PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,819 in full archive

Vulnerabilities exploitable today

378,819in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,414
  • High
    8,696
  • Medium
    6,987
  • Low
    790
Filters
Filters

Window

Severity

Flags

Vulnerabilities248,721–248,760 · 378,819
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9667
34.2%
10
CVE-2010-5264
34.2%
10
CVE-2007-4591
34.2%
10
CVE-2023-34291
34.2%
10
CVE-2001-1387
34.2%
10
CVE-2010-2532
34.2%
10
CVE-2023-34161
34.2%
10
CVE-2023-37347
34.2%
10
CVE-2025-49438
34.2%
10
CVE-2023-3196
34.2%
10
CVE-2025-0934
34.2%
10
CVE-2008-3866
34.2%
10
CVE-2011-2473
34.2%
10
CVE-2023-34311
34.2%
10
CVE-2024-2241
34.2%
10
CVE-2021-41527
34.2%
10
CVE-2019-14239
34.2%
10
CVE-2023-29680
34.1%
10
CVE-2026-21670
34.1%
10
CVE-2026-545208.1 HIG
34.1%
10AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved workflow directory. An authenticated user who can create or modify workflow file steps can supply traversal segments to escape the intended workspace and read sensitive files or write and overwrite files accessible to the backend process, including application-adjacent files when process permissions allow. This issue is fixed in version 0.9.1.5d
CVE-2023-5894
34.1%
10
CVE-2019-0035
34.1%
10
CVE-2024-11522
34.1%
10
CVE-2023-47716
34.1%
10
CVE-2023-0313
34.1%
10
CVE-2022-41919
34.1%
10
CVE-2023-27612
34.1%
10
CVE-2023-39224
34.1%
10
CVE-2024-11615
34.1%
10
CVE-2024-11533
34.1%
10
CVE-2026-334344.3 MED
34.1%
10Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unconditionally overwrite the general rate limit result. When the global max_request_per_minute is exceeded, requests to /events still succeed if the events-specific counter (hardcoded 30/min) has not been reached. This allows event injection into analysisd beyond the admin-configured global rate limit. This issue has been fixed in version 4.14.5.65d
CVE-2025-62055
34.1%
10
CVE-2024-2404
34.1%
10
CVE-2016-3834
34.1%
10
CVE-2022-34323
34.1%
10
CVE-2026-95217.3 HIG
34.1%
10A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 5.2.5 is able to address this issue. The name of the patch is 66d16516e24893bebc1c8af52bf2fe9ad0735061. Upgrading the affected component is advised.62d
CVE-2026-54523
34.1%
10
CVE-2004-2414
34.1%
10
CVE-2014-125109
34.1%
10
CVE-2026-333908.1 HIG
34.1%
10An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.43d