PULSE
LIVE36signals / 24h
FEED
ransomglobal secret group reclama a MACOFIN HELLAS S.A. · GR · Financial Servicesransomqilin reclama a City of Winchester · US · Government & Defenseransomqilin reclama a B Wright Drywall · US · Manufacturingransomglobal secret group reclama a Cook Remodeling · US · Otherransomstorm reclama a Southern Metals · US · Manufacturingransomstorm reclama a TRP International · US · Otherransomstorm reclama a Supportive Insurance Services · US · Financial Servicesransomwallstreet reclama a T.RAD North America · US · Technologyransomwallstreet reclama a Black Hills Bentonite · US · Manufacturingransomspacebears reclama a Elixi International SA · CH · Healthcareransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomglobal secret group reclama a MACOFIN HELLAS S.A. · GR · Financial Servicesransomqilin reclama a City of Winchester · US · Government & Defenseransomqilin reclama a B Wright Drywall · US · Manufacturingransomglobal secret group reclama a Cook Remodeling · US · Otherransomstorm reclama a Southern Metals · US · Manufacturingransomstorm reclama a TRP International · US · Otherransomstorm reclama a Supportive Insurance Services · US · Financial Servicesransomwallstreet reclama a T.RAD North America · US · Technologyransomwallstreet reclama a Black Hills Bentonite · US · Manufacturingransomspacebears reclama a Elixi International SA · CH · Healthcareransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technology
CVE Watch356,923 in full archive

Vulnerabilities exploitable today

356,923in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,543
  • High
    10,564
  • Medium
    6,729
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities323,561–323,600 · 356,923
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-178426.5 MED
9.3%
3Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)7d
CVE-2025-69315
9.3%
3
CVE-2023-53075
9.3%
3
CVE-2023-36538
9.3%
3
CVE-2026-5393
9.3%
3
CVE-2025-30409
9.3%
3
CVE-2026-161084.3 MED
9.3%
3A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.4d
CVE-2025-12031
9.3%
3
CVE-2025-49572
9.3%
3
CVE-2023-31031
9.3%
3
CVE-2026-606976.3 MED
9.3%
3Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Site Hub accessible data as well as unauthorized read access to a subset of Oracle Site Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Site Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).4d
CVE-2024-51640
9.3%
3
CVE-2026-178836.5 MED
9.3%
3Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)7d
CVE-2024-51633
9.3%
3
CVE-2024-51632
9.3%
3
CVE-2025-62482
9.3%
3
CVE-2020-7523
9.3%
3
CVE-2025-3588
9.3%
3
CVE-2025-1778
9.3%
3
CVE-2026-562245.4 MED
9.3%
3Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.40d
CVE-2025-31220
9.3%
3
CVE-2025-54187
9.3%
3
CVE-2024-54401
9.3%
3
CVE-2024-54389
9.3%
3
CVE-2017-18158
9.3%
3
CVE-2022-45192
9.3%
3
CVE-2024-54392
9.3%
3
CVE-2025-1697
9.3%
3
CVE-2024-47079
9.3%
3
CVE-2025-22395
9.3%
3
CVE-2024-54398
9.3%
3
CVE-2024-26705
9.3%
3
CVE-2024-54393
9.3%
3
CVE-2024-54410
9.3%
3
CVE-2021-47429
9.3%
3
CVE-2024-583636.3 MED
9.3%
3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter.20d
CVE-2025-53112
9.3%
3
CVE-2025-38298
9.3%
3
CVE-2026-2583
9.3%
3
CVE-2026-329766.5 MED
9.3%
3OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false.16d