PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch379,275 in full archive

Vulnerabilities exploitable today

379,275in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654

Distribution · last window

  • Critical
    2,375
  • High
    8,541
  • Medium
    7,074
  • Low
    796
Filters
Filters

Window

Severity

Flags

Vulnerabilities246,161–246,200 · 379,275
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15315
34.9%
10
CVE-2022-41500
34.9%
10
CVE-2023-45768
34.9%
10
CVE-2023-45767
34.9%
10
CVE-2024-1044
34.9%
10
CVE-2024-56525
34.9%
10
CVE-2022-3714
34.9%
10
CVE-2024-8154
34.9%
10
CVE-2024-54316
34.9%
10
CVE-2026-755897.5 HIG
34.9%
10Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings. A client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret.29d
CVE-2023-48410
34.9%
10
CVE-2026-778147.5 HIG
34.9%
10is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore satisfies the comparison, so where /data/images is allowed a request for /data/images_private/secret.txt is treated as trusted and served by FileResponse, disclosing files the confinement was meant to exclude. Whether the check applies depends on get_enable_access_control in scripts/iib/tool.py: it returns true when IIB_ACCESS_CONTROL is set to enable, false when set to disable, and otherwise true when the host Stable Diffusion WebUI was started with share, ngrok, listen or server_name, falling back to false. Confinement is therefore active in the network-exposed WebUI deployments that rely on it, while a standalone run with no such option serves every readable file regardless of this flaw. The fix compares against parent_path joined with os.sep.34d
CVE-2026-21726
34.9%
10
CVE-2026-584516.5 MED
34.9%
10Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation by appending sequences such as traversal segments after the matching prefix, causing file_get_contents() to read sensitive files whose contents are then exfiltrated as MIME parts in outgoing email; unauthenticated exploitation is also achievable via CSRF against an active authenticated session.72d
CVE-2019-19523
34.9%
10
CVE-2023-46068
34.9%
10
CVE-2025-0431
34.9%
10
CVE-2026-821009.6 CRI
34.9%
10IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.8d
CVE-2023-46613
34.9%
10
CVE-2026-771098.6 HIG
34.9%
10Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.15d
CVE-2022-22767
34.9%
10
CVE-2023-24975
34.9%
10
CVE-2024-39874
34.9%
10
CVE-2019-25525
34.9%
10
CVE-2022-23182
34.9%
10
CVE-2025-69035
34.9%
10
CVE-2026-43341
34.9%
10
CVE-2023-46069
34.9%
10
CVE-2023-45640
34.9%
10
CVE-2024-36046
34.9%
10
CVE-2025-51532
34.9%
10
CVE-2026-584204.4 MED
34.9%
10Local File Inclusion via file:// URI in Migration Restore29d
CVE-2024-44038
34.9%
10
CVE-2024-30278
34.9%
10
CVE-2025-7773
34.9%
10
CVE-2023-51067
34.9%
10
CVE-2024-5769
34.9%
10
CVE-2023-28673
34.9%
10
CVE-2024-12041
34.9%
10
CVE-2026-713496.8 MED
34.9%
10Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.2d