PULSE
LIVE30signals / 24h
FEED
ransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomthegentlemen reclama a AIMS Group · GB · Otherransomthegentlemen reclama a AnMed · US · Healthcareransomthegentlemen reclama a NTU Alumni Club · SG · Educationransomthegentlemen reclama a Canopy Support Services · CA · Professional Servicesransomthegentlemen reclama a Mikel Coffee · MX · Retail & E-Commerceransomthegentlemen reclama a Hong Kong Baptist University · HK · Educationransomthegentlemen reclama a Eva Care · GB · Healthcareransomthegentlemen reclama a Premier Pigs · GB · Agriculture and Food Productionransomthegentlemen reclama a Zion Contracting · US · Otherransomplay reclama a MIE Solutions · GB · Professional Servicesransomunsafe reclama a DECK APP TECHNOLOGIES PTE. LTD · IN · Technologyransomthegentlemen reclama a CONTAC Ingenieros · CL · Professional Servicesransomthegentlemen reclama a RAK Construction · IN · Manufacturingransomthegentlemen reclama a Lancesoft India · IN · Technologyransomthegentlemen reclama a AIMS Group · GB · Otherransomthegentlemen reclama a AnMed · US · Healthcareransomthegentlemen reclama a NTU Alumni Club · SG · Educationransomthegentlemen reclama a Canopy Support Services · CA · Professional Servicesransomthegentlemen reclama a Mikel Coffee · MX · Retail & E-Commerceransomthegentlemen reclama a Hong Kong Baptist University · HK · Educationransomthegentlemen reclama a Eva Care · GB · Healthcareransomthegentlemen reclama a Premier Pigs · GB · Agriculture and Food Productionransomthegentlemen reclama a Zion Contracting · US · Otherransomplay reclama a MIE Solutions · GB · Professional Services
CVE Watch356,780 in full archive

Vulnerabilities exploitable today

356,780in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,532
  • High
    10,545
  • Medium
    6,712
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities323,961–324,000 · 356,780
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8199
9.1%
3
CVE-2022-49918
9.1%
3
CVE-2026-182173.4 LOW
9.1%
3A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.3d
CVE-2025-13850
9.1%
3
CVE-2025-61803
9.1%
3
CVE-2025-40103
9.1%
3
CVE-2026-0680
9.1%
3
CVE-2026-1071
9.1%
3
CVE-2025-48701
9.1%
3
CVE-2026-5282
9.1%
3
CVE-2025-40021
9.1%
3
CVE-2022-49914
9.1%
3
CVE-2023-53802
9.1%
3
CVE-2026-26939
9.1%
3
CVE-2026-454032.0 LOW
9.1%
3AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only the top-level source and destination paths. The recursive copy helper then descends into child entries using fs.stat() and copies files with fs.copyFile() without validating each child or rejecting symlinks. Because both APIs follow symlinks, a symlink nested inside an allowed source directory can point outside the allowed filesystem root and cause outside file contents to be copied into an allowed destination as a regular file. This vulnerability is fixed in 1.13.0.20d
CVE-2026-7376
9.1%
3
CVE-2024-8120
9.1%
3
CVE-2021-21589
9.1%
3
CVE-2022-42464
9.1%
3
CVE-2026-2233
9.1%
3
CVE-2022-49915
9.1%
3
CVE-2025-40110
9.1%
3
CVE-2025-363598.1 HIG
9.1%
3IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.35d
CVE-2025-0567
9.1%
3
CVE-2025-442517.5 HIG
9.1%
3Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.36d
CVE-2025-13839
9.1%
3
CVE-2026-0580
9.1%
3
CVE-2025-40211
9.1%
3
CVE-2025-13843
9.1%
3
CVE-2026-2499
9.1%
3
CVE-2025-23382
9.1%
3
CVE-2025-8779
9.1%
3
CVE-2026-0812
9.1%
3
CVE-2023-41093
9.1%
3
CVE-2026-178998.8 HIG
9.1%
3Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)7d
CVE-2022-34855
9.1%
3
CVE-2023-23573
9.1%
3
CVE-2026-110386.5 MED
9.1%
3Insufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)18d
CVE-2026-7378
9.1%
3
CVE-2025-61805
9.1%
3