PULSE
FEED
vulnKEV agrega CVE-2026-67279 — MikroTik / RouterOSvulnKEV agrega CVE-2026-65660 — Microsoft / SharePointvulnKEV agrega CVE-2026-5430 — WSO2 / Multiple ProductsvulnKEV agrega CVE-2026-71362 — Adobe / Commerce and Magento vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-67279 — MikroTik / RouterOSvulnKEV agrega CVE-2026-65660 — Microsoft / SharePointvulnKEV agrega CVE-2026-5430 — WSO2 / Multiple ProductsvulnKEV agrega CVE-2026-71362 — Adobe / Commerce and Magento vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services Engine
CVE Watch380,362 in full archive

Vulnerabilities exploitable today

380,362in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642

Distribution · last window

  • Critical
    2,263
  • High
    8,419
  • Medium
    6,836
  • Low
    751
Filters
Filters

Window

Severity

Flags

Vulnerabilities244,681–244,720 · 380,362
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-42452—
35.5%
——11——
CVE-2026-541326.8 MED
35.5%
——11Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.65d
CVE-2024-50616—
35.5%
——11——
CVE-2026-22207—
35.5%
——11——
CVE-2025-7787—
35.5%
——11——
CVE-2010-5250—
35.5%
——11——
CVE-2000-0392—
35.5%
——11——
CVE-2022-0123—
35.5%
——11——
CVE-2026-749987.2 HIG
35.5%
——11In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.17d
CVE-2026-778926.8 MED
35.5%
——11No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.22h
CVE-2021-44299—
35.5%
——11——
CVE-2017-3291—
35.5%
——11——
CVE-2024-27156—
35.5%
——11——
CVE-2026-729856.8 MED
35.5%
——11Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.22h
CVE-2024-11506—
35.5%
——11——
CVE-2024-21195—
35.5%
——11——
CVE-2024-46488—
35.5%
——11——
CVE-2024-8101—
35.5%
——11——
CVE-2025-1645—
35.5%
——11——
CVE-2024-9906—
35.5%
——11——
CVE-2023-6881—
35.5%
——11——
CVE-2026-694906.8 MED
35.5%
——11Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.22h
CVE-2025-59109—
35.5%
——11——
CVE-2026-713296.8 MED
35.5%
——11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.22h
CVE-2024-9320—
35.5%
——11——
CVE-2019-2444—
35.5%
——11——
CVE-2024-48868—
35.5%
——11——
CVE-2022-40274—
35.5%
——11——
CVE-2013-4459—
35.5%
——11——
CVE-2026-888767.5 HIG
35.5%
——11AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes without supplying the configured password.10d
CVE-2026-695666.8 MED
35.5%
——11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.22h
CVE-2017-17044—
35.5%
——11——
CVE-2026-156903.1 LOW
35.5%
——11A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference. The attack can be executed remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit is publicly available and might be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.73d
CVE-2005-4412—
35.5%
——11——
CVE-2015-2577—
35.5%
——11——
CVE-2024-0895—
35.5%
——11——
CVE-2025-64898—
35.5%
——11——
CVE-2026-120975.3 MED
35.5%
——11The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.79d
CVE-2026-357176.3 MED
35.5%
——11A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.65d
CVE-2019-1836—
35.5%
——11——