PULSE
LIVE8signals / 24h
FEED
ransompanzer reclama a Daily Trust · NG · Otherransomqilin reclama a Impact Centre Chrétien · HT · Otherransomincransom reclama a Louisville Bar Association · US · Professional Servicesransomqilin reclama a Clausing · DE · Manufacturingransomqilin reclama a CLLS Co Ltd · SG · Not Foundransomstorm reclama a United Group of Companies · US · Otherransomstorm reclama a Sawyer Savings Bank · US · Financial Servicesransombravox reclama a MEDICOS · FR · Healthcareransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Servicesransompanzer reclama a Daily Trust · NG · Otherransomqilin reclama a Impact Centre Chrétien · HT · Otherransomincransom reclama a Louisville Bar Association · US · Professional Servicesransomqilin reclama a Clausing · DE · Manufacturingransomqilin reclama a CLLS Co Ltd · SG · Not Foundransomstorm reclama a United Group of Companies · US · Otherransomstorm reclama a Sawyer Savings Bank · US · Financial Servicesransombravox reclama a MEDICOS · FR · Healthcareransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Services
CVE Watch356,679 in full archive

Vulnerabilities exploitable today

356,679in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,534
  • High
    10,642
  • Medium
    6,742
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities327,321–327,360 · 356,679
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49964
8.1%
2
CVE-2024-33396
8.1%
2
CVE-2024-31109
8.1%
2
CVE-2025-12086
8.1%
2
CVE-2026-56376
8.1%
2
CVE-2022-50037
8.1%
2
CVE-2023-32554
8.1%
2
CVE-2017-18330
8.1%
2
CVE-2023-53710
8.1%
2
CVE-2025-2762
8.1%
2
CVE-2019-25315
8.1%
2
CVE-2024-51223
8.1%
2
CVE-2025-62845
8.1%
2
CVE-2022-42277
8.1%
2
CVE-2024-0245
8.1%
2
CVE-2025-12169
8.1%
2
CVE-2026-655177.1 HIG
8.1%
2Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.2d
CVE-2025-25334
8.1%
2
CVE-2025-38324
8.1%
2
CVE-2025-12751
8.1%
2
CVE-2026-42180
8.1%
2
CVE-2025-23179
8.1%
2
CVE-2026-177285.4 MED
8.1%
2Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)9d
CVE-2023-32555
8.1%
2
CVE-2026-24433
8.1%
2
CVE-2026-53536
8.1%
2Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined with a missing null-check on the decoded fileId, this allowed any caller holding any valid Activepieces JWT (including a freshly created user's own access token) to receive a step-file belonging to another tenant. The file returned was whatever PostgreSQL happened to scan first for type = FLOW_STEP_FILE, varying over time as the database changed, so an authenticated user could obtain step-file attachments belonging to other tenants on the same instance; the attacker could not target a specific victim or file, and the access was read-only with no integrity or availability impact. This issue is fixed in version 0.83.0.22d
CVE-2023-0221
8.1%
2
CVE-2024-31154
8.1%
2
CVE-2025-4294
8.1%
2
CVE-2026-503617.8 HIG
8.1%
2Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.17d
CVE-2025-12022
8.1%
2
CVE-2024-21801
8.1%
2
CVE-2025-12577
8.1%
2
CVE-2026-667015.3 MED
8.1%
2Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.20h
CVE-2021-39670
8.1%
2
CVE-2025-68331
8.1%
2
CVE-2022-50016
8.1%
2
CVE-2024-25630
8.1%
2
CVE-2026-454877.8 HIG
8.1%
2Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.17d
CVE-2026-666995.3 MED
8.1%
2Custom role Broken Access Control in Dokan <= 5.0.10 versions.2d