PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch379,124 in full archive

Vulnerabilities exploitable today

379,124in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654

Distribution · last window

  • Critical
    2,385
  • High
    8,589
  • Medium
    7,035
  • Low
    793
Filters
Filters

Window

Severity

Flags

Vulnerabilities247,201–247,240 · 379,124
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-0146
34.6%
10
CVE-2023-22718
34.6%
10
CVE-2023-25020
34.6%
10
CVE-2023-6742
34.6%
10
CVE-2022-4227
34.6%
10
CVE-2025-59330
34.6%
10
CVE-2024-21001
34.6%
10
CVE-2022-45838
34.6%
10
CVE-2010-2489
34.6%
10
CVE-2002-1551
34.6%
10
CVE-2022-22811
34.6%
10
CVE-2022-30623
34.6%
10
CVE-2024-400839.6 CRI
34.6%
10A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via sscanf reading the token and timezone JSON fields into a fixed-length buffer.81d
CVE-2024-1080
34.6%
10
CVE-2024-13597
34.6%
10
CVE-2021-40833
34.6%
10
CVE-2024-36422
34.6%
10
CVE-2023-47656
34.6%
10
CVE-2019-8758
34.6%
10
CVE-2024-37993
34.6%
10
CVE-2024-5710
34.6%
10
CVE-2026-278517.4 HIG
34.6%
10When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.71d
CVE-2025-7216
34.6%
10
CVE-2024-23171
34.6%
10
CVE-2023-34017
34.6%
10
CVE-2024-0897
34.6%
10
CVE-2023-41626
34.6%
10
CVE-2023-25713
34.6%
10
CVE-2026-348256.5 MED
34.6%
10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who triggers a workflow containing a SQL node with template variables from user-controlled data can inject arbitrary SQL. This issue has been patched in version 2.0.30.61d
CVE-2024-33327
34.6%
10
CVE-2024-21383
34.6%
10
CVE-2026-540768.1 HIG
34.6%
10ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and engine/src/main/java/com/arcadedb/schema/LocalProperty.java remained unchecked. An authenticated identity, including a read-only API token without UPDATE_SCHEMA permission, can use DROP PROPERTY, ALTER TYPE, or ALTER PROPERTY through the database command/query HTTP endpoints to rename types, change inheritance, alter aliases or buckets, drop properties, and change property constraints. The issue does not directly disclose or write record data, but unauthorized schema mutation can corrupt the meaning of stored records and breach the documented permission model. This issue is fixed in version 26.6.1.8d
CVE-2013-5781
34.6%
10
CVE-2025-59141
34.6%
10
CVE-2008-2576
34.6%
10
CVE-2024-23178
34.6%
10
CVE-2026-46553
34.6%
10
CVE-2023-23979
34.6%
10
CVE-2026-387545.1 MED
34.6%
10A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.63d
CVE-2023-27421
34.6%
10