PULSE
LIVE16signals / 24h
FEED
ransomsafepay reclama a azn.co.jp · JP · Retail & E-Commerceransomsafepay reclama a southshorerecycling.com · US · Manufacturingransomsafepay reclama a cpu-ag.com · DE · Manufacturingransomsafepay reclama a multiaqua.com · US · Agriculture and Food Productionransomanubis reclama a Winn-Dixie · US · Retail & E-Commerceransomanubis reclama a BLACKBURN'S Physicians Pharmacy, Inc. · US · Healthcareransomqilin reclama a Service Electric · US · Energy & Utilitiesransomakira reclama a Albers Mechanical Contractors · US · Manufacturingransomakira reclama a Belasco Electric · Energy & Utilitiesransomdragonforce reclama a TUI China · CN · Hospitalityransompayload reclama a Hans & Jos. Kronenberg GmbH · DE · Manufacturingransomqilin reclama a Freedom Claims Management · US · Financial Servicesransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomsafepay reclama a azn.co.jp · JP · Retail & E-Commerceransomsafepay reclama a southshorerecycling.com · US · Manufacturingransomsafepay reclama a cpu-ag.com · DE · Manufacturingransomsafepay reclama a multiaqua.com · US · Agriculture and Food Productionransomanubis reclama a Winn-Dixie · US · Retail & E-Commerceransomanubis reclama a BLACKBURN'S Physicians Pharmacy, Inc. · US · Healthcareransomqilin reclama a Service Electric · US · Energy & Utilitiesransomakira reclama a Albers Mechanical Contractors · US · Manufacturingransomakira reclama a Belasco Electric · Energy & Utilitiesransomdragonforce reclama a TUI China · CN · Hospitalityransompayload reclama a Hans & Jos. Kronenberg GmbH · DE · Manufacturingransomqilin reclama a Freedom Claims Management · US · Financial Servicesransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Services
CVE Watch355,082 in full archive

Vulnerabilities exploitable today

355,082in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,578
  • High
    9,224
  • Medium
    7,476
  • Low
    696
Filters

Window

Severity

Flags

Vulnerabilities331,281–331,320 · 355,082
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-4211
6.6%
2Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the use of the GetTempPath API, which can be exploited by attackers to manipulate temporary file paths, potentially leading to unauthorized access and privilege escalation. The affected public API in the Qt Framework is QDir::tempPath() and anything that uses it, such as QStandardPaths with TempLocation, QTemporaryDir, and QTemporaryFile. This issue affects all version of Qt up to and including 5.15.18, from 6.0.0 through 6.5.8, from 6.6.0 through 6.8.1. It is fixed in Qt 5.15.19, Qt 6.5.9, Qt 6.8.2, 6.9.05d
CVE-2026-578517.8 HIG
6.6%
2MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.24d
CVE-2019-2318
6.6%
2
CVE-2026-122715.4 MED
6.6%
2The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.21d
CVE-2024-57941
6.6%
2
CVE-2023-43591
6.6%
2
CVE-2023-48680
6.6%
2
CVE-2025-46543
6.6%
2
CVE-2023-23441
6.6%
2
CVE-2017-11078
6.6%
2
CVE-2024-8477
6.6%
2
CVE-2024-41776
6.6%
2
CVE-2025-43478
6.6%
2
CVE-2018-3573
6.6%
2
CVE-2025-0011
6.6%
2
CVE-2026-28713
6.6%
2
CVE-2025-46333
6.6%
2
CVE-2026-22006
6.6%
2
CVE-2023-53554
6.6%
2
CVE-2026-466285.4 MED
6.6%
2Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.19d
CVE-2025-49076
6.6%
2
CVE-2025-49075
6.6%
2
CVE-2025-156536.8 MED
6.6%
2Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy functions, manipulate device-processed data, or leverage the device as a pivot point for broader network-based attacks when connected to a network or Dräger Service Connect.12d
CVE-2024-12902
6.6%
2
CVE-2024-20824
6.6%
2
CVE-2025-24495
6.6%
2
CVE-2025-48113
6.6%
2
CVE-2026-116913.1 LOW
6.6%
2Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)11d
CVE-2025-61994
6.6%
2
CVE-2026-5940
6.6%
2
CVE-2026-477305.4 MED
6.6%
2Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.13d
CVE-2023-28089
6.6%
2
CVE-2026-563663.3 LOW
6.6%
2ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.21d
CVE-2025-49919
6.6%
2
CVE-2024-20823
6.6%
2
CVE-2026-26345
6.6%
2
CVE-2026-7581
6.6%
2
CVE-2025-5040
6.6%
2
CVE-2024-32485
6.6%
2
CVE-2025-656215.4 MED
6.6%
2Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.30d