PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,377 in full archive

Vulnerabilities exploitable today

378,377in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,326
  • High
    8,522
  • Medium
    6,833
  • Low
    770
Filters
Filters

Window

Severity

Flags

Vulnerabilities253,001–253,040 · 378,377
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-5062
33.0%
10
CVE-2017-14556
33.0%
10
CVE-2024-20264
33.0%
10
CVE-2023-30314
33.0%
10
CVE-2017-14290
33.0%
10
CVE-2022-0071
33.0%
10
CVE-2017-14548
33.0%
10
CVE-2017-14538
33.0%
10
CVE-2016-8813
33.0%
10
CVE-2025-26306
33.0%
10
CVE-2025-65075
33.0%
10
CVE-2022-2454
33.0%
10
CVE-2013-5866
33.0%
10
CVE-2015-1992
33.0%
10
CVE-2023-29192
33.0%
10
CVE-2017-10749
33.0%
10
CVE-2024-49764
33.0%
10
CVE-2017-14575
33.0%
10
CVE-2025-5096
33.0%
10
CVE-2017-10750
33.0%
10
CVE-2024-45786
33.0%
10
CVE-2017-14692
33.0%
10
CVE-2016-8815
33.0%
10
CVE-2026-193635.3 MED
33.0%
10A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs` logs raw Authorization header values and complete bearer tokens/JWTs on authentication failure paths, potentially exposing credentials through CloudWatch Logs. `src/models.rs` serializes the complete validated JWT claims set with `serde_json::to_string(token_claims).unwrap()` and propagates it through `context["jwtClaims"]` to downstream integrations. This code performs serialization, not deserialization, and does not process attacker-controlled `jwtClaims` input. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.41d
CVE-2017-14573
33.0%
10
CVE-2026-27125
33.0%
10
CVE-2024-30618
33.0%
10
CVE-2017-14580
33.0%
10
CVE-2022-29580
33.0%
10
CVE-2025-2910
33.0%
10
CVE-2022-3267
33.0%
10
CVE-2023-32260
33.0%
10
CVE-2026-635236.5 MED
33.0%
10Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.6d
CVE-2025-26309
33.0%
10
CVE-2026-25165
33.0%
10
CVE-2023-51553
33.0%
10
CVE-2025-26307
33.0%
10
CVE-2024-32315
33.0%
10
CVE-2025-43308
33.0%
10
CVE-2024-12184
33.0%
10