PULSE
LIVE17signals / 24h
FEED
ransomaurora reclama a Bretford Manufacturing · US · Manufacturingransomgunra reclama a Weilhotel · MY · Hospitalityransomdeadlock reclama a AHENK lab · TR · Technologyransomqilin reclama a Hoc · GB · Not Foundransomblacknevas reclama a Speed Group · Transportationransomthegentlemen reclama a Buck Knives · US · Manufacturingransomcoinbasecartel reclama a Accesso · GB · Technologyransomchaos reclama a thecranewaregroup.com · GB · Technologyransomcmdorganization reclama a B-K Tool & Design · US · Manufacturingransomdeadlock reclama a DIATER · ES · Manufacturingransomdeadlock reclama a Pasello · Technologyransombooba project reclama a Oklahoma Manufacturing Alliance · US · Manufacturingransomakira reclama a Franz Krause artworksgroup · Otherransomincransom reclama a https://eclmn.com/ · US · Not Foundransomaurora reclama a Bretford Manufacturing · US · Manufacturingransomgunra reclama a Weilhotel · MY · Hospitalityransomdeadlock reclama a AHENK lab · TR · Technologyransomqilin reclama a Hoc · GB · Not Foundransomblacknevas reclama a Speed Group · Transportationransomthegentlemen reclama a Buck Knives · US · Manufacturingransomcoinbasecartel reclama a Accesso · GB · Technologyransomchaos reclama a thecranewaregroup.com · GB · Technologyransomcmdorganization reclama a B-K Tool & Design · US · Manufacturingransomdeadlock reclama a DIATER · ES · Manufacturingransomdeadlock reclama a Pasello · Technologyransombooba project reclama a Oklahoma Manufacturing Alliance · US · Manufacturingransomakira reclama a Franz Krause artworksgroup · Otherransomincransom reclama a https://eclmn.com/ · US · Not Found
CVE Watch353,511 in full archive

Vulnerabilities exploitable today

353,511in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,600

Distribution · last window

  • Critical
    2,435
  • High
    8,291
  • Medium
    7,422
  • Low
    691
Filters

Window

Severity

Flags

Vulnerabilities338,241–338,280 · 353,511
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20032
4.1%
1
CVE-2022-50418
4.1%
1
CVE-2024-13068
4.1%
1
CVE-2024-28172
4.1%
1
CVE-2022-50263
4.1%
1
CVE-2025-29948
4.1%
1
CVE-2024-58323
4.1%
1
CVE-2026-348835.3 MED
4.1%
1An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with elevated privileges. Because the installer does not properly validate symbolic links or reparse points at the destination path, an attacker can create a malicious link that redirects the write operation to an arbitrary system location, enabling arbitrary file creation or overwrite with elevated privileges.5d
CVE-2024-31953
4.1%
1
CVE-2024-33660
4.1%
1
CVE-2024-57974
4.1%
1
CVE-2024-58322
4.1%
1
CVE-2024-27457
4.1%
1
CVE-2025-67734
4.1%
1
CVE-2022-50461
4.1%
1
CVE-2022-50464
4.1%
1
CVE-2026-42743
4.1%
1
CVE-2026-45004
4.1%
1
CVE-2025-39957
4.1%
1
CVE-2026-31890
4.1%
1
CVE-2023-53577
4.1%
1
CVE-2026-466714.4 MED
4.1%
1Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed inside the `.onetoc2` and joins them against the notebook's base directory without validating that they are relative paths confined to that directory. The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using `onenote_parser` to parse .onetoc2 files received from untrusted sources is affected. Users who only ever parse their own notebooks are not at meaningful risk. The issue is fixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. For users who cannot upgrade to 1.1.1, only call `Parser::parse_notebook` on `.onetoc2` files from trusted sources. Alternatively, use `Parser::parse_section` / `Parser::parse_section_buffer` on individual .one files, which do not perform the directory walk.6d
CVE-2021-22454
4.1%
1
CVE-2023-53547
4.1%
1
CVE-2021-22453
4.1%
1
CVE-2025-1755
4.1%
1
CVE-2026-529725.5 MED
4.1%
1In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the TX buffer size, cap the associated data length to 0x80000000.5d
CVE-2025-399315.5 MED
4.1%
1In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx->merge may contain a garbage value from the previous loop. This may then trigger a crash on the next entry into af_alg_sendmsg when it attempts to do a merge that can't be done. Fix this by setting ctx->merge to zero near the start of the loop.15d
CVE-2025-33176
4.1%
1
CVE-2025-66002
4.1%
1
CVE-2021-22457
4.1%
1
CVE-2022-50685
4.1%
1
CVE-2025-57977
4.1%
1
CVE-2026-614337.8 HIG
4.1%
1PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.14d
CVE-2025-547704.9 MED
4.1%
1A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from memory. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash and halt system availability29d
CVE-2020-0054
4.1%
1
CVE-2025-63717
4.1%
1
CVE-2026-28201
4.1%
1
CVE-2024-58073
4.1%
1
CVE-2023-53607
4.1%
1