PULSE
LIVE12signals / 24h
FEED
ransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomqilin reclama a INTERTRUST AUSTRALIA PTY LTD · AU · Professional Servicesransomqilin reclama a Asset Flooring Group Australia · AU · Retail & E-Commerceransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomsilentransomgroup reclama a Moses & Singer · US · Professional Servicesransomkrybit reclama a www.buzztrading104.co.za · ZA · Financial Servicesransomqilin reclama a Wire Products · US · Manufacturingransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomkrybit reclama a www.prohealth.sg · SG · Healthcareransomincransom reclama a ecfa.org · US · Professional Servicesransomqilin reclama a INTERTRUST AUSTRALIA PTY LTD · AU · Professional Servicesransomqilin reclama a Asset Flooring Group Australia · AU · Retail & E-Commerceransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomsilentransomgroup reclama a Moses & Singer · US · Professional Servicesransomkrybit reclama a www.buzztrading104.co.za · ZA · Financial Servicesransomqilin reclama a Wire Products · US · Manufacturingransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerce
CVE Watch354,882 in full archive

Vulnerabilities exploitable today

354,882in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,556
  • High
    9,177
  • Medium
    7,435
  • Low
    692
Filters

Window

Severity

Flags

Vulnerabilities332,641–332,680 · 354,882
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-34390
6.2%
2
CVE-2026-28714
6.2%
2
CVE-2021-1888
6.2%
2
CVE-2025-57880
6.2%
2
CVE-2025-20692
6.2%
2
CVE-2022-34391
6.2%
2
CVE-2026-7429
6.2%
2
CVE-2024-42245
6.2%
2
CVE-2026-38948
6.2%
2
CVE-2021-38422
6.2%
2
CVE-2019-25367
6.2%
2
CVE-2023-31028
6.2%
2
CVE-2020-3626
6.2%
2
CVE-2021-21559
6.2%
2
CVE-2019-20574
6.2%
2
CVE-2023-53125
6.2%
2
CVE-2025-37992
6.2%
2
CVE-2026-44473
6.2%
2
CVE-2026-35363
6.2%
2
CVE-2026-660305.4 MED
6.2%
2Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.5d
CVE-2025-384347.8 HIG
6.2%
2In the Linux kernel, the following vulnerability has been resolved: Revert "riscv: Define TASK_SIZE_MAX for __access_ok()" This reverts commit ad5643cf2f69 ("riscv: Define TASK_SIZE_MAX for __access_ok()"). This commit changes TASK_SIZE_MAX to be LONG_MAX to optimize access_ok(), because the previous TASK_SIZE_MAX (default to TASK_SIZE) requires some computation. The reasoning was that all user addresses are less than LONG_MAX, and all kernel addresses are greater than LONG_MAX. Therefore access_ok() can filter kernel addresses. Addresses between TASK_SIZE and LONG_MAX are not valid user addresses, but access_ok() let them pass. That was thought to be okay, because they are not valid addresses at hardware level. Unfortunately, one case is missed: get_user_pages_fast() happily accepts addresses between TASK_SIZE and LONG_MAX. futex(), for instance, uses get_user_pages_fast(). This causes the problem reported by Robert [1]. Therefore, revert this commit. TASK_SIZE_MAX is changed to the default: TASK_SIZE. This unfortunately reduces performance, because TASK_SIZE is more expensive to compute compared to LONG_MAX. But correctness first, we can think about optimization later, if required.4d
CVE-2026-45875
6.2%
2
CVE-2026-637524.3 MED
6.2%
2SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing to an existing edge id, causing the storage layer to silently overwrite the target record instead of rejecting the operation.11d
CVE-2025-14331
6.2%
2
CVE-2026-3389
6.2%
2
CVE-2022-34881
6.2%
2
CVE-2025-58205
6.2%
2
CVE-2022-20480
6.2%
2
CVE-2025-38200
6.2%
2
CVE-2026-27492
6.2%
2
CVE-2026-3388
6.2%
2
CVE-2025-12715
6.2%
2
CVE-2025-37748
6.2%
2
CVE-2026-242407.8 HIG
6.2%
2NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.31d
CVE-2024-56637
6.2%
2
CVE-2017-14893
6.2%
2
CVE-2024-27415
6.2%
2
CVE-2022-48685
6.2%
2
CVE-2026-660295.4 MED
6.2%
2Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Manage Clients or Manage Client Projects pages where client names are rendered unsanitized.5d
CVE-2026-655685.0 MED
6.2%
2Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.6d