PULSE
LIVE13signals / 24h
FEED
ransompayload reclama a Hans & Jos. Kronenberg GmbH · DE · Manufacturingransomqilin reclama a Freedom Claims Management · US · Financial Servicesransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomqilin reclama a INTERTRUST AUSTRALIA PTY LTD · AU · Professional Servicesransomqilin reclama a Asset Flooring Group Australia · AU · Retail & E-Commerceransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomsilentransomgroup reclama a Moses & Singer · US · Professional Servicesransomkrybit reclama a www.buzztrading104.co.za · ZA · Financial Servicesransomqilin reclama a Wire Products · US · Manufacturingransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransompayload reclama a Hans & Jos. Kronenberg GmbH · DE · Manufacturingransomqilin reclama a Freedom Claims Management · US · Financial Servicesransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomqilin reclama a INTERTRUST AUSTRALIA PTY LTD · AU · Professional Servicesransomqilin reclama a Asset Flooring Group Australia · AU · Retail & E-Commerceransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomsilentransomgroup reclama a Moses & Singer · US · Professional Servicesransomkrybit reclama a www.buzztrading104.co.za · ZA · Financial Servicesransomqilin reclama a Wire Products · US · Manufacturingransomcrpxo reclama a Encore Enterprises, Inc. · US · Other
CVE Watch354,883 in full archive

Vulnerabilities exploitable today

354,883in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,556
  • High
    9,177
  • Medium
    7,435
  • Low
    692
Filters

Window

Severity

Flags

Vulnerabilities332,201–332,240 · 354,883
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-403317.8 HIG
6.3%
2In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the following path not holding the sock lock, sctp_diag_dump() -> sctp_for_each_endpoint() -> sctp_ep_dump() make sure not to exceed bounds in case the address list has grown between buffer allocation (time-of-check) and write (time-of-use).4d
CVE-2026-27234
6.3%
2
CVE-2025-38699
6.3%
2
CVE-2026-27235
6.3%
2
CVE-2026-48861
6.3%
2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices the caller-supplied method and target arguments directly into the HTTP/1 request line without any character validation: [method, ?\s, target, " HTTP/1.1\r\n"]. An application that forwards attacker-controlled input as the HTTP method or target to Mint.HTTP.request/5 is therefore exposed to request-line CRLF injection: the attacker can terminate the request line early, inject arbitrary headers, and smuggle an entirely separate pipelined HTTP request onto the same TCP connection. Mint 1.7.0 introduced validate_request_target/2, which rejects CRLF and other control characters in the target by default and closes the path/query vector unless the caller opts out via skip_target_validation: true. The method field remains unvalidated, so the method-based injection is exploitable under the default Mint configuration on all versions. This issue affects mint: from 0.1.0 before 1.9.0.11d
CVE-2022-37336
6.3%
2
CVE-2017-6293
6.3%
2
CVE-2026-600735.9 MED
6.3%
2An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a system crash or disclosure of kernel memory.16d
CVE-2025-20255
6.3%
2
CVE-2026-27239
6.3%
2
CVE-2026-353905.4 MED
6.3%
2Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header. This means cross-site scripting (XSS) attacks were logged but not blocked. Any user who could inject script content (e.g., via crafted email HTML) could execute arbitrary JavaScript in the context of the application, potentially stealing session tokens or performing actions on behalf of the user. This vulnerability is fixed in 1.4.11.9d
CVE-2025-48796
6.3%
2
CVE-2026-27232
6.3%
2
CVE-2026-27237
6.3%
2
CVE-2017-15844
6.3%
2
CVE-2026-6915
6.3%
2
CVE-2026-33361
6.3%
2
CVE-2025-62982
6.3%
2
CVE-2020-36994
6.3%
2
CVE-2022-40708
6.3%
2
CVE-2026-6553
6.3%
2
CVE-2025-55159
6.3%
2
CVE-2026-27249
6.3%
2
CVE-2024-2208
6.3%
2
CVE-2025-67875
6.3%
2
CVE-2025-13751
6.3%
2
CVE-2021-25361
6.3%
2
CVE-2026-27242
6.3%
2
CVE-2026-3340
6.3%
2
CVE-2025-68950
6.3%
2
CVE-2022-20504
6.3%
2
CVE-2025-68386
6.3%
2
CVE-2025-67983
6.3%
2
CVE-2023-47717
6.3%
2
CVE-2025-59889
6.3%
2
CVE-2025-62731
6.3%
2
CVE-2026-27257
6.3%
2
CVE-2026-27251
6.3%
2
CVE-2025-36375
6.3%
2
CVE-2026-27247
6.3%
2