PULSE
LIVE18signals / 24h
FEED
ransomplay reclama a MIE Solutions · GB · Professional Servicesransomplay reclama a Rilpa Enterprises · Not Foundransomplay reclama a Marconi Industrial Services · IT · Manufacturingransomqilin reclama a Synergy Interactive · US · Technologyransomqilin reclama a Energetic Development Corp · TW · Energy & Utilitiesransomqilin reclama a Panda Logistics Taichung Branch · TW · Transportationransomqilin reclama a East Field Corporation · JP · Agriculture and Food Productionransomqilin reclama a Chun Tai Sing Chemical Industry · HK · Manufacturingransomqilin reclama a pm-energy Die Solarexperten · DE · Energy & Utilitiesransomunsafe reclama a Constellation HomeBuilder Systems · US · Manufacturingransomqilin reclama a Harplast SRL · RO · Manufacturingransomqilin reclama a Price Shoes · MX · Retail & E-Commerceransomqilin reclama a Naval Interior Team · FI · Government & Defenseransomqilin reclama a Phithan Phanich · TH · Manufacturingransomplay reclama a MIE Solutions · GB · Professional Servicesransomplay reclama a Rilpa Enterprises · Not Foundransomplay reclama a Marconi Industrial Services · IT · Manufacturingransomqilin reclama a Synergy Interactive · US · Technologyransomqilin reclama a Energetic Development Corp · TW · Energy & Utilitiesransomqilin reclama a Panda Logistics Taichung Branch · TW · Transportationransomqilin reclama a East Field Corporation · JP · Agriculture and Food Productionransomqilin reclama a Chun Tai Sing Chemical Industry · HK · Manufacturingransomqilin reclama a pm-energy Die Solarexperten · DE · Energy & Utilitiesransomunsafe reclama a Constellation HomeBuilder Systems · US · Manufacturingransomqilin reclama a Harplast SRL · RO · Manufacturingransomqilin reclama a Price Shoes · MX · Retail & E-Commerceransomqilin reclama a Naval Interior Team · FI · Government & Defenseransomqilin reclama a Phithan Phanich · TH · Manufacturing
CVE Watch356,780 in full archive

Vulnerabilities exploitable today

356,780in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,532
  • High
    10,545
  • Medium
    6,712
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities324,001–324,040 · 356,780
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48701
9.1%
3
CVE-2026-5282
9.1%
3
CVE-2025-0567
9.1%
3
CVE-2023-23632
9.1%
3
CVE-2025-3677
9.1%
3
CVE-2022-49912
9.1%
3
CVE-2026-2420
9.1%
3
CVE-2022-42464
9.1%
3
CVE-2025-54999
9.1%
3
CVE-2025-13705
9.1%
3
CVE-2017-12306
9.1%
3
CVE-2026-2233
9.1%
3
CVE-2021-47873
9.1%
3
CVE-2026-2553
9.1%
3
CVE-2025-22562
9.1%
3
CVE-2022-48689
9.1%
3
CVE-2026-33862
9.1%
3
CVE-2024-39020
9.1%
3
CVE-2022-35868
9.1%
3
CVE-2026-7391
9.1%
3
CVE-2026-58236.3 MED
9.1%
3A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.17d
CVE-2026-6190
9.1%
3
CVE-2025-68588
9.1%
3
CVE-2021-34390
9.1%
3
CVE-2026-188966.3 MED
9.1%
3A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.5d
CVE-2024-10405
9.1%
3
CVE-2026-7741
9.1%
3
CVE-2026-7410
9.1%
3
CVE-2026-7746
9.1%
3
CVE-2024-48916
9.1%
3
CVE-2026-4507
9.1%
3
CVE-2017-15818
9.1%
3
CVE-2026-7392
9.1%
3
CVE-2025-14956
9.1%
3
CVE-2026-56756.3 MED
9.1%
3A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.17d
CVE-2026-348354.8 MED
9.1%
3Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed. This can lead to host header poisoning in applications that use req.host, req.url, or req.base_url for link generation, redirects, or origin validation. This issue has been patched in versions 3.1.21 and 3.2.6.16d
CVE-2026-4234
9.1%
3
CVE-2023-54007
9.1%
3
CVE-2023-54006
9.1%
3
CVE-2026-3672
9.1%
3