PULSE
LIVE84signals / 24h
FEED
ransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomgenesis reclama a Williams Accounting Professional · CA · Professional Servicesransomgenesis reclama a JJP Slip Forming Inc. · US · Manufacturingransomgenesis reclama a Building Envelope Systems · US · Manufacturingransomgenesis reclama a Westlake Realty Group, Inc. · US · Retail & E-Commerceransomgenesis reclama a Servonix Technologies · US · Not Foundransomgenesis reclama a Infinity Pipeline,Inc. · US · Energy & Utilitiesransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomgenesis reclama a Williams Accounting Professional · CA · Professional Servicesransomgenesis reclama a JJP Slip Forming Inc. · US · Manufacturingransomgenesis reclama a Building Envelope Systems · US · Manufacturingransomgenesis reclama a Westlake Realty Group, Inc. · US · Retail & E-Commerceransomgenesis reclama a Servonix Technologies · US · Not Foundransomgenesis reclama a Infinity Pipeline,Inc. · US · Energy & Utilitiesransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Services
CVE Watch352,788 in full archive

Vulnerabilities exploitable today

352,788in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600

Distribution · last window

  • Critical
    2,281
  • High
    7,882
  • Medium
    7,175
  • Low
    676
Filters

Window

Severity

Flags

Vulnerabilities340,081–340,120 · 352,788
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-38233
3.6%
1
CVE-2023-53579
3.6%
1
CVE-2026-1553
3.6%
1
CVE-2017-14900
3.6%
1
CVE-2025-63060
3.6%
1
CVE-2026-43260
3.6%
1
CVE-2026-126895.4 MED
3.6%
1The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.2d
CVE-2024-12973
3.6%
1
CVE-2022-32599
3.6%
1
CVE-2026-88747.1 HIG
3.6%
1Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS.4d
CVE-2025-64462
3.6%
1
CVE-2025-24304
3.6%
1
CVE-2023-28568
3.6%
1
CVE-2019-9273
3.6%
1
CVE-2026-33785
3.6%
1
CVE-2023-28569
3.6%
1
CVE-2025-53966
3.6%
1
CVE-2026-40449
3.6%
1
CVE-2025-50370
3.6%
1
CVE-2021-0952
3.6%
1
CVE-2025-8887
3.6%
1
CVE-2023-53031
3.6%
1
CVE-2026-139054.2 MED
3.6%
1Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Medium)25d
CVE-2025-6496
3.6%
1
CVE-2025-49495
3.6%
1
CVE-2025-64461
3.6%
1
CVE-2026-598587.8 HIG
3.5%
1Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.13d
CVE-2022-39888
3.6%
1
CVE-2024-34585
3.6%
1
CVE-2026-565863.1 LOW
3.6%
1HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.4d
CVE-2025-64466
3.6%
1
CVE-2026-599487.0 HIG
3.6%
1Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.16d
CVE-2025-62758
3.6%
1
CVE-2018-25323
3.6%
1
CVE-2026-111486.5 MED
3.6%
1Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)4d
CVE-2025-64465
3.6%
1
CVE-2019-6198
3.6%
1
CVE-2025-34062
3.6%
1
CVE-2025-8301
3.5%
1
CVE-2025-20050
3.6%
1