PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCenter
CVE Watch365,446 in full archive

Vulnerabilities exploitable today

365,446in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626

Distribution · last window

  • Critical
    2,325
  • High
    9,981
  • Medium
    4,918
  • Low
    460
Filters

Window

Severity

Flags

Vulnerabilities365,001–365,040 · 365,446
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47379
0.0%
0
CVE-2022-20243
0.0%
0
CVE-2026-28538
0.0%
0
CVE-2023-20684
0.0%
0
CVE-2023-20785
0.0%
0
CVE-2023-20942
0.0%
0
CVE-2026-00163.3 LOW
0.0%
0In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.36d
CVE-2026-419756.3 MED
0.0%
0Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.35d
CVE-2023-20623
0.0%
0
CVE-2026-20437
0.0%
0
CVE-2026-16459
0.0%
0Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.22h
CVE-2026-240888.2 HIG
0.0%
0Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.36d
CVE-2025-58740
0.0%
0
CVE-2026-00987.8 HIG
0.0%
0In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36d
CVE-2026-00897.8 HIG
0.0%
0In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36d
CVE-2025-48641
0.0%
0
CVE-2024-34725
0.0%
0
CVE-2026-207572.5 LOW
0.0%
0Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.9d
CVE-2025-15548
0.0%
0
CVE-2025-47333
0.0%
0
CVE-2026-112905.0 MED
0.0%
0Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)35d
CVE-2025-22442
0.0%
0
CVE-2026-25266
0.0%
0
CVE-2026-213667.8 HIG
0.0%
0Memory corruption while processing a packet with a size close to the maximum allowed value.21d
CVE-2024-45547
0.0%
0
CVE-2026-252597.8 HIG
0.0%
0Memory corruption while processing multiple IOCTL command for escape operations.36d
CVE-2026-0125
0.0%
0
CVE-2023-44128
0.0%
0
CVE-2023-20801
0.0%
0
CVE-2026-16458
0.0%
0Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.22h
CVE-2024-47025
0.0%
0
CVE-2025-59600
0.0%
0
CVE-2026-0153
0.0%
0
CVE-2023-20620
0.0%
0
CVE-2026-285785.5 MED
0.0%
0In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36d
CVE-2025-54625
0.0%
0
CVE-2026-44509
0.0%
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.37d
CVE-2026-00185.5 MED
0.0%
0In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.36d
CVE-2026-00503.3 LOW
0.0%
0In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.36d
CVE-2026-21002
0.0%
0