PULSE
LIVE25signals / 24h
FEED
ransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcareransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcare
CVE Watch358,291 in full archive

Vulnerabilities exploitable today

358,291in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,606

Distribution · last window

  • Critical
    2,645
  • High
    11,456
  • Medium
    7,216
  • Low
    681
Filters

Window

Severity

Flags

Vulnerabilities323,201–323,240 · 358,291
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-12822
9.4%
3
CVE-2020-10040
9.4%
3
CVE-2020-3680
9.4%
3
CVE-2026-2721
9.4%
3
CVE-2024-26275
9.4%
3
CVE-2026-7209
9.4%
3
CVE-2023-532577.1 HIG
9.4%
3In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check S1G action frame size Before checking the action code, check that it even exists in the frame.7d
CVE-2026-6551
9.4%
3
CVE-2025-13136
9.4%
3
CVE-2026-1591
9.4%
3
CVE-2025-54543
9.4%
3
CVE-2026-6800
9.4%
3
CVE-2026-4610
9.4%
3
CVE-2019-2298
9.4%
3
CVE-2022-50620
9.4%
3
CVE-2022-30745
9.4%
3
CVE-2025-21902
9.4%
3
CVE-2025-2596
9.4%
3
CVE-2022-48781
9.4%
3
CVE-2024-28666
9.4%
3
CVE-2026-340493.3 LOW
9.4%
3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged attacker who can configure backup inputs to inject commands. This issue is fixed in version 4.0.0-beta.471.35d
CVE-2025-66291
9.4%
3
CVE-2025-32802
9.4%
3
CVE-2026-143436.4 MED
9.4%
3The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because wp_kses_post filters post content on save for users without unfiltered_html, only kses-allowed tag and attribute payloads that survive save-time filtering will reach the unescaped sink; however, the sink itself remains unsafe and such payloads can still execute in the browser when a user renders the shortcode.33d
CVE-2026-226624.3 MED
9.4%
3prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters. Attackers can exploit this vulnerability by sending POST requests to the /api/media-generate endpoint to probe internal networks, access internal services, and exfiltrate data through the upstream Wiro service without receiving direct response bodies.18d
CVE-2026-6532
9.4%
3
CVE-2022-50617
9.4%
3
CVE-2023-53742
9.4%
3
CVE-2021-47723
9.4%
3
CVE-2018-11899
9.4%
3
CVE-2026-59368.5 HIG
9.4%
3An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.35d
CVE-2026-46536.4 MED
9.4%
3The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including 3.6.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.33d
CVE-2026-57918
9.4%
3
CVE-2024-31086
9.4%
3
CVE-2022-48633
9.4%
3
CVE-2026-11717
9.4%
3
CVE-2025-40555
9.4%
3
CVE-2023-27545
9.4%
3
CVE-2024-26709
9.4%
3
CVE-2025-13653
9.4%
3