PULSE
LIVE10signals / 24h
FEED
ransomqilin reclama a Service Electric · US · Energy & Utilitiesransomakira reclama a Albers Mechanical Contractors · US · Manufacturingransomakira reclama a Belasco Electric · Energy & Utilitiesransomdragonforce reclama a TUI China · CN · Hospitalityransompayload reclama a Hans & Jos. Kronenberg GmbH · DE · Manufacturingransomqilin reclama a Freedom Claims Management · US · Financial Servicesransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomqilin reclama a INTERTRUST AUSTRALIA PTY LTD · AU · Professional Servicesransomqilin reclama a Asset Flooring Group Australia · AU · Retail & E-Commerceransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomqilin reclama a Service Electric · US · Energy & Utilitiesransomakira reclama a Albers Mechanical Contractors · US · Manufacturingransomakira reclama a Belasco Electric · Energy & Utilitiesransomdragonforce reclama a TUI China · CN · Hospitalityransompayload reclama a Hans & Jos. Kronenberg GmbH · DE · Manufacturingransomqilin reclama a Freedom Claims Management · US · Financial Servicesransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomqilin reclama a INTERTRUST AUSTRALIA PTY LTD · AU · Professional Servicesransomqilin reclama a Asset Flooring Group Australia · AU · Retail & E-Commerceransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerce
CVE Watch355,017 in full archive

Vulnerabilities exploitable today

355,017in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,558
  • High
    9,191
  • Medium
    7,449
  • Low
    695
Filters

Window

Severity

Flags

Vulnerabilities331,481–331,520 · 355,017
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-562525.4 MED
6.6%
2Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their declared app boundary, bypassing the limited_to_apps authorization check.21d
CVE-2025-6689
6.6%
2
CVE-2021-4142
6.6%
2
CVE-2025-4701
6.6%
2
CVE-2023-38022
6.6%
2
CVE-2022-24410
6.6%
2
CVE-2022-41628
6.6%
2
CVE-2026-22183
6.6%
2
CVE-2024-51481
6.6%
2
CVE-2024-6405
6.6%
2
CVE-2022-43474
6.6%
2
CVE-2025-21084
6.6%
2
CVE-2025-712348.8 HIG
6.6%
2In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add The driver does not set hw->sta_data_size, which causes mac80211 to allocate insufficient space for driver private station data in __sta_info_alloc(). When rtl8xxxu_sta_add() accesses members of struct rtl8xxxu_sta_info through sta->drv_priv, this results in a slab-out-of-bounds write. KASAN report on RISC-V (VisionFive 2) with RTL8192EU adapter: BUG: KASAN: slab-out-of-bounds in rtl8xxxu_sta_add+0x31c/0x346 Write of size 8 at addr ffffffd6d3e9ae88 by task kworker/u16:0/12 Set hw->sta_data_size to sizeof(struct rtl8xxxu_sta_info) during probe, similar to how hw->vif_data_size is configured. This ensures mac80211 allocates sufficient space for the driver's per-station private data. Tested on StarFive VisionFive 2 v1.2A board.4d
CVE-2025-43294
6.6%
2
CVE-2025-4742
6.6%
2
CVE-2022-34157
6.6%
2
CVE-2022-32576
6.6%
2
CVE-2026-37337
6.6%
2
CVE-2025-47661
6.6%
2
CVE-2024-52870
6.6%
2
CVE-2026-37336
6.6%
2
CVE-2023-20582
6.6%
2
CVE-2026-482295.4 MED
6.6%
2Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into HTML form hidden input value attributes. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.11d
CVE-2025-23414
6.6%
2
CVE-2024-40035
6.6%
2
CVE-2022-41693
6.6%
2
CVE-2025-5585
6.6%
2
CVE-2025-4965
6.6%
2
CVE-2023-6363
6.6%
2
CVE-2022-20073
6.6%
2
CVE-2023-30760
6.6%
2
CVE-2026-398757.8 HIG
6.6%
2A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.5d
CVE-2026-31350
6.6%
2
CVE-2024-13943
6.6%
2
CVE-2026-482465.9 MED
6.6%
2Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys or session-bearing data in transit.11d
CVE-2026-673076.3 MED
6.6%
2Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document _id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.2d
CVE-2025-674077.3 HIG
6.6%
2Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.4d
CVE-2026-343844.5 MED
6.6%
2Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in the same file (which correctly validates the token), these three approval actions read their parameters from $_GET and perform irreversible state changes without any protection. An attacker who has submitted a pending registration can extract their own user UUID from the registration confirmation email URL, then trick any user with the rol_approve_users right into visiting a crafted URL that automatically approves the registration. This bypasses the manual registration approval workflow entirely. This issue has been patched in version 5.0.8.10d
CVE-2025-4740
6.6%
2
CVE-2026-26204
6.6%
2