PULSE
LIVE31signals / 24h
FEED
ransomtermite reclama a JD Young · CN · Not Foundransomanubis reclama a Coca-Cola / Fairlife · US · Agriculture and Food Productionransomsafepay reclama a zinorm.de · DE · Not Foundransomsafepay reclama a moebelmayer.de · DE · Retail & E-Commerceransomsafepay reclama a paritaet-nrw.org · DE · Professional Servicesransomsafepay reclama a haugbuersten.de · DE · Retail & E-Commerceransomsafepay reclama a landesmuseum.de · DE · Educationransomsafepay reclama a hst.eu · DE · Not Foundransomsafepay reclama a braywoodschool.co.uk · GB · Educationransomsafepay reclama a weier.org · DE · Not Foundransomsafepay reclama a bnpdist.com · US · Retail & E-Commerceransomnightspire reclama a Kates Nussman Ellis Earle & Landolfi LLP · US · Professional Servicesransomchaos reclama a vit-best.com · RU · Educationransomshinyhunters reclama a RingCentral, Inc. · US · Technologyransomtermite reclama a JD Young · CN · Not Foundransomanubis reclama a Coca-Cola / Fairlife · US · Agriculture and Food Productionransomsafepay reclama a zinorm.de · DE · Not Foundransomsafepay reclama a moebelmayer.de · DE · Retail & E-Commerceransomsafepay reclama a paritaet-nrw.org · DE · Professional Servicesransomsafepay reclama a haugbuersten.de · DE · Retail & E-Commerceransomsafepay reclama a landesmuseum.de · DE · Educationransomsafepay reclama a hst.eu · DE · Not Foundransomsafepay reclama a braywoodschool.co.uk · GB · Educationransomsafepay reclama a weier.org · DE · Not Foundransomsafepay reclama a bnpdist.com · US · Retail & E-Commerceransomnightspire reclama a Kates Nussman Ellis Earle & Landolfi LLP · US · Professional Servicesransomchaos reclama a vit-best.com · RU · Educationransomshinyhunters reclama a RingCentral, Inc. · US · Technology
CVE Watch353,240 in full archive

Vulnerabilities exploitable today

353,240in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600

Distribution · last window

  • Critical
    2,348
  • High
    8,119
  • Medium
    7,274
  • Low
    684
Filters

Window

Severity

Flags

Vulnerabilities338,601–338,640 · 353,240
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-43697
4.0%
1
CVE-2020-0325
4.0%
1
CVE-2025-23337
4.0%
1
CVE-2025-46743
4.0%
1
CVE-2019-9421
4.0%
1
CVE-2022-20144
4.0%
1
CVE-2024-68586.5 MED
4.0%
1In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.5d
CVE-2026-654719.6 CRI
4.0%
1Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.4d
CVE-2017-3750
4.0%
1
CVE-2025-39776
4.0%
1
CVE-2021-21547
4.0%
1
CVE-2020-0272
4.0%
1
CVE-2026-448947.5 HIG
4.0%
1Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8.1, a validated address lifts the 3× anti-amplification send limit. Thus any attacker who includes ANY non-empty token bytes in an Initial packet — with a spoofed victim source IP — causes the Netty server to treat the victim as validated and reflect full-size handshake flights (certificates, etc.) toward it without the 3× cap. The correct 'no token handler' semantics would be to return -1 (invalid) so the normal un-validated path and amplification limit apply. Version 4.2.15.Final patches the issue.13d
CVE-2026-547837.4 HIG
4.0%
1CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with one captured signed SOAP envelope to replay arbitrary service operations as the victim principal. This issue is fixed in versions 1.8.1 and 1.9.1.18d
CVE-2024-34681
4.0%
1
CVE-2026-23599
4.0%
1
CVE-2026-35339
4.0%
1
CVE-2024-44238
4.0%
1
CVE-2025-43345
4.0%
1
CVE-2026-4407
4.0%
1
CVE-2025-67745
4.0%
1
CVE-2026-597766.8 MED
4.0%
1Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.6d
CVE-2022-50310
4.0%
1
CVE-2026-12249
4.0%
1
CVE-2026-25818
4.0%
1
CVE-2026-0665
4.0%
1
CVE-2020-27034
4.0%
1
CVE-2022-31252
4.0%
1
CVE-2025-49850
4.0%
1
CVE-2023-53388
4.0%
1
CVE-2025-24791
4.0%
1
CVE-2026-396409.6 CRI
4.0%
1Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.3d
CVE-2025-20925
4.0%
1
CVE-2025-46733
4.0%
1
CVE-2025-607497.8 HIG
4.0%
1DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.23d
CVE-2026-7937
4.0%
1
CVE-2026-95293.3 LOW
4.0%
1A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.5d
CVE-2024-43696
4.0%
1
CVE-2025-21908
4.0%
1
CVE-2022-38687
4.0%
1