PULSE
LIVE13signals / 24h
FEED
ransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomplay reclama a Sigma Plastics Group · US · Manufacturingransomplay reclama a Cambridge Management · US · Professional Servicesransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomqilin reclama a The Saturday Evening Post · US · Otherransomqilin reclama a Commercial Furniture Interiors · US · Retail & E-Commerceransomqilin reclama a Dienst Pack Systems · DE · Manufacturingransomqilin reclama a Ceragres · CA · Manufacturingransomqilin reclama a Pointe Property Group · US · Otherransomqilin reclama a Schreiner Trockenbau GmbH · AT · Manufacturingransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Co) · SA · Otherransomcrpxo reclama a Encore Enterprises, Inc. · US · Otherransomthegentlemen reclama a Philippine Savings Bank · PH · Financial Servicesransomplay reclama a The Butcher Brothers · US · Retail & E-Commerceransomplay reclama a Sigma Plastics Group · US · Manufacturingransomplay reclama a Cambridge Management · US · Professional Servicesransomincransom reclama a quantinuum.com · US · Technologyransomglobal secret group reclama a Vernon & Waldrep · US · Professional Servicesransomqilin reclama a The Saturday Evening Post · US · Otherransomqilin reclama a Commercial Furniture Interiors · US · Retail & E-Commerceransomqilin reclama a Dienst Pack Systems · DE · Manufacturingransomqilin reclama a Ceragres · CA · Manufacturingransomqilin reclama a Pointe Property Group · US · Otherransomqilin reclama a Schreiner Trockenbau GmbH · AT · Manufacturingransomgammax reclama a MTCO (Mahmoud Altaheni & Partners Trading Co) · SA · Other
CVE Watch354,835 in full archive

Vulnerabilities exploitable today

354,835in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,555
  • High
    9,167
  • Medium
    7,427
  • Low
    691
Filters

Window

Severity

Flags

Vulnerabilities333,481–333,520 · 354,835
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-369568.8 HIG
5.9%
2A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.28d
CVE-2025-59399
5.9%
2
CVE-2025-31976
5.9%
2
CVE-2026-3387
5.9%
2
CVE-2022-39878
5.9%
2
CVE-2026-58225
5.9%
2
CVE-2026-574136.4 MED
5.9%
2Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.20d
CVE-2020-0375
5.9%
2
CVE-2025-52936
5.9%
2Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.16h
CVE-2024-29951
5.9%
2
CVE-2020-0374
5.9%
2
CVE-2026-6386
5.9%
2
CVE-2026-45918
5.9%
2
CVE-2026-153927.7 HIG
5.9%
2DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.18d
CVE-2026-9595
5.9%
2
CVE-2026-41030
5.9%
2
CVE-2025-68324
5.9%
2
CVE-2025-37731
5.9%
2
CVE-2025-68334
5.9%
2
CVE-2025-12586
5.9%
2
CVE-2026-24964
5.9%
2
CVE-2024-52548
5.9%
2
CVE-2026-58465.7 MED
5.9%
2The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.2d
CVE-2024-52541
5.9%
2
CVE-2025-53456
5.9%
2
CVE-2023-36160
5.9%
2
CVE-2025-15641
5.9%
2
CVE-2024-21829
5.9%
2
CVE-2025-11772
5.9%
2
CVE-2025-55043
5.9%
2
CVE-2025-38548
5.9%
2
CVE-2024-37387
5.9%
2
CVE-2026-8369
5.9%
2
CVE-2026-3384
5.9%
2
CVE-2026-12779
5.9%
2
CVE-2026-20614
5.9%
2
CVE-2025-46547
5.9%
2
CVE-2026-12780
5.9%
2
CVE-2023-6939
5.9%
2
CVE-2018-253558.4 HIG
5.9%
2Audiograbber 1.83 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious input in the Interpret or Album fields that triggers a buffer overflow, overwriting SEH pointers and executing injected shellcode with application privileges.10d