PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-CommercevulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2026-55040 — Microsoft / SharePointvulnKEV agrega CVE-2026-65400 — Apple / macOSvulnKEV agrega CVE-2025-62593 — Ray-Project / Rayransomclop reclama a ZEBRA.COM · US · Manufacturingransomshinyhunters reclama a Metabase · US · Technologyransomshinyhunters reclama a Sharecare, Inc. · US · Healthcareransomthegentlemen reclama a IPS · IT · Not Foundransomshinyhunters reclama a Carhartt, Inc. · US · Retail & E-Commerceransomthegentlemen reclama a Gfeller Treuhand und Verwaltungs · CH · Professional Servicesransomshinyhunters reclama a Cook Medical LLC · US · Healthcareransomthegentlemen reclama a Gravity Coffee · US · Retail & E-Commerce
CVE Watch363,707 in full archive

Vulnerabilities exploitable today

363,707in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610

Distribution · last window

  • Critical
    2,937
  • High
    12,416
  • Medium
    7,621
  • Low
    708
Filters

Window

Severity

Flags

Vulnerabilities362,241–362,280 · 363,707
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-256006.4 MED
0.0%
0The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file. Because the secret is constant across installations, any attacker with sufficient local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored password and authenticate as the user defined in the configuration file. In the affected version, this user account is configured with administrative privileges, granting full access to PDBM’s management interface and its underlying operational functions.30d
CVE-2026-00163.3 LOW
0.0%
0In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.30d
CVE-2026-34861
0.0%
0
CVE-2025-68962
0.0%
0
CVE-2026-00503.3 LOW
0.0%
0In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.30d
CVE-2026-207572.5 LOW
0.0%
0Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.3d
CVE-2026-419756.3 MED
0.0%
0Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.29d
CVE-2022-48451
0.0%
0
CVE-2026-285785.5 MED
0.0%
0In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.30d
CVE-2026-9266
0.0%
0
CVE-2025-47378
0.0%
0
CVE-2023-20686
0.0%
0
CVE-2025-58740
0.0%
0
CVE-2026-585574.8 MED
0.0%
0Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.37d
CVE-2025-64313
0.0%
0
CVE-2025-22442
0.0%
0
CVE-2025-15548
0.0%
0
CVE-2023-20942
0.0%
0
CVE-2022-42775
0.0%
0
CVE-2025-57806
0.0%
0
CVE-2026-21002
0.0%
0
CVE-2023-20736
0.0%
0
CVE-2026-2345
0.0%
0
CVE-2026-00987.8 HIG
0.0%
0In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30d
CVE-2019-20775
0.0%
0
CVE-2025-47333
0.0%
0
CVE-2025-48641
0.0%
0
CVE-2026-34862
0.0%
0
CVE-2026-178726.1 MED
0.0%
0Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)18d
CVE-2025-48575
0.0%
0
CVE-2025-54651
0.0%
0
CVE-2024-34725
0.0%
0
CVE-2026-210796.5 MED
0.0%
0Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.2d
CVE-2025-23364
0.0%
0
CVE-2023-20685
0.0%
0
CVE-2025-36889
0.0%
0
CVE-2024-43766
0.0%
0
CVE-2026-00997.8 HIG
0.0%
0In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.30d
CVE-2023-21101
0.0%
0
CVE-2025-264187.8 HIG
0.0%
0In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30d