PULSE
LIVE50signals / 24h
FEED
ransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Servicesransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Services
CVE Watch352,162 in full archive

Vulnerabilities exploitable today

352,162in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590

Distribution · last window

  • Critical
    2,073
  • High
    6,924
  • Medium
    5,904
  • Low
    547
Filters

Window

Severity

Flags

Vulnerabilities352,041–352,080 · 352,162
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654736.5 MED
0Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.4h
CVE-2026-648158.1 HIG
0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files4h
CVE-2026-648148.6 HIG
0In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session4h
CVE-2026-655167.2 HIG
0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.4h
CVE-2026-655244.3 MED
0Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.4h
CVE-2026-654756.5 MED
0Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.4h
CVE-2026-619477.1 HIG
0Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.4h
CVE-2026-6481310.0 CRI
0In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session4h
CVE-2026-6481210.0 CRI
0In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session4h
CVE-2026-648117.8 HIG
0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration4h
CVE-2026-648104.3 MED
0In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking4h
CVE-2026-655255.3 MED
0Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.4h
CVE-2026-654765.3 MED
0Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.4h
CVE-2026-648098.4 HIG
0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter4h
CVE-2026-655327.6 HIG
0Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.4h
CVE-2026-595449.8 CRI
0Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.4h
CVE-2026-595439.9 CRI
0Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.4h
CVE-2026-655336.5 MED
0Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.4h
CVE-2026-648088.4 HIG
0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling4h
CVE-2026-655385.9 MED
0Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.4h
CVE-2026-648077.8 HIG
0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration4h
CVE-2026-595427.7 HIG
0Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.4h
CVE-2026-595409.8 CRI
0Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.4h
CVE-2026-656069.6 CRI
0SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.4h
CVE-2026-648037.8 HIG
0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK4h
CVE-2026-648027.8 HIG
0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration4h
CVE-2026-658967.1 HIG
0Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to an arbitrary writable location outside user/pages/, including outside the Grav installation.4h
CVE-2026-654777.5 HIG
0Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.4h
CVE-2026-654785.4 MED
0Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.4h
CVE-2026-648003.5 LOW
0In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default4h
CVE-2026-619815.4 MED
0Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.4h
CVE-2026-619734.3 MED
0Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.4h
CVE-2026-654795.4 MED
0Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.4h
CVE-2026-62165
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61446. Reason: This candidate is a duplicate of CVE-2026-61446. Notes: All CVE users should reference CVE-2026-61446 instead of this candidate.8d
CVE-2026-619725.3 MED
0Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.4h
CVE-2026-131196.5 MED
0The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identifier; that function escapes quotes, backslashes, and a few control characters but does not escape spaces, equals signs, parentheses, or hyphens, so an attacker can break out of the identifier context and inject subqueries (terminated with a SQL comment). This makes it possible for authenticated attackers, with Contributor-level access and above who can edit the targeted event, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.6h
CVE-2026-595269.3 CRI
0Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.4h
CVE-2026-654806.5 MED
0Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.4h
CVE-2026-595259.3 CRI
0Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.4h
CVE-2026-654817.5 HIG
0Contributor Local File Inclusion in Vino <= 1.9 versions.4h