PULSE
LIVE40signals / 24h
FEED
ransomkrybit reclama a reflet2000.fr · FR · Otherransomkrybit reclama a www.actini.com · FR · Technologyransomkrybit reclama a www.ernat-bureau-etudes.fr · FR · Professional Servicesransomkrybit reclama a www.serengetiestates.co.za · ZA · Not Foundransomkrybit reclama a www.hymiasa.com · PE · Otherransomsilentransomgroup reclama a Mayer Brown · US · Professional Servicesransomqilin reclama a Crystal Pharmatech · US · Healthcareransomplay reclama a Signature Services · Professional Servicesransomplay reclama a GCATS Investments · US · Financial Servicesransomplay reclama a Platinum Group · SG · Manufacturingransomlynx reclama a www.jerryleigh.com · US · Otherransomlynx reclama a www.talbotdes.org · GB · Otherransomgammax reclama a King International LLC · US · Otherransomqilin reclama a AmSpec · US · Energy & Utilitiesransomkrybit reclama a reflet2000.fr · FR · Otherransomkrybit reclama a www.actini.com · FR · Technologyransomkrybit reclama a www.ernat-bureau-etudes.fr · FR · Professional Servicesransomkrybit reclama a www.serengetiestates.co.za · ZA · Not Foundransomkrybit reclama a www.hymiasa.com · PE · Otherransomsilentransomgroup reclama a Mayer Brown · US · Professional Servicesransomqilin reclama a Crystal Pharmatech · US · Healthcareransomplay reclama a Signature Services · Professional Servicesransomplay reclama a GCATS Investments · US · Financial Servicesransomplay reclama a Platinum Group · SG · Manufacturingransomlynx reclama a www.jerryleigh.com · US · Otherransomlynx reclama a www.talbotdes.org · GB · Otherransomgammax reclama a King International LLC · US · Otherransomqilin reclama a AmSpec · US · Energy & Utilities
CVE Watch356,393 in full archive

Vulnerabilities exploitable today

356,393in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603

Distribution · last window

  • Critical
    2,787
  • High
    11,178
  • Medium
    7,418
  • Low
    700
Filters

Window

Severity

Flags

Vulnerabilities355,321–355,360 · 356,393
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59600
0.1%
0
CVE-2025-20796
0.1%
0
CVE-2025-27049
0.1%
0
CVE-2025-47343
0.1%
0
CVE-2026-00967.8 HIG
0.1%
0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.15d
CVE-2025-27039
0.1%
0
CVE-2023-21260
0.1%
0
CVE-2025-47394
0.1%
0
CVE-2024-34725
0.1%
0
CVE-2026-240888.2 HIG
0.1%
0Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.15d
CVE-2026-0134
0.1%
0
CVE-2023-3781
0.1%
0
CVE-2024-49735
0.1%
0
CVE-2026-24929
0.1%
0
CVE-2022-44420
0.1%
0
CVE-2026-56272
0.1%
0
CVE-2025-682437.0 HIG
0.1%
0In the Linux kernel, the following vulnerability has been resolved: NFS: Check the TLS certificate fields in nfs_match_client() If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the cert_serial and privkey_serial fields need to match as well since they define the client's identity, as presented to the server.8d
CVE-2017-13312
0.1%
0
CVE-2025-47331
0.1%
0
CVE-2017-13311
0.1%
0
CVE-2026-20429
0.1%
0
CVE-2023-20942
0.0%
0
CVE-2026-252597.8 HIG
0.0%
0Memory corruption while processing multiple IOCTL command for escape operations.15d
CVE-2023-20686
0.0%
0
CVE-2026-285777.8 HIG
0.0%
0In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.15d
CVE-2026-34862
0.0%
0
CVE-2025-32317
0.0%
0
CVE-2025-21481
0.0%
0
CVE-2024-29779
0.0%
0
CVE-2026-20442
0.0%
0
CVE-2026-00163.3 LOW
0.0%
0In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.16d
CVE-2026-178726.1 MED
0.0%
0Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)4d
CVE-2026-0133
0.0%
0
CVE-2025-36889
0.0%
0
CVE-2023-20787
0.0%
0
CVE-2026-256006.4 MED
0.0%
0The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file. Because the secret is constant across installations, any attacker with sufficient local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored password and authenticate as the user defined in the configuration file. In the affected version, this user account is configured with administrative privileges, granting full access to PDBM’s management interface and its underlying operational functions.16d
CVE-2025-48608
0.0%
0
CVE-2022-42775
0.0%
0
CVE-2025-463713.6 LOW
0.0%
0Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.14d
CVE-2025-54651
0.0%
0