PULSE
LIVE18signals / 24h
FEED
ransomplay reclama a MIE Solutions · GB · Professional Servicesransomplay reclama a Rilpa Enterprises · Not Foundransomplay reclama a Marconi Industrial Services · IT · Manufacturingransomqilin reclama a Synergy Interactive · US · Technologyransomqilin reclama a Energetic Development Corp · TW · Energy & Utilitiesransomqilin reclama a Panda Logistics Taichung Branch · TW · Transportationransomqilin reclama a East Field Corporation · JP · Agriculture and Food Productionransomqilin reclama a Chun Tai Sing Chemical Industry · HK · Manufacturingransomqilin reclama a pm-energy Die Solarexperten · DE · Energy & Utilitiesransomunsafe reclama a Constellation HomeBuilder Systems · US · Manufacturingransomqilin reclama a Harplast SRL · RO · Manufacturingransomqilin reclama a Price Shoes · MX · Retail & E-Commerceransomqilin reclama a Naval Interior Team · FI · Government & Defenseransomqilin reclama a Phithan Phanich · TH · Manufacturingransomplay reclama a MIE Solutions · GB · Professional Servicesransomplay reclama a Rilpa Enterprises · Not Foundransomplay reclama a Marconi Industrial Services · IT · Manufacturingransomqilin reclama a Synergy Interactive · US · Technologyransomqilin reclama a Energetic Development Corp · TW · Energy & Utilitiesransomqilin reclama a Panda Logistics Taichung Branch · TW · Transportationransomqilin reclama a East Field Corporation · JP · Agriculture and Food Productionransomqilin reclama a Chun Tai Sing Chemical Industry · HK · Manufacturingransomqilin reclama a pm-energy Die Solarexperten · DE · Energy & Utilitiesransomunsafe reclama a Constellation HomeBuilder Systems · US · Manufacturingransomqilin reclama a Harplast SRL · RO · Manufacturingransomqilin reclama a Price Shoes · MX · Retail & E-Commerceransomqilin reclama a Naval Interior Team · FI · Government & Defenseransomqilin reclama a Phithan Phanich · TH · Manufacturing
CVE Watch356,780 in full archive

Vulnerabilities exploitable today

356,780in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,532
  • High
    10,545
  • Medium
    6,712
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities324,121–324,160 · 356,780
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-113663.7 LOW
9.1%
3The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid signature and overwrite a MonsterInsights WordPress plugin before 11.1.0 configuration value, disrupting the MonsterInsights WordPress plugin before 11.1.0's server-side analytics in Manual GA4 mode.6d
CVE-2025-69013
9.1%
3
CVE-2026-22052
9.1%
3
CVE-2026-7117
9.1%
3
CVE-2026-7267
9.1%
3
CVE-2026-56816.3 MED
9.1%
3A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.17d
CVE-2026-5660
9.1%
3
CVE-2026-164496.3 MED
9.1%
3A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation of the argument orderField causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.19d
CVE-2026-4970
9.1%
3
CVE-2026-119155.9 MED
9.1%
3vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.27d
CVE-2026-94116.3 MED
9.1%
3A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of the component Invoice Generation Handler. Performing a manipulation of the argument customer_name/category results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.18d
CVE-2026-483498.1 HIG
9.1%
3Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.25d
CVE-2019-10497
9.1%
3
CVE-2019-10506
9.1%
3
CVE-2024-25812
9.1%
3
CVE-2019-10508
9.1%
3
CVE-2024-46778
9.1%
3
CVE-2023-25509
9.1%
3
CVE-2022-32569
9.1%
3
CVE-2022-48191
9.1%
3
CVE-2018-11296
9.1%
3
CVE-2026-156377.5 HIG
9.1%
3Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.11d
CVE-2022-49406
9.1%
3
CVE-2026-20686
9.1%
3
CVE-2024-0079
9.1%
3
CVE-2022-50687
9.1%
3
CVE-2026-658356.6 MED
9.1%
3Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guard used by NamespacedItems, allowing a Tenant Owner to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration through the cluster-admin controller client. This issue is fixed in version 0.13.8.9d
CVE-2024-39732
9.1%
3
CVE-2020-0408
9.1%
3
CVE-2025-22173
9.1%
3
CVE-2025-48994
9.1%
3
CVE-2018-11295
9.1%
3
CVE-2019-10524
9.1%
3
CVE-2024-449948.8 HIG
9.1%
3In the Linux kernel, the following vulnerability has been resolved: iommu: Restore lost return in iommu_report_device_fault() When iommu_report_device_fault gets called with a partial fault it is supposed to collect the fault into the group and then return. Instead the return was accidently deleted which results in trying to process the fault and an eventual crash. Deleting the return was a typo, put it back.6d
CVE-2025-22178
9.1%
3
CVE-2024-35011
9.1%
3
CVE-2025-4284
9.1%
3
CVE-2024-38341
9.1%
3
CVE-2025-22172
9.1%
3
CVE-2019-10491
9.1%
3