PULSE
LIVE53signals / 24h
FEED
ransomcrpxo reclama a KUVEYT TURK · TR · Financial Servicesransomcrpxo reclama a FINANSBANK · TR · Financial Servicesransomcrpxo reclama a ANADOLUBANK · TR · Financial Servicesransomcrpxo reclama a THY · TR · Transportationransomcrpxo reclama a JOHNSON & JOHNSON · US · Healthcareransomcrpxo reclama a DOĞAN HOLDİNG · TR · Otherransomcrpxo reclama a ANADOLU SİGORTA · TR · Financial Servicesransomcrpxo reclama a HYUNDAI · KR · Manufacturingransomcrpxo reclama a ASELSAN · TR · Government & Defenseransomcrpxo reclama a A101 · TR · Retail & E-Commerceransomqilin reclama a Community Management Associates · US · Professional Servicesransomthegentlemen reclama a Las Cenizas · CL · Otherransomthegentlemen reclama a Kenaitze Indian Tribe · US · Government & Defenseransomthegentlemen reclama a Additive Manufacturing · US · Manufacturingransomcrpxo reclama a KUVEYT TURK · TR · Financial Servicesransomcrpxo reclama a FINANSBANK · TR · Financial Servicesransomcrpxo reclama a ANADOLUBANK · TR · Financial Servicesransomcrpxo reclama a THY · TR · Transportationransomcrpxo reclama a JOHNSON & JOHNSON · US · Healthcareransomcrpxo reclama a DOĞAN HOLDİNG · TR · Otherransomcrpxo reclama a ANADOLU SİGORTA · TR · Financial Servicesransomcrpxo reclama a HYUNDAI · KR · Manufacturingransomcrpxo reclama a ASELSAN · TR · Government & Defenseransomcrpxo reclama a A101 · TR · Retail & E-Commerceransomqilin reclama a Community Management Associates · US · Professional Servicesransomthegentlemen reclama a Las Cenizas · CL · Otherransomthegentlemen reclama a Kenaitze Indian Tribe · US · Government & Defenseransomthegentlemen reclama a Additive Manufacturing · US · Manufacturing
CVE Watch354,684 in full archive

Vulnerabilities exploitable today

354,684in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601

Distribution · last window

  • Critical
    2,622
  • High
    9,423
  • Medium
    7,591
  • Low
    711
Filters

Window

Severity

Flags

Vulnerabilities335,961–336,000 · 354,684
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-39875
5.2%
2
CVE-2026-105106.1 MED
5.2%
2Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter.9d
CVE-2025-8148
5.2%
2
CVE-2025-59298
5.2%
2
CVE-2026-21497
5.2%
2
CVE-2023-34972
5.1%
2
CVE-2021-30323
5.1%
2
CVE-2021-30257
5.1%
2
CVE-2021-30316
5.1%
2
CVE-2026-34257
5.1%
2
CVE-2014-6274
5.1%
2
CVE-2025-84446.4 MED
5.1%
2The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.9d
CVE-2023-41779
5.1%
2
CVE-2026-27756
5.1%
2
CVE-2025-8070
5.1%
2
CVE-2021-30282
5.1%
2
CVE-2026-363246.1 MED
5.1%
2SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.10d
CVE-2023-41826
5.1%
2
CVE-2023-53372
5.1%
2
CVE-2025-20718
5.1%
2
CVE-2025-38069
5.1%
2
CVE-2026-29520
5.1%
2
CVE-2021-30291
5.1%
2
CVE-2021-30274
5.1%
2
CVE-2026-35055
5.1%
2
CVE-2024-48974
5.1%
2
CVE-2026-63859
5.1%
2In the Linux kernel, the following vulnerability has been resolved: net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue() Similar to airoha_qdma_cleanup_rx_queue(), reset DMA TX descriptors in airoha_qdma_cleanup_tx_queue routine. Moreover, reset TX_DMA_IDX to TX_CPU_IDX to notify the NIC the QDMA TX ring is empty.4d
CVE-2025-385507.8 HIG
5.1%
2In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.2d
CVE-2025-12986
5.1%
2
CVE-2024-33685
5.1%
2
CVE-2025-31962
5.1%
2
CVE-2021-0991
5.1%
2
CVE-2025-42616
5.1%
2
CVE-2024-47896
5.1%
2
CVE-2026-614536.1 MED
5.1%
2Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: true), an attacker with page-write API permission can use Twig's string concatenation operator (~) to dynamically construct event handler names, dangerous tag names, or dangerous protocols at render time (e.g. {% set x = "on" ~ "error" %}). The validator sees only the harmless Twig expression and allows the content, but after Twig rendering the output (rendered via {{ page.content|raw }}) contains an active payload such as <img src=1 onerror=alert(1)>, executing arbitrary JavaScript in visitors' browsers.16d
CVE-2018-253496.1 MED
5.1%
2userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log page.8d
CVE-2023-48360
5.1%
2
CVE-2022-21139
5.1%
2
CVE-2025-21032
5.1%
2
CVE-2025-14312
5.1%
2