PULSE
LIVE12signals / 24h
FEED
ransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomsilentransomgroup reclama a Moses & Singer · US · Professional Servicesransomkrybit reclama a www.buzztrading104.co.za · ZA · Financial Servicesransomqilin reclama a Wire Products · US · Manufacturingransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomplay reclama a Sigma Plastics Group · US · Manufacturingransomplay reclama a Cambridge Management · US · Professional Servicesransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomkrybit reclama a www.dcpartner.co.za · ZA · Professional Servicesransomkrybit reclama a nigeria.asa-international.com · NG · Professional Servicesransomkrybit reclama a www.ville-rinxent.fr · FR · Government & Defenseransomkrybit reclama a countrymotors.com.mx · MX · Retail & E-Commerceransomsilentransomgroup reclama a Moses & Singer · US · Professional Servicesransomkrybit reclama a www.buzztrading104.co.za · ZA · Financial Servicesransomqilin reclama a Wire Products · US · Manufacturingransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomplay reclama a Sigma Plastics Group · US · Manufacturingransomplay reclama a Cambridge Management · US · Professional Servicesransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Services
CVE Watch354,867 in full archive

Vulnerabilities exploitable today

354,867in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,555
  • High
    9,167
  • Medium
    7,432
  • Low
    691
Filters

Window

Severity

Flags

Vulnerabilities333,121–333,160 · 354,867
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44659
6.1%
2
CVE-2023-53765
6.1%
2
CVE-2025-41392
6.1%
2
CVE-2025-38185
6.1%
2
CVE-2025-6923
6.1%
2
CVE-2025-40287
6.1%
2
CVE-2023-53134
6.1%
2
CVE-2026-470112.6 LOW
6.1%
2Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).10d
CVE-2024-34595
6.1%
2
CVE-2025-4198
6.1%
2
CVE-2025-13955
6.1%
2
CVE-2026-32891
6.1%
2
CVE-2025-30919
6.1%
2
CVE-2024-11263
6.1%
2
CVE-2023-53750
6.1%
2
CVE-2024-20832
6.1%
2
CVE-2025-37790
6.1%
2
CVE-2026-28678
6.1%
2Rejected reason: Further research determined the issue is not a vulnerability.33d
CVE-2020-0115
6.1%
2
CVE-2025-20935
6.1%
2
CVE-2025-38109
6.1%
2
CVE-2026-656965.4 MED
6.1%
2Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing ownership check in the affected handlers to access target user records without the filteredFields filter, leaking sensitive data including email addresses and plexId values.10d
CVE-2024-13522
6.1%
2
CVE-2025-40289
6.1%
2
CVE-2024-43866
6.1%
2
CVE-2025-12575
6.1%
2
CVE-2019-11341
6.1%
2
CVE-2024-9450
6.1%
2
CVE-2022-38707
6.1%
2
CVE-2023-43079
6.1%
2
CVE-2025-20882
6.1%
2
CVE-2025-2098
6.1%
2
CVE-2026-151465.9 MED
6.1%
2GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.18d
CVE-2025-6241
6.1%
2
CVE-2024-235704.3 MED
6.1%
2HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.16d
CVE-2025-34180
6.1%
2
CVE-2023-53358
6.1%
2
CVE-2023-53806
6.1%
2
CVE-2025-52713
6.1%
2
CVE-2024-48842
6.1%
2