PULSE
LIVE22signals / 24h
FEED
ransomincransom reclama a pushidrosal.id · ID · Otherransomincransom reclama a lccgroup.com · PH · Professional Servicesransomincransom reclama a https://geleximco.vn/ · VN · Manufacturingransomincransom reclama a clintonhealthaccess.org · US · Healthcareransomincransom reclama a Oleoductos del Valle · AR · Energy & Utilitiesransomsafepay reclama a pradotuylaw.com · US · Professional Servicesransomsafepay reclama a naskdoorinc.com · US · Manufacturingransomsafepay reclama a new-point.it · IT · Technologyransomsafepay reclama a simonrack.com · ES · Manufacturingransomsafepay reclama a hanan-hov.co.il · IL · Otherransomanubis reclama a BLACKBURN'S · US · Healthcareransomanubis reclama a Cameron Regional Medical Center · US · Healthcareransomsafepay reclama a azn.co.jp · JP · Retail & E-Commerceransomsafepay reclama a southshorerecycling.com · US · Manufacturingransomincransom reclama a pushidrosal.id · ID · Otherransomincransom reclama a lccgroup.com · PH · Professional Servicesransomincransom reclama a https://geleximco.vn/ · VN · Manufacturingransomincransom reclama a clintonhealthaccess.org · US · Healthcareransomincransom reclama a Oleoductos del Valle · AR · Energy & Utilitiesransomsafepay reclama a pradotuylaw.com · US · Professional Servicesransomsafepay reclama a naskdoorinc.com · US · Manufacturingransomsafepay reclama a new-point.it · IT · Technologyransomsafepay reclama a simonrack.com · ES · Manufacturingransomsafepay reclama a hanan-hov.co.il · IL · Otherransomanubis reclama a BLACKBURN'S · US · Healthcareransomanubis reclama a Cameron Regional Medical Center · US · Healthcareransomsafepay reclama a azn.co.jp · JP · Retail & E-Commerceransomsafepay reclama a southshorerecycling.com · US · Manufacturing
CVE Watch355,177 in full archive

Vulnerabilities exploitable today

355,177in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,498
  • High
    9,083
  • Medium
    7,310
  • Low
    690
Filters

Window

Severity

Flags

Vulnerabilities330,441–330,480 · 355,177
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-0999
6.9%
2
CVE-2022-50933
6.9%
2
CVE-2025-36600
6.9%
2
CVE-2026-565843.7 LOW
6.9%
2HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.5d
CVE-2025-13127
6.9%
2
CVE-2026-396045.9 MED
6.9%
2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.10d
CVE-2026-180034.3 MED
6.9%
2Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)11h
CVE-2025-41432
6.9%
2
CVE-2026-584025.4 MED
6.9%
2Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.27d
CVE-2024-22037
6.9%
2
CVE-2022-46824
6.9%
2
CVE-2024-26708
6.9%
2
CVE-2023-54288
6.9%
2
CVE-2025-21657
6.9%
2
CVE-2026-32509
6.9%
2
CVE-2021-37692
6.9%
2
CVE-2022-34423
6.9%
2
CVE-2025-59110
6.9%
2
CVE-2026-46356.5 MED
6.9%
2Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel.. Mattermost Advisory ID: MMSA-2026-0063712d
CVE-2022-34406
6.9%
2
CVE-2026-0930
6.9%
2
CVE-2020-37167
6.8%
2
CVE-2026-21939
6.8%
2
CVE-2026-555424.3 MED
6.8%
2Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file branch. Version 8.6.1 contains a patch.24d
CVE-2023-53720
6.8%
2
CVE-2024-9002
6.8%
2
CVE-2022-3990
6.8%
2
CVE-2024-52543
6.8%
2
CVE-2024-52898
6.8%
2
CVE-2025-43403
6.8%
2
CVE-2026-31826
6.8%
2
CVE-2026-0499
6.8%
2
CVE-2026-456844.9 MED
6.8%
2OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy length. When log injection is enabled, a crafted multi-segment writev call can make OBI read and overwrite memory beyond the first segment. This issue has been patched in version 0.9.0.12d
CVE-2026-141147.5 HIG
6.8%
2Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)29d
CVE-2026-31876
6.8%
2
CVE-2026-22713
6.8%
2
CVE-2025-62779
6.8%
2
CVE-2025-31076
6.8%
2
CVE-2026-624825.4 MED
6.8%
2Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).6d
CVE-2025-46277
6.8%
2