PULSE
LIVE7signals / 24h
FEED
ransomqilin reclama a Impact Centre Chrétien · HT · Otherransomincransom reclama a Louisville Bar Association · US · Professional Servicesransomqilin reclama a Clausing · DE · Manufacturingransomqilin reclama a CLLS Co Ltd · SG · Not Foundransomstorm reclama a United Group of Companies · US · Otherransomstorm reclama a Sawyer Savings Bank · US · Financial Servicesransombravox reclama a MEDICOS · FR · Healthcareransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Servicesransomqilin reclama a John C Saunders, CPA · US · Professional Servicesransomqilin reclama a Impact Centre Chrétien · HT · Otherransomincransom reclama a Louisville Bar Association · US · Professional Servicesransomqilin reclama a Clausing · DE · Manufacturingransomqilin reclama a CLLS Co Ltd · SG · Not Foundransomstorm reclama a United Group of Companies · US · Otherransomstorm reclama a Sawyer Savings Bank · US · Financial Servicesransombravox reclama a MEDICOS · FR · Healthcareransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Servicesransomqilin reclama a John C Saunders, CPA · US · Professional Services
CVE Watch356,679 in full archive

Vulnerabilities exploitable today

356,679in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605

Distribution · last window

  • Critical
    2,538
  • High
    10,671
  • Medium
    6,789
  • Low
    678
Filters

Window

Severity

Flags

Vulnerabilities327,801–327,840 · 356,679
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-01286.5 MED
8.0%
2In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.33d
CVE-2026-43981
8.0%
2
CVE-2026-354736.1 MED
8.0%
2WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IentradaControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.15d
CVE-2024-38557
8.0%
2
CVE-2026-562404.3 MED
8.0%
2Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion.26d
CVE-2025-24516
8.0%
2
CVE-2024-39283
8.0%
2
CVE-2024-54550
8.0%
2
CVE-2025-43262
8.0%
2
CVE-2025-3082
8.0%
2
CVE-2025-40773
8.0%
2
CVE-2025-59824
8.0%
2
CVE-2024-37941
8.0%
2
CVE-2026-648234.7 MED
8.0%
2Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against an image-only allowlist. Attackers can cause the media player proxy endpoint to serve attacker-controlled bytes with Content-Type text/html in the Home Assistant web origin, enabling theft of session tokens from local storage and authenticated calls to sensitive service endpoints including lock, alarm, and cover controls.17d
CVE-2026-156157.5 HIG
8.0%
2Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.12d
CVE-2025-1939
8.0%
2
CVE-2023-42830
8.0%
2
CVE-2025-49333
8.0%
2
CVE-2025-55713
8.0%
2
CVE-2025-66498
8.0%
2
CVE-2024-41885
8.0%
2
CVE-2026-419896.7 MED
8.0%
2Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.25d
CVE-2020-0399
8.0%
2
CVE-2024-42231
8.0%
2
CVE-2021-38121
8.0%
2
CVE-2024-12484.8 MED
8.0%
2The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.30d
CVE-2023-50821
8.0%
2
CVE-2025-71326
8.0%
2
CVE-2025-42936
8.0%
2
CVE-2025-21973
8.0%
2
CVE-2026-26291
8.0%
2
CVE-2024-37938
8.0%
2
CVE-2025-70297
8.0%
2
CVE-2024-37939
8.0%
2
CVE-2024-51679
8.0%
2
CVE-2025-57890
8.0%
2
CVE-2021-22458
8.0%
2
CVE-2026-110346.1 MED
8.0%
2Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)17d
CVE-2026-41479
8.0%
2
CVE-2024-27363
8.0%
2