PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch380,233 in full archive

Vulnerabilities exploitable today

380,233in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,640

Distribution · last window

  • Critical
    2,360
  • High
    8,597
  • Medium
    7,170
  • Low
    799
Filters
Filters

Window

Severity

Flags

Vulnerabilities245,881–245,920 · 380,233
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2000-0367—
35.1%
——11——
CVE-2026-862237.3 HIG
35.1%
——11A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.17d
CVE-2000-0117—
35.1%
——11——
CVE-2026-703205.5 MED
35.1%
——11Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.42d
CVE-2025-701487.5 HIG
35.1%
——11Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).17d
CVE-2025-637479.8 CRI
35.1%
——11QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.83d
CVE-2026-703235.5 MED
35.1%
——11Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.42d
CVE-2022-34452—
35.1%
——11——
CVE-2026-153346.4 MED
35.1%
——11The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.63d
CVE-2026-668065.5 MED
35.1%
——11Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.42d
CVE-2012-5511—
35.1%
——11——
CVE-2006-6698—
35.0%
——11——
CVE-2026-711137.5 HIG
35.1%
——11Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).36d
CVE-2023-40314—
35.1%
——11——
CVE-2026-4801—
35.1%
——11——
CVE-2020-10139—
35.1%
——11——
CVE-2026-0647—
35.1%
——11——
CVE-2025-25617—
35.1%
——11——
CVE-2024-47779—
35.1%
——11——
CVE-2024-29278—
35.1%
——11——
CVE-2015-0378—
35.1%
——11——
CVE-2023-6993—
35.1%
——11——
CVE-2026-688095.5 MED
35.1%
——11Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.42d
CVE-2016-3815—
35.1%
——11——
CVE-2024-22496—
35.1%
——11——
CVE-2026-703105.5 MED
35.1%
——11Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.42d
CVE-2012-3440—
35.1%
——11——
CVE-2019-19662—
35.1%
——11——
CVE-2024-11049—
35.1%
——11——
CVE-2025-13242—
35.1%
——11——
CVE-2023-21907—
35.1%
——11——
CVE-2025-48293—
35.1%
——11——
CVE-2026-1112—
35.1%
——11——
CVE-2026-703255.5 MED
35.1%
——11Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.42d
CVE-2023-35649—
35.1%
——11——
CVE-2026-33124—
35.1%
——11——
CVE-2025-14988—
35.0%
——11——
CVE-2026-534224.3 MED
35.1%
——11Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3 with Canonicalize=false, unlike every other SFTP operation handler. This allows .. components in the requested path to bypass the is_within_root/2 check without being resolved. The un-canonicalized path then enters resolve_symlinks/2, which walks up the directory tree above the configured root and issues read_link() syscalls on arbitrary filesystem paths. An authenticated SFTP client can exploit this by sending a REALPATH request with a crafted traversal path. The server response differs depending on whether the target path exists on the host filesystem (SSH_FXP_NAME when the path resolves successfully, SSH_FX_NO_SUCH_FILE when it does not). This creates a path-existence oracle that an attacker can use to enumerate the filesystem structure outside the configured root, including the existence of sensitive files, directories, and mount points. The vulnerability leaks only the existence of paths. No file contents, credentials, or write access are obtainable through this issue alone. The information gained may assist further attacks when combined with other vulnerabilities. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routine ssh_sftpd:handle_op/4. This issue affects OTP from OTP 17.0 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssh from 3.0.1 before 6.0.2, 5.5.2.2 and 5.2.11.9.63d
CVE-2024-57407—
35.1%
——11——
CVE-2026-2546—
35.1%
——11——