PULSE
LIVE8signals / 24h
FEED
ransompanzer reclama a Daily Trust · NG · Otherransomqilin reclama a Impact Centre Chrétien · HT · Otherransomincransom reclama a Louisville Bar Association · US · Professional Servicesransomqilin reclama a Clausing · DE · Manufacturingransomqilin reclama a CLLS Co Ltd · SG · Not Foundransomstorm reclama a United Group of Companies · US · Otherransomstorm reclama a Sawyer Savings Bank · US · Financial Servicesransombravox reclama a MEDICOS · FR · Healthcareransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Servicesransompanzer reclama a Daily Trust · NG · Otherransomqilin reclama a Impact Centre Chrétien · HT · Otherransomincransom reclama a Louisville Bar Association · US · Professional Servicesransomqilin reclama a Clausing · DE · Manufacturingransomqilin reclama a CLLS Co Ltd · SG · Not Foundransomstorm reclama a United Group of Companies · US · Otherransomstorm reclama a Sawyer Savings Bank · US · Financial Servicesransombravox reclama a MEDICOS · FR · Healthcareransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Services
CVE Watch356,679 in full archive

Vulnerabilities exploitable today

356,679in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,534
  • High
    10,642
  • Medium
    6,742
  • Low
    670
Filters

Window

Severity

Flags

Vulnerabilities327,361–327,400 · 356,679
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-503858.8 HIG
8.1%
2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.17d
CVE-2026-504277.8 HIG
8.1%
2Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.17d
CVE-2025-21688
8.1%
2
CVE-2025-64736
8.1%
2
CVE-2023-4028
8.1%
2
CVE-2026-8561
8.1%
2
CVE-2022-41749
8.1%
2
CVE-2026-25306
8.1%
2
CVE-2026-30979
8.1%
2
CVE-2026-504577.8 HIG
8.1%
2Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.17d
CVE-2022-42276
8.1%
2
CVE-2025-2630
8.1%
2
CVE-2026-648807.1 HIG
8.1%
2Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.17d
CVE-2022-23817
8.1%
2
CVE-2023-34419
8.1%
2
CVE-2025-38037
8.1%
2
CVE-2025-2629
8.1%
2
CVE-2023-4029
8.1%
2
CVE-2024-38864
8.1%
2
CVE-2024-2313
8.1%
2
CVE-2026-12450
8.1%
2
CVE-2025-20117
8.1%
2
CVE-2026-42341
8.1%
2FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.32d
CVE-2026-541257.8 HIG
8.1%
2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.18d
CVE-2024-51440
8.1%
2
CVE-2022-49962
8.1%
2
CVE-2024-34367
8.1%
2
CVE-2024-31105
8.1%
2
CVE-2022-34147
8.1%
2
CVE-2024-56666
8.1%
2
CVE-2021-3722
8.1%
2
CVE-2025-25183
8.1%
2
CVE-2024-51225
8.1%
2
CVE-2025-25329
8.1%
2
CVE-2026-177345.4 MED
8.1%
2Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)9d
CVE-2025-46276
8.1%
2
CVE-2025-25326
8.1%
2
CVE-2024-31285
8.1%
2
CVE-2026-31989
8.1%
2
CVE-2026-26276
8.1%
2