PULSE
LIVE32signals / 24h
FEED
ransomsecurotrop reclama a MAG USA Inc · US · Manufacturingransomsection9 reclama a And where does the newborn go from here? The net is vast and infinite. · Not Foundransomincransom reclama a PARTNERED HEALTH GROUP · AU · Healthcareransomcmdorganization reclama a Contact Group · AU · Professional Servicesransomincransom reclama a sslf.local · US · Not Foundransomqilin reclama a TenSparrows · US · Not Foundransomcmdorganization reclama a Collge Mont Notre-Dame de Sherbrooke · CA · Educationransomqilin reclama a Db Tarimsal Enerji · TR · Agriculture and Food Productionransomcmdorganization reclama a Rondout Electric · US · Energy & Utilitiesransomqilin reclama a Byonyks · US · Technologyransomqilin reclama a Prenisac · US · Not Foundransomqilin reclama a Excel Consultores · MX · Professional Servicesransomqilin reclama a Affinity Capital · US · Financial Servicesransomkairos reclama a Warwick Fabrics · NZ · Manufacturingransomsecurotrop reclama a MAG USA Inc · US · Manufacturingransomsection9 reclama a And where does the newborn go from here? The net is vast and infinite. · Not Foundransomincransom reclama a PARTNERED HEALTH GROUP · AU · Healthcareransomcmdorganization reclama a Contact Group · AU · Professional Servicesransomincransom reclama a sslf.local · US · Not Foundransomqilin reclama a TenSparrows · US · Not Foundransomcmdorganization reclama a Collge Mont Notre-Dame de Sherbrooke · CA · Educationransomqilin reclama a Db Tarimsal Enerji · TR · Agriculture and Food Productionransomcmdorganization reclama a Rondout Electric · US · Energy & Utilitiesransomqilin reclama a Byonyks · US · Technologyransomqilin reclama a Prenisac · US · Not Foundransomqilin reclama a Excel Consultores · MX · Professional Servicesransomqilin reclama a Affinity Capital · US · Financial Servicesransomkairos reclama a Warwick Fabrics · NZ · Manufacturing
CVE Watch354,348 in full archive

Vulnerabilities exploitable today

354,348in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602

Distribution · last window

  • Critical
    2,600
  • High
    9,343
  • Medium
    7,528
  • Low
    679
Filters

Window

Severity

Flags

Vulnerabilities337,841–337,880 · 354,348
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-41687
4.4%
1
CVE-2024-34635
4.4%
1
CVE-2022-26468
4.4%
1
CVE-2026-444345.3 MED
4.4%
1Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. The QUIC protocol is designed to withstand packet injection attacks, once the handshake is complete. Only packets that carry some secret patterns are considered as stateless resets. Quicly allows the peer to share up to 4 such patterns per connection. However, until now, it failed to determine which of the 4 slots that it uses to retain the secret patterns contains a valid entry. As the slots are zero-initialized, the failure meant that, unless the peer advertised 4 of such patterns, an all-zero pattern was treated as a stateless reset.In effect, this allowed an on-path attacker to reset QUIC connections governed by Quicly. This issue has been fixed by commit dccf5d4.13d
CVE-2026-341655.0 MED
4.4%
1go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.6d
CVE-2020-0029
4.4%
1
CVE-2025-673994.6 MED
4.4%
1An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access26d
CVE-2026-598417.5 HIG
4.4%
1A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>16d
CVE-2022-50225
4.4%
1
CVE-2025-20024
4.4%
1
CVE-2026-3939
4.4%
1
CVE-2026-35275
4.4%
1
CVE-2024-34632
4.4%
1
CVE-2024-42036
4.4%
1
CVE-2022-38103
4.4%
1
CVE-2026-54736
4.4%
1Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise comparison that returns early on the first differing byte. This observable timing discrepancy can allow an attacker to recover a valid tag byte-by-byte and attach it to a chosen IV and ciphertext so that decrypt() accepts tampered encrypted content as authentic. This issue is fixed in version 5.14.1.17d
CVE-2025-36755
4.4%
1
CVE-2025-7020
4.4%
1
CVE-2025-37880
4.4%
1
CVE-2022-33963
4.4%
1
CVE-2025-43284
4.4%
1
CVE-2025-13737
4.4%
1
CVE-2025-31195
4.4%
1
CVE-2026-328627.8 HIG
4.4%
1There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.6d
CVE-2023-21484
4.4%
1
CVE-2021-0553
4.4%
1
CVE-2022-41577
4.4%
1
CVE-2023-27382
4.4%
1
CVE-2025-30631
4.4%
1
CVE-2025-20623
4.4%
1
CVE-2020-27030
4.4%
1
CVE-2024-42192
4.4%
1
CVE-2025-53523
4.4%
1
CVE-2023-22440
4.4%
1
CVE-2025-66102
4.4%
1
CVE-2026-0027
4.4%
1
CVE-2025-67341
4.4%
1
CVE-2025-46251
4.4%
1
CVE-2022-40972
4.4%
1
CVE-2019-2110
4.4%
1