PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,819 in full archive

Vulnerabilities exploitable today

378,819in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,414
  • High
    8,705
  • Medium
    6,988
  • Low
    790
Filters
Filters

Window

Severity

Flags

Vulnerabilities249,161–249,200 · 378,819
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-1738
34.0%
10
CVE-2020-4992
34.0%
10
CVE-2024-54243
34.0%
10
CVE-2026-30998
34.0%
10
CVE-2025-46205
34.0%
10
CVE-2026-692507.5 HIG
34.0%
10Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without authentication, triggered outbound POST requests to an attacker-controlled server, reflected the full remote response body to the caller through tokenInfo, and sent client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body. This issue is fixed in version 3.1.3.9d
CVE-2017-5669
34.0%
10
CVE-2026-76243
34.0%
10stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.29d
CVE-2021-45442
34.0%
10
CVE-2024-5662
34.0%
10
CVE-2023-5416
34.0%
10
CVE-2011-0685
34.0%
10
CVE-2026-854497.5 HIG
34.0%
10MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPORT data to cause memory exhaustion and stall the operator display without authentication.15d
CVE-2023-34262
34.0%
10
CVE-2024-6936
34.0%
10
CVE-2026-582785.4 MED
34.0%
10Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.79d
CVE-2024-24195
34.0%
10
CVE-2026-937487.5 HIG
34.0%
10http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.4d
CVE-2026-120647.5 HIG
34.0%
10When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.8d
CVE-2025-62711
34.0%
10
CVE-2024-54272
34.0%
10
CVE-2023-29237
34.0%
10
CVE-2026-839495.5 MED
34.0%
10Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.14d
CVE-2026-839515.5 MED
34.0%
10Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.14d
CVE-2020-10588
34.0%
10
CVE-2022-48361
34.0%
10
CVE-2026-40104
34.0%
10
CVE-2011-4338
34.0%
10
CVE-2016-1420
34.0%
10
CVE-2022-38195
34.0%
10
CVE-2014-5509
34.0%
10
CVE-2024-54360
34.0%
10
CVE-2021-23227
34.0%
10
CVE-1999-0340
34.0%
10
CVE-1999-0341
34.0%
10
CVE-2025-22686
34.0%
10
CVE-2016-6836
34.0%
10
CVE-2026-2161
34.0%
10
CVE-2004-0471
34.0%
10
CVE-2026-637305.0 MED
34.0%
10HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist validation in the webhook handler to enumerate internal services, interact with internal containers, or access cloud instance metadata services including provider metadata endpoints.62d