PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch380,233 in full archive

Vulnerabilities exploitable today

380,233in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,640

Distribution · last window

  • Critical
    2,316
  • High
    8,470
  • Medium
    6,946
  • Low
    766
Filters
Filters

Window

Severity

Flags

Vulnerabilities245,681–245,720 · 380,233
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-34473—
35.1%
——11——
CVE-2024-44843—
35.1%
——11——
CVE-2019-6488—
35.1%
——11——
CVE-2024-8561—
35.1%
——11——
CVE-2025-2517—
35.1%
——11——
CVE-2020-37183—
35.1%
——11——
CVE-2016-7909—
35.1%
——11——
CVE-2019-11850—
35.1%
——11——
CVE-2021-44421—
35.1%
——11——
CVE-2026-144078.8 HIG
35.1%
——11Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)85d
CVE-2026-65759—
35.1%
——11Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.64d
CVE-2025-69143—
35.1%
——11——
CVE-2022-34758—
35.1%
——11——
CVE-2022-23490—
35.1%
——11——
CVE-2026-91778—
35.1%
——11In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.9d
CVE-2025-69149—
35.1%
——11——
CVE-2025-69163—
35.1%
——11——
CVE-2025-69114—
35.1%
——11——
CVE-2023-38559—
35.1%
——11——
CVE-2023-50571—
35.1%
——11——
CVE-2024-27623—
35.1%
——11——
CVE-2024-1584—
35.1%
——11——
CVE-2025-57816—
35.1%
——11——
CVE-2020-3216—
35.1%
——11——
CVE-2025-69148—
35.1%
——11——
CVE-2024-36411—
35.1%
——11——
CVE-2026-40543—
35.1%
——11SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information. This issue affects SOPlanning version 1.55 and below.65d
CVE-2025-69173—
35.1%
——11——
CVE-2026-585226.8 MED
35.1%
——11Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.80d
CVE-2025-31424—
35.1%
——11——
CVE-2019-5982—
35.1%
——11——
CVE-2024-52983—
35.1%
——11——
CVE-2017-10998—
35.1%
——11——
CVE-2026-68929—
35.1%
——11FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result, an unauthenticated attacker who knows a victim team's shareId can take that team's WeChat bot offline or hijack the channel to their own bot: the logout endpoint is gated only by an existence check yet wipes the outLink's stored WeChat token, and the QR-code status endpoint performs no authorization at all and writes attacker-supplied bot credentials into the outLink identified by shareId. By generating a QR for a victim shareId, scanning it with their own WeChat, and calling the status endpoint, an attacker binds the victim team's app to the attacker's bot, exposing the app's private responses, displacing the legitimate binding, and consuming the victim's resources. The shareId is exposed in every shared chat URL, iframe, and embed, so it is not a secret. This issue is fixed in version 4.15.2.28d
CVE-2026-820206.8 MED
35.1%
——11Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.17d
CVE-2024-8794—
35.1%
——11——
CVE-2025-69172—
35.1%
——11——
CVE-2025-69106—
35.1%
——11——
CVE-2026-731806.8 MED
35.1%
——11Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.29d
CVE-2026-44775—
35.1%
——11——