PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,819 in full archive

Vulnerabilities exploitable today

378,819in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,414
  • High
    8,705
  • Medium
    6,988
  • Low
    790
Filters
Filters

Window

Severity

Flags

Vulnerabilities249,121–249,160 · 378,819
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54360
34.0%
10
CVE-2014-5509
34.0%
10
CVE-2016-6836
34.0%
10
CVE-2016-1420
34.0%
10
CVE-2025-22686
34.0%
10
CVE-2021-23227
34.0%
10
CVE-2026-2161
34.0%
10
CVE-2022-38195
34.0%
10
CVE-1999-0341
34.0%
10
CVE-1999-0340
34.0%
10
CVE-2026-12798
34.0%
10
CVE-2023-45715
34.0%
10
CVE-2026-637305.0 MED
34.0%
10HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist validation in the webhook handler to enumerate internal services, interact with internal containers, or access cloud instance metadata services including provider metadata endpoints.62d
CVE-2021-29082
34.0%
10
CVE-2016-5553
34.0%
10
CVE-2011-5119
34.0%
10
CVE-2004-0471
34.0%
10
CVE-2009-3290
34.0%
10
CVE-2015-4526
34.0%
10
CVE-2025-10978
34.0%
10
CVE-2020-1738
34.0%
10
CVE-2023-40483
34.0%
10
CVE-2004-1079
34.0%
10
CVE-2011-5118
34.0%
10
CVE-2024-5856
34.0%
10
CVE-2026-130606.5 MED
34.0%
10An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.49d
CVE-2023-21524
34.0%
10
CVE-2026-344308.8 HIG
34.0%
10ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.71d
CVE-2022-40290
34.0%
10
CVE-2003-0452
34.0%
10
CVE-2026-7301
34.0%
10
CVE-2024-52924
34.0%
10
CVE-2024-49419
34.0%
10
CVE-2026-31799
34.0%
10
CVE-2024-4482
34.0%
10
CVE-2024-51812
34.0%
10
CVE-2026-94914.3 MED
34.0%
10A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.21d
CVE-2018-15470
34.0%
10
CVE-2025-10979
34.0%
10
CVE-2024-51834
34.0%
10