PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,819 in full archive

Vulnerabilities exploitable today

378,819in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,412
  • High
    8,681
  • Medium
    6,983
  • Low
    790
Filters
Filters

Window

Severity

Flags

Vulnerabilities248,481–248,520 · 378,819
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-7163
34.2%
10
CVE-2024-22279
34.2%
10
CVE-2024-11786
34.2%
10
CVE-2024-46874
34.2%
10
CVE-2025-62466
34.2%
10
CVE-2026-841088.1 HIG
34.2%
10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.18h
CVE-2026-41502
34.2%
10
CVE-2026-477326.5 MED
34.2%
10Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.69d
CVE-2026-813905.5 MED
34.2%
10Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.6d
CVE-2026-840829.8 CRI
34.2%
10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.10h
CVE-2026-737128.1 HIG
34.2%
10A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.20d
CVE-2025-60713
34.2%
10
CVE-2022-28887
34.2%
10
CVE-2014-6184
34.2%
10
CVE-2026-925768.6 HIG
34.2%
10HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.7d
CVE-2023-24031
34.2%
10
CVE-2017-5688
34.2%
10
CVE-2025-48742
34.2%
10
CVE-2015-0530
34.2%
10
CVE-2024-7132
34.2%
10
CVE-2026-534476.5 MED
34.2%
10Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.69d
CVE-2024-5143
34.2%
10
CVE-2025-55233
34.2%
10
CVE-2026-340447.7 HIG
34.2%
10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the current team, allowing an authenticated user to access logs for applications owned by other teams by supplying a victim resource UUID. This issue is fixed in version 4.0.0-beta.466.76d
CVE-2018-18913
34.2%
10
CVE-2022-1204
34.2%
10
CVE-2014-2673
34.2%
10
CVE-2024-11147
34.2%
10
CVE-2025-12808
34.2%
10
CVE-2025-22251
34.2%
10
CVE-2017-18648
34.2%
10
CVE-2026-579496.5 MED
34.2%
10ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.71d
CVE-2026-2109
34.2%
10
CVE-2026-940839.4 CRI
34.2%
10Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.18h
CVE-2026-59853
34.2%
10
CVE-2026-56695
34.2%
10
CVE-2026-940849.4 CRI
34.2%
10Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.18h
CVE-2024-12982
34.2%
10
CVE-2024-47832
34.2%
10
CVE-2017-6007
34.2%
10