PULSE
LIVE18signals / 24h
FEED
ransomplay reclama a MIE Solutions · GB · Professional Servicesransomplay reclama a Rilpa Enterprises · Not Foundransomplay reclama a Marconi Industrial Services · IT · Manufacturingransomqilin reclama a Synergy Interactive · US · Technologyransomqilin reclama a Energetic Development Corp · TW · Energy & Utilitiesransomqilin reclama a Panda Logistics Taichung Branch · TW · Transportationransomqilin reclama a East Field Corporation · JP · Agriculture and Food Productionransomqilin reclama a Chun Tai Sing Chemical Industry · HK · Manufacturingransomqilin reclama a pm-energy Die Solarexperten · DE · Energy & Utilitiesransomunsafe reclama a Constellation HomeBuilder Systems · US · Manufacturingransomqilin reclama a Harplast SRL · RO · Manufacturingransomqilin reclama a Price Shoes · MX · Retail & E-Commerceransomqilin reclama a Naval Interior Team · FI · Government & Defenseransomqilin reclama a Phithan Phanich · TH · Manufacturingransomplay reclama a MIE Solutions · GB · Professional Servicesransomplay reclama a Rilpa Enterprises · Not Foundransomplay reclama a Marconi Industrial Services · IT · Manufacturingransomqilin reclama a Synergy Interactive · US · Technologyransomqilin reclama a Energetic Development Corp · TW · Energy & Utilitiesransomqilin reclama a Panda Logistics Taichung Branch · TW · Transportationransomqilin reclama a East Field Corporation · JP · Agriculture and Food Productionransomqilin reclama a Chun Tai Sing Chemical Industry · HK · Manufacturingransomqilin reclama a pm-energy Die Solarexperten · DE · Energy & Utilitiesransomunsafe reclama a Constellation HomeBuilder Systems · US · Manufacturingransomqilin reclama a Harplast SRL · RO · Manufacturingransomqilin reclama a Price Shoes · MX · Retail & E-Commerceransomqilin reclama a Naval Interior Team · FI · Government & Defenseransomqilin reclama a Phithan Phanich · TH · Manufacturing
CVE Watch356,768 in full archive

Vulnerabilities exploitable today

356,768in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,532
  • High
    10,540
  • Medium
    6,708
  • Low
    668
Filters

Window

Severity

Flags

Vulnerabilities324,281–324,320 · 356,768
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-49274
9.0%
3
CVE-2026-35625
9.0%
3
CVE-2025-45091
9.0%
3
CVE-2024-8781
9.0%
3
CVE-2023-54123
9.0%
3
CVE-2023-53343
9.0%
3
CVE-2020-11123
9.0%
3
CVE-2019-25554
9.0%
3
CVE-2026-27918
9.0%
3
CVE-2026-35068
9.0%
3
CVE-2017-9498
9.0%
3
CVE-2025-6258
9.0%
3
CVE-2025-5532
9.0%
3
CVE-2025-41080
9.0%
3
CVE-2023-54114
9.0%
3
CVE-2021-29601
9.0%
3
CVE-2024-2858
9.0%
3
CVE-2025-62963
9.0%
3
CVE-2022-30715
9.0%
3
CVE-2025-5539
9.0%
3
CVE-2025-62943
9.0%
3
CVE-2024-3993
9.0%
3
CVE-2025-62641
9.0%
3
CVE-2025-50061
9.0%
3
CVE-2023-28091
9.0%
3
CVE-2024-8256
9.0%
3
CVE-2025-5686
9.0%
3
CVE-2026-122615.3 MED
9.0%
3A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active through ordinary NLTK APIs. This issue persists across fresh interpreter restarts and can affect downstream workflows, including machine learning pipelines and reproducibility-sensitive environments.3d
CVE-2024-35039
9.0%
3
CVE-2025-22638
9.0%
3
CVE-2026-177365.8 MED
9.0%
3Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)7d
CVE-2026-76626.4 MED
9.0%
3The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed` shortcode in all versions up to, and including, 1. This is due to insufficient input sanitization and output escaping on the shortcode attribute which is injected directly into inline JavaScript. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.18d
CVE-2026-88806.4 MED
9.0%
3The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the romancart_button shortcode in versions up to, and including, 2.0.8. This is due to insufficient input sanitization and output escaping on user supplied attributes within the romancart_button_shortcode() function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.18d
CVE-2026-598028.2 HIG
9.0%
3PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.26d
CVE-2025-5534
9.0%
3
CVE-2023-21444
9.0%
3
CVE-2026-118896.5 MED
9.0%
3SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product.23d
CVE-2025-22026
9.0%
3
CVE-2025-5533
9.0%
3
CVE-2018-11270
9.0%
3