PULSE
LIVE91signals / 24h
FEED
ransomqilin reclama a Savills France · FR · Professional Servicesransomqilin reclama a Wilbert's · US · Retail & E-Commerceransomdragonforce reclama a Katathani Phuket Beach Resort · TH · Hospitalityransomcrpxo reclama a IPTV Platform · US · Technology · 3.2 GBransomcrpxo reclama a Marketech · US · Technology · 6.7 GBransomcrpxo reclama a American Hospice & Home Health Services (Ahhh Care) · US · Healthcare · 11.3 GBransomcrpxo reclama a Bright Star Partners Insurance · US · Financial Services · 41.8 GBransomcrpxo reclama a eCare Platform · US · Healthcare · 14.2 GBransomcrpxo reclama a Dignity Phoenix · US · Healthcare · 5.4 GBransomcrpxo reclama a Schorr Law · US · Professional Services · 27.6 GBransomcrpxo reclama a Simpkins Law Firm · US · Professional Services · 31.2 GBransomcrpxo reclama a Leah Walker Orthodontics · US · Healthcare · 8.3 GBransomcrpxo reclama a Elko Dental Specialists · US · Healthcare · 7.8 GBransomdeadlock reclama a Hardware Asesorias Software Ltda · CL · Technologyransomqilin reclama a Savills France · FR · Professional Servicesransomqilin reclama a Wilbert's · US · Retail & E-Commerceransomdragonforce reclama a Katathani Phuket Beach Resort · TH · Hospitalityransomcrpxo reclama a IPTV Platform · US · Technology · 3.2 GBransomcrpxo reclama a Marketech · US · Technology · 6.7 GBransomcrpxo reclama a American Hospice & Home Health Services (Ahhh Care) · US · Healthcare · 11.3 GBransomcrpxo reclama a Bright Star Partners Insurance · US · Financial Services · 41.8 GBransomcrpxo reclama a eCare Platform · US · Healthcare · 14.2 GBransomcrpxo reclama a Dignity Phoenix · US · Healthcare · 5.4 GBransomcrpxo reclama a Schorr Law · US · Professional Services · 27.6 GBransomcrpxo reclama a Simpkins Law Firm · US · Professional Services · 31.2 GBransomcrpxo reclama a Leah Walker Orthodontics · US · Healthcare · 8.3 GBransomcrpxo reclama a Elko Dental Specialists · US · Healthcare · 7.8 GBransomdeadlock reclama a Hardware Asesorias Software Ltda · CL · Technology
CVE Watch352,832 in full archive

Vulnerabilities exploitable today

352,832in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600

Distribution · last window

  • Critical
    2,306
  • High
    8,005
  • Medium
    7,178
  • Low
    677
Filters

Window

Severity

Flags

Vulnerabilities339,521–339,560 · 352,832
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-12539
3.7%
1Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as untrusted, can therefore defeat the documented ICMP egress block to perform network reconnaissance and exfiltrate data over an ICMP covert channel, regardless of the configured allowlist.27d
CVE-2026-24007
3.7%
1
CVE-2023-28545
3.7%
1
CVE-2026-115815.9 MED
3.7%
1The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.27d
CVE-2026-577518.1 HIG
3.7%
1Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.25d
CVE-2026-31996
3.7%
1
CVE-2026-29050
3.7%
1
CVE-2025-68527
3.7%
1
CVE-2026-5923
3.7%
1Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.18d
CVE-2025-0432
3.7%
1
CVE-2025-68528
3.7%
1
CVE-2025-14159
3.7%
1
CVE-2026-21338
3.7%
1
CVE-2025-15363
3.7%
1
CVE-2026-26317
3.7%
1
CVE-2024-34610
3.7%
1
CVE-2016-11027
3.7%
1
CVE-2026-24632
3.7%
1
CVE-2018-254236.2 MED
3.7%
1Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.5d
CVE-2018-21077
3.7%
1
CVE-2025-220604.7 MED
3.7%
1In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM information, from concurrent modifications. Both the TCAM and SRAM tables are indirectly accessed by configuring an index register that selects the row to read or write to. This means that operations must be atomic in order to, e.g., avoid spreading writes across multiple rows. Since the shadow SRAM array is used to find free rows in the hardware table, it must also be protected in order to avoid TOCTOU errors where multiple cores allocate the same row. This issue was detected in a situation where `mvpp2_set_rx_mode()` ran concurrently on two CPUs. In this particular case the MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the classifier unit to drop all incoming unicast - indicated by the `rx_classifier_drops` counter.13d
CVE-2019-2190
3.7%
1
CVE-2025-39894
3.7%
1
CVE-2024-28046
3.7%
1
CVE-2025-59135
3.7%
1
CVE-2023-22383
3.7%
1
CVE-2019-9472
3.7%
1
CVE-2018-21073
3.7%
1
CVE-2020-11173
3.7%
1
CVE-2023-28570
3.7%
1
CVE-2019-9435
3.7%
1
CVE-2024-45355
3.7%
1
CVE-2024-24977
3.7%
1
CVE-2025-5344
3.7%
1
CVE-2025-38093
3.7%
1
CVE-2021-35085
3.7%
1
CVE-2024-29015
3.7%
1
CVE-2025-64469
3.7%
1
CVE-2023-53600
3.7%
1
CVE-2025-38092
3.7%
1