PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,755 in full archive

Vulnerabilities exploitable today

378,755in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,413
  • High
    8,699
  • Medium
    6,979
  • Low
    789
Filters
Filters

Window

Severity

Flags

Vulnerabilities249,241–249,280 · 378,755
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-5525
34.0%
10
CVE-2024-96664.7 MED
34.0%
10A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.2d
CVE-2010-5224
34.0%
10
CVE-2024-35229
34.0%
10
CVE-2026-32733
34.0%
10
CVE-2025-8519
34.0%
10
CVE-2010-5231
34.0%
10
CVE-2020-15304
34.0%
10
CVE-2022-2237
34.0%
10
CVE-2025-30944
34.0%
10
CVE-2025-63679
34.0%
10
CVE-2010-5229
34.0%
10
CVE-2010-5273
34.0%
10
CVE-2002-2293
34.0%
10
CVE-2010-5235
34.0%
10
CVE-2023-4105
34.0%
10
CVE-2001-1593
34.0%
10
CVE-2024-3261
34.0%
10
CVE-2024-12559
34.0%
10
CVE-2023-32105
34.0%
10
CVE-2024-1868
34.0%
10
CVE-2026-845048.1 HIG
34.0%
10fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that satisfied the schema. An authenticated low-privilege caller can use this to make nested data replace the validated body and trigger an operation the route schema did not authorize, leading to unauthorized state changes and data disclosure. Users should upgrade to fastify 5.12.2 or later.7d
CVE-2021-1277
34.0%
10
CVE-2024-47417
34.0%
10
CVE-2026-115467.1 HIG
34.0%
10IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.83d
CVE-2026-862894.3 MED
34.0%
10A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component.11d
CVE-2023-46448
34.0%
10
CVE-2024-6888
34.0%
10
CVE-2026-15310
34.0%
10When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.6d
CVE-2025-63019
34.0%
10
CVE-2026-21676
34.0%
10
CVE-2010-5248
34.0%
10
CVE-2026-87791
34.0%
10A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.5d
CVE-2025-24432
34.0%
10
CVE-2005-3629
34.0%
10
CVE-2006-3786
34.0%
10
CVE-2026-866697.3 HIG
34.0%
10A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.15d
CVE-2007-5936
34.0%
10
CVE-2023-32742
34.0%
10
CVE-2023-32801
34.0%
10