PULSE
LIVE16signals / 24h
FEED
ransomakira reclama a Northwood Country Club · Hospitalityransomsection9 reclama a ****.com.pa · PA · Not Foundransomspacebears reclama a StellarRAD Systems · US · Technologyransomaurora reclama a Bretford Manufacturing · US · Manufacturingransomgunra reclama a Weilhotel · MY · Hospitalityransomdeadlock reclama a AHENK lab · TR · Technologyransomqilin reclama a Hoc · GB · Not Foundransomblacknevas reclama a Speed Group · Transportationransomthegentlemen reclama a Buck Knives · US · Manufacturingransomcoinbasecartel reclama a Accesso · GB · Technologyransomchaos reclama a thecranewaregroup.com · GB · Technologyransomcmdorganization reclama a B-K Tool & Design · US · Manufacturingransomdeadlock reclama a DIATER · ES · Manufacturingransomdeadlock reclama a Pasello · Technologyransomakira reclama a Northwood Country Club · Hospitalityransomsection9 reclama a ****.com.pa · PA · Not Foundransomspacebears reclama a StellarRAD Systems · US · Technologyransomaurora reclama a Bretford Manufacturing · US · Manufacturingransomgunra reclama a Weilhotel · MY · Hospitalityransomdeadlock reclama a AHENK lab · TR · Technologyransomqilin reclama a Hoc · GB · Not Foundransomblacknevas reclama a Speed Group · Transportationransomthegentlemen reclama a Buck Knives · US · Manufacturingransomcoinbasecartel reclama a Accesso · GB · Technologyransomchaos reclama a thecranewaregroup.com · GB · Technologyransomcmdorganization reclama a B-K Tool & Design · US · Manufacturingransomdeadlock reclama a DIATER · ES · Manufacturingransomdeadlock reclama a Pasello · Technology
CVE Watch353,604 in full archive

Vulnerabilities exploitable today

353,604in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,602

Distribution · last window

  • Critical
    2,451
  • High
    8,318
  • Medium
    7,448
  • Low
    696
Filters

Window

Severity

Flags

Vulnerabilities338,041–338,080 · 353,604
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-9570
4.3%
1
CVE-2026-278824.8 MED
4.3%
1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation is vulnerable to timing attacks, which could allow an attacker to gradually discover the secret token by measuring response time differences. This vulnerability is fixed in 4.0.0-beta.461.29d
CVE-2025-38251
4.3%
1
CVE-2025-38343
4.3%
1
CVE-2026-654437.1 HIG
4.3%
1Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.22h
CVE-2026-654407.1 HIG
4.3%
1Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.22h
CVE-2026-654417.1 HIG
4.3%
1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.22h
CVE-2026-654477.1 HIG
4.3%
1Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.22h
CVE-2026-654387.1 HIG
4.3%
1Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.22h
CVE-2021-1928
4.3%
1
CVE-2025-156547.1 HIG
4.3%
1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.7d
CVE-2025-42908
4.3%
1
CVE-2026-436536.2 MED
4.3%
1The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.2d
CVE-2026-39046.2 MED
4.3%
1Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurrently modified by another thread, potentially resulting in spurious cache misses, which in itself is not a security issue.  However in the GNU C Library version 2.36 an optimized implementation of memcmp was introduced for x86_64 which could crash when invoked with such undefined behaviour, turning this into a potential crash of the nscd client and the application that uses it. This implementation was backported to the 2.35 branch, making the nscd client in that branch vulnerable as well.  Subsequently, the fix for this issue was backported to all vulnerable branches in the GNU C Library repository. It is advised that distributions that may have cherry-picked the memcpy SSE2 optimization in their copy of the GNU C Library, also apply the fix to avoid the potential crash in the nscd client.15d
CVE-2025-14095
4.3%
1
CVE-2026-483085.9 MED
4.3%
1Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.12d
CVE-2025-34210
4.3%
1
CVE-2026-654377.1 HIG
4.3%
1Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.22h
CVE-2025-7011
4.3%
1
CVE-2023-1548
4.3%
1
CVE-2021-33632
4.3%
1
CVE-2022-20045
4.3%
1
CVE-2026-28109
4.3%
1
CVE-2026-27072
4.3%
1
CVE-2025-38537
4.3%
1
CVE-2025-23667
4.3%
1
CVE-2022-49850
4.3%
1
CVE-2025-1245
4.3%
1
CVE-2026-35094
4.3%
1
CVE-2024-20324
4.3%
1
CVE-2025-53649
4.3%
1
CVE-2025-20314
4.3%
1
CVE-2025-5824
4.3%
1
CVE-2026-471445.5 MED
4.3%
1Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose contents of files outside the repository, one line at a time, to the terminal of a user who runs the command. See patch commit for technical details. The issue is fixed in 0.1.7. Upgrade to either 0.1.7 or later versions to incorporate the patch. As a workaround, do not run `shame next` against untrusted `shamefile.yaml`. Use `shame me --dry-run` for CI validation.6d
CVE-2020-3483
4.3%
1
CVE-2025-67933
4.3%
1
CVE-2025-7008
4.3%
1
CVE-2021-26387
4.3%
1
CVE-2022-20028
4.3%
1
CVE-2026-56813
4.3%
1