PULSE
LIVE53signals / 24h
FEED
ransomcrpxo reclama a KUVEYT TURK · TR · Financial Servicesransomcrpxo reclama a FINANSBANK · TR · Financial Servicesransomcrpxo reclama a ANADOLUBANK · TR · Financial Servicesransomcrpxo reclama a THY · TR · Transportationransomcrpxo reclama a JOHNSON & JOHNSON · US · Healthcareransomcrpxo reclama a DOĞAN HOLDİNG · TR · Otherransomcrpxo reclama a ANADOLU SİGORTA · TR · Financial Servicesransomcrpxo reclama a HYUNDAI · KR · Manufacturingransomcrpxo reclama a ASELSAN · TR · Government & Defenseransomcrpxo reclama a A101 · TR · Retail & E-Commerceransomqilin reclama a Community Management Associates · US · Professional Servicesransomthegentlemen reclama a Las Cenizas · CL · Otherransomthegentlemen reclama a Kenaitze Indian Tribe · US · Government & Defenseransomthegentlemen reclama a Additive Manufacturing · US · Manufacturingransomcrpxo reclama a KUVEYT TURK · TR · Financial Servicesransomcrpxo reclama a FINANSBANK · TR · Financial Servicesransomcrpxo reclama a ANADOLUBANK · TR · Financial Servicesransomcrpxo reclama a THY · TR · Transportationransomcrpxo reclama a JOHNSON & JOHNSON · US · Healthcareransomcrpxo reclama a DOĞAN HOLDİNG · TR · Otherransomcrpxo reclama a ANADOLU SİGORTA · TR · Financial Servicesransomcrpxo reclama a HYUNDAI · KR · Manufacturingransomcrpxo reclama a ASELSAN · TR · Government & Defenseransomcrpxo reclama a A101 · TR · Retail & E-Commerceransomqilin reclama a Community Management Associates · US · Professional Servicesransomthegentlemen reclama a Las Cenizas · CL · Otherransomthegentlemen reclama a Kenaitze Indian Tribe · US · Government & Defenseransomthegentlemen reclama a Additive Manufacturing · US · Manufacturing
CVE Watch354,684 in full archive

Vulnerabilities exploitable today

354,684in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,622
  • High
    9,423
  • Medium
    7,591
  • Low
    711
Filters

Window

Severity

Flags

Vulnerabilities335,921–335,960 · 354,684
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-35207
5.2%
2
CVE-2026-45973
5.2%
2
CVE-2026-5026
5.2%
2
CVE-2017-9689
5.2%
2
CVE-2025-38417
5.2%
2
CVE-2026-565873.7 LOW
5.2%
2HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.2d
CVE-2024-36266
5.2%
2
CVE-2024-29086
5.2%
2
CVE-2025-38651
5.2%
2
CVE-2025-36258
5.2%
2
CVE-2019-2194
5.2%
2
CVE-2025-38655
5.2%
2
CVE-2024-39532
5.2%
2
CVE-2025-38654
5.2%
2
CVE-2026-21498
5.2%
2
CVE-2026-45874
5.2%
2
CVE-2026-4971
5.2%
2
CVE-2026-8576
5.2%
2
CVE-2026-0063
5.2%
2
CVE-2025-2501
5.2%
2
CVE-2025-8386
5.2%
2
CVE-2024-53160
5.2%
2
CVE-2026-63873
5.2%
2In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range() aie2_populate_range() jumps back to the again label without calling mmput(mm), leaking a reference to the mm_struct. Add the missing mmput() before jumping to again.4d
CVE-2026-41125
5.2%
2
CVE-2026-45863
5.2%
2
CVE-2025-37088
5.2%
2
CVE-2024-20867
5.2%
2
CVE-2026-606368.8 HIG
5.1%
2Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).2d
CVE-2023-23348
5.2%
2
CVE-2025-15622
5.2%
2
CVE-2025-60360
5.2%
2
CVE-2024-42344
5.1%
2
CVE-2025-41701
5.2%
2
CVE-2024-235733.7 LOW
5.2%
2HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.14d
CVE-2026-277875.4 MED
5.2%
2Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.7d
CVE-2026-442306.1 MED
5.2%
2RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.8d
CVE-2025-60359
5.2%
2
CVE-2025-42895
5.2%
2
CVE-2024-10382
5.2%
2
CVE-2026-273005.5 MED
5.2%
2Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7d