PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,377 in full archive

Vulnerabilities exploitable today

378,377in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,326
  • High
    8,522
  • Medium
    6,833
  • Low
    770
Filters
Filters

Window

Severity

Flags

Vulnerabilities253,201–253,240 · 378,377
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25029
32.9%
10
CVE-2026-79754
32.9%
10Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.build.tempDir field before using it to construct a shell command. When the Kaniko container builder is enabled, a user with function-create permission can inject shell metacharacters into this field and achieve arbitrary command execution inside the Dashboard container, which runs with a Kubernetes service account holding wildcard access to Secrets, Pods, Jobs, and Deployments in its namespace. This issue has been patched in version 1.17.2.20d
CVE-2021-4400
32.9%
10
CVE-2021-4405
32.9%
10
CVE-2025-2250
32.9%
10
CVE-2025-603069.9 CRI
32.9%
10code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.80d
CVE-2022-42942
32.9%
10
CVE-2024-2820
32.9%
10
CVE-2008-4941
32.9%
10
CVE-2026-8994
32.9%
10
CVE-2026-781864.3 MED
32.9%
10A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. It is recommended to apply a patch to fix this issue.29d
CVE-2022-41309
32.9%
10
CVE-2008-4970
32.9%
10
CVE-2021-32557
32.9%
10
CVE-2020-29484
32.9%
10
CVE-2015-0238
32.9%
10
CVE-2023-31245
32.9%
10
CVE-2023-25148
32.9%
10
CVE-2008-4982
32.9%
10
CVE-2025-1918
32.9%
10
CVE-2026-3287
32.9%
10
CVE-2023-47548
32.9%
10
CVE-2021-4403
32.9%
10
CVE-2024-43009
32.9%
10
CVE-2008-4973
32.9%
10
CVE-2022-42939
32.9%
10
CVE-2024-7383
32.9%
10
CVE-2023-46854
32.9%
10
CVE-2024-0805
32.9%
10
CVE-2024-45159
32.9%
10
CVE-2022-40680
32.9%
10
CVE-2026-384319.8 CRI
32.9%
10ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.60d
CVE-2008-4964
32.9%
10
CVE-2017-5957
32.9%
10
CVE-2021-4398
32.9%
10
CVE-2023-7038
32.9%
10
CVE-2025-26304
32.9%
10
CVE-2023-28416
32.9%
10
CVE-2026-71393
32.9%
10GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap allocation. A subsequent read() call writes beyond the buffer, causing a heap buffer overflow. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This can lead to heap memory corruption and potential code execution. This issue was fixed in commit d51a4722316efe0960994d371e1859099894d1ca25d
CVE-2023-50235
32.9%
10