PULSE
FEED
vulnKEV agrega CVE-2026-67279 — MikroTik / RouterOSvulnKEV agrega CVE-2026-65660 — Microsoft / SharePointvulnKEV agrega CVE-2026-5430 — WSO2 / Multiple ProductsvulnKEV agrega CVE-2026-71362 — Adobe / Commerce and Magento vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-67279 — MikroTik / RouterOSvulnKEV agrega CVE-2026-65660 — Microsoft / SharePointvulnKEV agrega CVE-2026-5430 — WSO2 / Multiple ProductsvulnKEV agrega CVE-2026-71362 — Adobe / Commerce and Magento vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services Engine
CVE Watch380,362 in full archive

Vulnerabilities exploitable today

380,362in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642

Distribution · last window

  • Critical
    2,263
  • High
    8,419
  • Medium
    6,836
  • Low
    751
Filters
Filters

Window

Severity

Flags

Vulnerabilities244,721–244,760 · 380,362
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-49143—
35.5%
——11——
CVE-2026-506686.8 MED
35.5%
——11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.65d
CVE-2026-598493.1 LOW
35.5%
——11A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.3d
CVE-2025-670399.8 CRI
35.5%
——11An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.21d
CVE-2025-59526—
35.5%
——11——
CVE-2025-5062—
35.5%
——11——
CVE-2018-16878—
35.5%
——11——
CVE-2018-17450—
35.5%
——11——
CVE-2025-10487—
35.5%
——11——
CVE-2024-7309—
35.5%
——11——
CVE-2026-34354—
35.5%
——11——
CVE-2024-11517—
35.5%
——11——
CVE-2022-3449—
35.5%
——11——
CVE-2026-48152—
35.5%
——11——
CVE-2026-21508—
35.5%
——11——
CVE-2026-15289—
35.5%
——11——
CVE-2026-626996.8 MED
35.5%
——11Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.40d
CVE-2023-3226—
35.5%
——11——
CVE-2015-2577—
35.5%
——11——
CVE-2025-33202—
35.4%
——11——
CVE-2024-46488—
35.5%
——11——
CVE-2024-8101—
35.5%
——11——
CVE-2024-21195—
35.5%
——11——
CVE-2024-27156—
35.5%
——11——
CVE-2026-491686.8 MED
35.5%
——11Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.65d
CVE-2026-688336.8 MED
35.5%
——11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.22h
CVE-2026-348815.0 MED
35.5%
——11OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.42d
CVE-2025-10485—
35.5%
——11——
CVE-2026-778926.8 MED
35.5%
——11No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.22h
CVE-2024-22002—
35.5%
——11——
CVE-2024-11506—
35.5%
——11——
CVE-2017-3291—
35.5%
——11——
CVE-2025-1645—
35.5%
——11——
CVE-2019-1836—
35.5%
——11——
CVE-2026-357166.3 MED
35.5%
——11A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries.65d
CVE-2026-193613.7 LOW
35.5%
——11A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.43d
CVE-2026-447275.4 MED
35.5%
——11Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed in 2.20.28d
CVE-2023-5909—
35.5%
——11——
CVE-2026-888767.5 HIG
35.5%
——11AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes without supplying the configured password.10d
CVE-2026-695666.8 MED
35.5%
——11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.22h