PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch378,631 in full archive

Vulnerabilities exploitable today

378,631in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652

Distribution · last window

  • Critical
    2,396
  • High
    8,640
  • Medium
    6,936
  • Low
    787
Filters
Filters

Window

Severity

Flags

Vulnerabilities250,841–250,880 · 378,631
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-42125
33.6%
10
CVE-2019-5679
33.6%
10
CVE-2007-4526
33.6%
10
CVE-2015-7869
33.6%
10
CVE-2021-27704
33.6%
10
CVE-2026-73648
33.6%
10rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.4d
CVE-2026-408985.3 MED
33.6%
10quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large values. The implementation builds an `http.Header` for the corresponding `http.Request` or `http.Response`, while only enforcing limits on the size of the QPACK-compressed HEADERS frame, not on the decoded field section. This can lead to memory exhaustion. This is very similar to CVE-2025-64702. The difference is that this issue uses HTTP trailers, rather than HTTP headers, as the attack vector. A misbehaving or malicious peer can cause a denial-of-service (DoS) attack against quic-go's HTTP/3 servers or clients by triggering excessive memory allocation, potentially leading to crashes or resource exhaustion. This affects both servers and clients due to symmetric header construction. Version 0.59.1 enforces RFC 9114 decoded field section size limits for trailers as well. It incrementally decodes QPACK entries and checks the field section size after each entry, aborting the stream if an entry causes the limit to be exceeded.62d
CVE-2002-0971
33.6%
10
CVE-2006-0576
33.6%
10
CVE-2024-51737
33.6%
10
CVE-2012-6333
33.6%
10
CVE-2023-42126
33.6%
10
CVE-2019-8529
33.6%
10
CVE-2026-342278.8 HIG
33.6%
10Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser. This issue has been patched in version 1.7.4.60d
CVE-2024-4363
33.6%
10
CVE-2023-23672
33.6%
10
CVE-2010-4656
33.6%
10
CVE-2024-31525
33.6%
10
CVE-2004-0966
33.6%
10
CVE-2023-5211
33.6%
10
CVE-2003-0607
33.6%
10
CVE-2006-1451
33.6%
10
CVE-2014-0972
33.6%
10
CVE-2009-1295
33.6%
10
CVE-2017-11130
33.6%
10
CVE-2013-4361
33.6%
10
CVE-2010-5331
33.6%
10
CVE-2010-3846
33.6%
10
CVE-2019-2955
33.6%
10
CVE-2019-0070
33.6%
10
CVE-2026-56701
33.6%
10
CVE-2014-9715
33.6%
10
CVE-2025-8436
33.6%
10
CVE-2024-22473
33.6%
10
CVE-2018-15371
33.6%
10
CVE-2026-733508.2 HIG
33.6%
10Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.33d
CVE-2025-58716
33.6%
10
CVE-2024-0007
33.6%
10
CVE-2025-7518
33.6%
10
CVE-2026-117217.5 HIG
33.6%
10It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.62d