-13933
10.9%
3
CVE-2024-46861
10.9%
3
CVE-2026-44967
10.9%
3
CVE-2023-20924
10.9%
3
CVE-2026-40213
10.9%
3
CVE-2026-23032
10.9%
3
CVE-2026-53701
10.9%
3
CVE-2016-20029
10.9%
3
CVE-2021-474467.8 HIG
10.9%
3In the Linux kernel, the following vulnerability has been resolved: drm/msm/a4xx: fix error handling in a4xx_gpu_init() This code returns 1 on error instead of a negative error. It leads to an Oops in the caller. A second problem is that the check for "if (ret != -ENODATA)" cannot be true because "ret" is set to 1.11d
CVE-2024-46864
10.9%
3
CVE-2026-4239
10.9%
3
CVE-2025-47491
10.9%
3
CVE-2025-68470
10.9%
3
CVE-2023-42552
10.9%
3
CVE-2026-393707.1 HIG
10.9%
3WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm to bypass SSRF validation. The server then fetches the response and stores it as media content. This allows an authenticated uploader to turn the upload-by-URL flow into a reliable SSRF response-exfiltration primitive. The vulnerability is caused by an incomplete fix for CVE-2026-27732.21d
CVE-2025-68297
10.9%
3