PULSE
LIVE85signals / 24h
FEED
ransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomgenesis reclama a Williams Accounting Professional · CA · Professional Servicesransomgenesis reclama a JJP Slip Forming Inc. · US · Manufacturingransomgenesis reclama a Building Envelope Systems · US · Manufacturingransomgenesis reclama a Westlake Realty Group, Inc. · US · Retail & E-Commerceransomgenesis reclama a Servonix Technologies · US · Not Foundransomgenesis reclama a Infinity Pipeline,Inc. · US · Energy & Utilitiesransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Servicesransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomgenesis reclama a Williams Accounting Professional · CA · Professional Servicesransomgenesis reclama a JJP Slip Forming Inc. · US · Manufacturingransomgenesis reclama a Building Envelope Systems · US · Manufacturingransomgenesis reclama a Westlake Realty Group, Inc. · US · Retail & E-Commerceransomgenesis reclama a Servonix Technologies · US · Not Foundransomgenesis reclama a Infinity Pipeline,Inc. · US · Energy & Utilitiesransomglobal secret group reclama a Hinduja Tech | BMW Group & Škoda Auto · IN · Manufacturingransomglobal secret group reclama a Pro-Tuff | Decals · US · Retail & E-Commerceransomdeadlock reclama a High Class Car Limo · US · Transportationransomanubis reclama a Eagle Crest Communities · US · Hospitalityransomglobal secret group reclama a Spergel · CA · Professional Services
CVE Watch352,788 in full archive

Vulnerabilities exploitable today

352,788in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600

Distribution · last window

  • Critical
    2,281
  • High
    7,882
  • Medium
    7,175
  • Low
    676
Filters

Window

Severity

Flags

Vulnerabilities340,161–340,200 · 352,788
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32460
3.6%
1
CVE-2025-71124
3.6%
1
CVE-2026-24805
3.6%
1
CVE-2020-0089
3.6%
1
CVE-2018-11818
3.6%
1
CVE-2020-0135
3.6%
1
CVE-2026-99593.1 LOW
3.6%
1Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)6d
CVE-2025-23300
3.6%
1
CVE-2025-49163
3.6%
1
CVE-2023-28566
3.6%
1
CVE-2023-28553
3.6%
1
CVE-2020-0109
3.6%
1
CVE-2023-21195
3.6%
1
CVE-2026-161304.4 MED
3.6%
1A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local access is required to approach this attack. The exploit is publicly available and might be used. The identifier of the patch is 369ff3d240cf3c0787b50e1e9f182e1a06c71255. It is recommended to apply a patch to fix this issue.6d
CVE-2025-21634
3.6%
1
CVE-2026-556268.0 HIG
3.6%
1xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active desktop sessions of other users on the same system. Users using other backends, such as xorgxrdp or Xvnc over TCP sockets, are not affected. This issue has been fixed in version 0.10.6.1.2d
CVE-2025-71307
3.6%
1
CVE-2025-64463
3.6%
1
CVE-2025-26474
3.6%
1
CVE-2025-23098
3.6%
1
CVE-2020-0105
3.6%
1
CVE-2023-28563
3.6%
1
CVE-2018-13909
3.6%
1
CVE-2025-6497
3.6%
1
CVE-2024-39821
3.6%
1
CVE-2025-46614
3.6%
1
CVE-2024-31756
3.6%
1
CVE-2026-349936.4 MED
3.6%
1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.5d
CVE-2025-9336
3.6%
1
CVE-2025-64467
3.6%
1
CVE-2025-50369
3.6%
1
CVE-2025-64468
3.6%
1
CVE-2026-20044
3.6%
1
CVE-2023-21202
3.6%
1
CVE-2025-71308
3.6%
1
CVE-2025-38246
3.6%
1
CVE-2025-23134
3.6%
1
CVE-2026-40450
3.6%
1
CVE-2026-3457
3.6%
1
CVE-2025-71312
3.6%
1