PULSE
LIVE31signals / 24h
FEED
ransomtermite reclama a JD Young · CN · Not Foundransomanubis reclama a Coca-Cola / Fairlife · US · Agriculture and Food Productionransomsafepay reclama a zinorm.de · DE · Not Foundransomsafepay reclama a moebelmayer.de · DE · Retail & E-Commerceransomsafepay reclama a paritaet-nrw.org · DE · Professional Servicesransomsafepay reclama a haugbuersten.de · DE · Retail & E-Commerceransomsafepay reclama a landesmuseum.de · DE · Educationransomsafepay reclama a hst.eu · DE · Not Foundransomsafepay reclama a braywoodschool.co.uk · GB · Educationransomsafepay reclama a weier.org · DE · Not Foundransomsafepay reclama a bnpdist.com · US · Retail & E-Commerceransomnightspire reclama a Kates Nussman Ellis Earle & Landolfi LLP · US · Professional Servicesransomchaos reclama a vit-best.com · RU · Educationransomshinyhunters reclama a RingCentral, Inc. · US · Technologyransomtermite reclama a JD Young · CN · Not Foundransomanubis reclama a Coca-Cola / Fairlife · US · Agriculture and Food Productionransomsafepay reclama a zinorm.de · DE · Not Foundransomsafepay reclama a moebelmayer.de · DE · Retail & E-Commerceransomsafepay reclama a paritaet-nrw.org · DE · Professional Servicesransomsafepay reclama a haugbuersten.de · DE · Retail & E-Commerceransomsafepay reclama a landesmuseum.de · DE · Educationransomsafepay reclama a hst.eu · DE · Not Foundransomsafepay reclama a braywoodschool.co.uk · GB · Educationransomsafepay reclama a weier.org · DE · Not Foundransomsafepay reclama a bnpdist.com · US · Retail & E-Commerceransomnightspire reclama a Kates Nussman Ellis Earle & Landolfi LLP · US · Professional Servicesransomchaos reclama a vit-best.com · RU · Educationransomshinyhunters reclama a RingCentral, Inc. · US · Technology
CVE Watch353,240 in full archive

Vulnerabilities exploitable today

353,240in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600

Distribution · last window

  • Critical
    2,348
  • High
    8,119
  • Medium
    7,274
  • Low
    684
Filters

Window

Severity

Flags

Vulnerabilities338,641–338,680 · 353,240
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-396179.6 CRI
4.0%
1Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.3d
CVE-2026-41384
4.0%
1
CVE-2025-39790
4.0%
1
CVE-2025-70560
4.0%
1
CVE-2020-0151
4.0%
1
CVE-2020-0044
4.0%
1
CVE-2020-0437
4.0%
1
CVE-2025-61973
4.0%
1
CVE-2025-20932
4.0%
1
CVE-2020-0145
4.0%
1
CVE-2025-20930
4.0%
1
CVE-2021-30263
4.0%
1
CVE-2025-20933
4.0%
1
CVE-2025-22240
4.0%
1
CVE-2022-45874
4.0%
1
CVE-2020-27039
4.0%
1
CVE-2025-13958
4.0%
1
CVE-2025-20928
4.0%
1
CVE-2023-53481
4.0%
1
CVE-2024-3479
4.0%
1
CVE-2025-38598
4.0%
1
CVE-2026-27609
4.0%
1
CVE-2024-24901
4.0%
1
CVE-2025-21094
4.0%
1
CVE-2024-56559
4.0%
1
CVE-2024-28953
4.0%
1
CVE-2025-24520
4.0%
1
CVE-2025-39883
4.0%
1
CVE-2026-396218.8 HIG
4.0%
1Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.3d
CVE-2026-396209.6 CRI
4.0%
1Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.3d
CVE-2026-24201
4.0%
1
CVE-2026-488157.5 HIG
4.0%
1sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.12d
CVE-2026-526843.7 LOW
4.0%
1If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.4d
CVE-2026-341934.3 MED
4.0%
1Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.6d
CVE-2025-22053
4.0%
1
CVE-2025-38536
4.0%
1
CVE-2025-38667
4.0%
1
CVE-2024-6619
4.0%
1
CVE-2026-39855
4.0%
1
CVE-2025-32797
4.0%
1