PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,916 in full archive

Vulnerabilities exploitable today

378,916in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,357
  • High
    8,518
  • Medium
    6,901
  • Low
    784
Filters
Filters

Window

Severity

Flags

Vulnerabilities247,881–247,920 · 378,916
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2007-0003
34.4%
10
CVE-2026-28029
34.4%
10
CVE-2001-1553
34.4%
10
CVE-2026-27991
34.4%
10
CVE-2022-0135
34.4%
10
CVE-2024-33602
34.4%
10
CVE-2022-2773
34.4%
10
CVE-2025-54715
34.4%
10
CVE-2023-2328
34.4%
10
CVE-2026-28097
34.4%
10
CVE-2026-28012
34.4%
10
CVE-2026-419377.2 HIG
34.4%
10Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containing a plugin.php with a valid Slug header and a public/index.php file with arbitrary PHP code, which executes as the web server user once accessed via subsequent unauthenticated HTTP requests to the plugin's public path.71d
CVE-2014-8583
34.4%
10
CVE-2022-40968
34.4%
10
CVE-2026-27340
34.4%
10
CVE-2023-1429
34.4%
10
CVE-2023-25756
34.4%
10
CVE-2024-3047
34.4%
10
CVE-2026-832668.2 HIG
34.4%
10Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).2d
CVE-2022-2768
34.4%
10
CVE-2024-2595
34.4%
10
CVE-2025-58455
34.4%
10
CVE-2025-59487
34.4%
10
CVE-2025-9013
34.4%
10
CVE-2026-28085
34.4%
10
CVE-2026-27334
34.4%
10
CVE-2026-28095
34.4%
10
CVE-2026-28090
34.4%
10
CVE-2026-28031
34.4%
10
CVE-2026-28007
34.4%
10
CVE-2026-27995
34.4%
10
CVE-2026-32500
34.4%
10
CVE-2026-49342
34.4%
10
CVE-2025-8957
34.4%
10
CVE-2026-3693
34.4%
10
CVE-2020-1733
34.4%
10
CVE-2026-27079
34.4%
10
CVE-2026-28018
34.4%
10
CVE-2025-12253
34.4%
10
CVE-2026-618936.5 MED
34.4%
10A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.15d