PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,377 in full archive

Vulnerabilities exploitable today

378,377in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,326
  • High
    8,522
  • Medium
    6,833
  • Low
    770
Filters
Filters

Window

Severity

Flags

Vulnerabilities253,041–253,080 · 378,377
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-6408
33.0%
10
CVE-2023-51367
33.0%
10
CVE-2016-4964
33.0%
10
CVE-2017-14558
33.0%
10
CVE-2015-7813
33.0%
10
CVE-2017-14286
33.0%
10
CVE-2022-24318
33.0%
10
CVE-2026-592248.0 HIG
33.0%
10Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query parameter, allowing query injection to make the terminal backend resolve another user identity; the HTTP proxy path also forwarded X-User-Id as an integrity-unbound identity claim. This issue is fixed in version 0.10.0.74d
CVE-2025-2212
33.0%
10
CVE-2025-60537
33.0%
10
CVE-2017-14288
33.0%
10
CVE-2017-14289
33.0%
10
CVE-2023-50303
33.0%
10
CVE-2024-20300
33.0%
10
CVE-2024-50350
33.0%
10
CVE-2025-57787
33.0%
10
CVE-2017-14287
33.0%
10
CVE-2017-14294
33.0%
10
CVE-2015-8701
33.0%
10
CVE-2017-14275
33.0%
10
CVE-2017-10740
33.0%
10
CVE-2019-25489
33.0%
10
CVE-2025-34106
33.0%
10
CVE-2026-568768.1 HIG
33.0%
10extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.78d
CVE-2026-202849.1 CRI
33.0%
10A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.4d
CVE-2022-3614
33.0%
10
CVE-2018-8842
33.0%
10
CVE-2017-14563
33.0%
10
CVE-2024-39776
33.0%
10
CVE-2016-3713
33.0%
10
CVE-2023-49501
32.9%
10
CVE-2008-4945
32.9%
10
CVE-2024-10875
32.9%
10
CVE-2023-6081
32.9%
10
CVE-2023-39918
32.9%
10
CVE-2025-27679
32.9%
10
CVE-2019-0086
32.9%
10
CVE-2026-22984
32.9%
10
CVE-2024-11683
32.9%
10
CVE-2026-81030
32.9%
10