PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,631 in full archive

Vulnerabilities exploitable today

378,631in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,396
  • High
    8,640
  • Medium
    6,936
  • Low
    787
Filters
Filters

Window

Severity

Flags

Vulnerabilities250,601–250,640 · 378,631
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6963
33.7%
10
CVE-2023-23143
33.7%
10
CVE-2026-697705.5 MED
33.7%
10Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.6h
CVE-2026-696725.5 MED
33.7%
10Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.7h
CVE-2026-625998.6 HIG
33.7%
10Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. While the vulnerability is in Oracle Trading Community, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).22d
CVE-2021-22118
33.7%
10
CVE-2017-9969
33.7%
10
CVE-2001-0104
33.7%
10
CVE-1999-0900
33.7%
10
CVE-1999-0319
33.7%
10
CVE-2025-7784
33.7%
10
CVE-2026-2381
33.7%
10
CVE-2025-35965
33.7%
10
CVE-1999-0297
33.7%
10
CVE-2026-47383
33.7%
10
CVE-2022-20824
33.7%
10
CVE-2025-10707
33.7%
10
CVE-2015-5833
33.7%
10
CVE-2016-6724
33.7%
10
CVE-2017-20020
33.7%
10
CVE-1999-0339
33.7%
10
CVE-2025-69213
33.7%
10
CVE-2025-54014
33.7%
10
CVE-2024-5005
33.7%
10
CVE-2026-693035.5 MED
33.7%
10Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.14d
CVE-2023-49813
33.7%
10
CVE-2024-27346
33.6%
10
CVE-2025-63917
33.6%
10
CVE-2026-770879.6 CRI
33.6%
10Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.32d
CVE-2024-23125
33.6%
10
CVE-2015-0413
33.6%
10
CVE-2004-0563
33.6%
10
CVE-2017-16646
33.6%
10
CVE-2024-32131
33.6%
10
CVE-2026-43995
33.6%
10
CVE-2024-7878
33.6%
10
CVE-2021-47848
33.6%
10
CVE-2025-11177
33.6%
10
CVE-2005-3268
33.6%
10
CVE-2019-10224
33.6%
10