PULSE
LIVE35signals / 24h
FEED
ransomsilentransomgroup reclama a Mayer Brown · US · Professional Servicesransomqilin reclama a Crystal Pharmatech · US · Healthcareransomplay reclama a Signature Services · Professional Servicesransomplay reclama a GCATS Investments · US · Financial Servicesransomplay reclama a Platinum Group · SG · Manufacturingransomlynx reclama a www.jerryleigh.com · US · Otherransomlynx reclama a www.talbotdes.org · GB · Otherransomgammax reclama a King International LLC · US · Otherransomqilin reclama a AmSpec · US · Energy & Utilitiesransomqilin reclama a ALIZE (alize-sud.fr) · FR · Professional Servicesransomqilin reclama a Jakle & Alexander · US · Not Foundransomqilin reclama a Akuur Law Firm · TR · Professional Servicesransomqilin reclama a J&T Bank and Trust · US · Financial Servicesransombravox reclama a MITC AG · CH · Otherransomsilentransomgroup reclama a Mayer Brown · US · Professional Servicesransomqilin reclama a Crystal Pharmatech · US · Healthcareransomplay reclama a Signature Services · Professional Servicesransomplay reclama a GCATS Investments · US · Financial Servicesransomplay reclama a Platinum Group · SG · Manufacturingransomlynx reclama a www.jerryleigh.com · US · Otherransomlynx reclama a www.talbotdes.org · GB · Otherransomgammax reclama a King International LLC · US · Otherransomqilin reclama a AmSpec · US · Energy & Utilitiesransomqilin reclama a ALIZE (alize-sud.fr) · FR · Professional Servicesransomqilin reclama a Jakle & Alexander · US · Not Foundransomqilin reclama a Akuur Law Firm · TR · Professional Servicesransomqilin reclama a J&T Bank and Trust · US · Financial Servicesransombravox reclama a MITC AG · CH · Other
CVE Watch356,393 in full archive

Vulnerabilities exploitable today

356,393in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603

Distribution · last window

  • Critical
    2,794
  • High
    11,183
  • Medium
    7,442
  • Low
    701
Filters

Window

Severity

Flags

Vulnerabilities355,401–355,440 · 356,393
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-20620
0.0%
0
CVE-2025-47404
0.0%
0
CVE-2026-440594.5 MED
0.0%
0A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or cause a minor service disruption.14d
CVE-2025-47330
0.0%
0
CVE-2026-00987.8 HIG
0.0%
0In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.15d
CVE-2026-130676.3 MED
0.0%
0When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.2d
CVE-2026-285785.5 MED
0.0%
0In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.15d
CVE-2025-47378
0.0%
0
CVE-2023-20687
0.0%
0
CVE-2019-20775
0.0%
0
CVE-2023-20684
0.0%
0
CVE-2025-22442
0.0%
0
CVE-2024-0028
0.0%
0
CVE-2025-58313
0.0%
0
CVE-2023-20685
0.0%
0
CVE-2026-20439
0.0%
0
CVE-2023-20787
0.0%
0
CVE-2025-54651
0.0%
0
CVE-2026-0153
0.0%
0
CVE-2026-256006.4 MED
0.0%
0The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file. Because the secret is constant across installations, any attacker with sufficient local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored password and authenticate as the user defined in the configuration file. In the affected version, this user account is configured with administrative privileges, granting full access to PDBM’s management interface and its underlying operational functions.16d
CVE-2026-178726.1 MED
0.0%
0Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)4d
CVE-2022-42775
0.0%
0
CVE-2025-36889
0.0%
0
CVE-2026-0057
0.0%
0
CVE-2023-21399
0.0%
0
CVE-2026-0133
0.0%
0
CVE-2025-48608
0.0%
0
CVE-2025-54625
0.0%
0
CVE-2025-36751
0.0%
0
CVE-2026-9266
0.0%
0
CVE-2025-57806
0.0%
0
CVE-2026-213797.8 HIG
0.0%
0Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.30d
CVE-2022-47331
0.0%
0
CVE-2026-28548
0.0%
0
CVE-2025-48960
0.0%
0
CVE-2026-285863.3 LOW
0.0%
0In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.15d
CVE-2025-68962
0.0%
0
CVE-2025-58316
0.0%
0
CVE-2026-0150
0.0%
0
CVE-2024-235816.7 MED
0.0%
0The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.31d