PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,183 in full archive

Vulnerabilities exploitable today

378,183in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,332
  • High
    8,494
  • Medium
    6,769
  • Low
    765
Filters
Filters

Window

Severity

Flags

Vulnerabilities254,601–254,640 · 378,183
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68537
32.5%
10
CVE-2026-3489
32.5%
10
CVE-2026-492537.1 HIG
32.5%
10electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/zmodem.js, prepareReceiveFile() joins the filename to the user-selected save path, and in src/app/server/trzsz.js, getUniqueFilePath(), the openSaveFile() callback, and the savedFilePaths mapping construct destinations without sanitization. A malicious SSH server or remote shell can provide a filename containing traversal components such as ../escaped.txt or ../../.bashrc. When the victim accepts the transfer and selects a download directory, electerm can write outside that directory and overwrite files accessible to the desktop user, potentially changing sensitive configuration or impairing availability. This issue is fixed in version 3.11.11.12d
CVE-2022-4614
32.5%
10
CVE-2010-3877
32.5%
10
CVE-2005-1751
32.5%
10
CVE-2006-1355
32.5%
10
CVE-2010-4072
32.5%
10
CVE-2019-15347
32.5%
10
CVE-2007-0669
32.5%
10
CVE-2016-2779
32.5%
10
CVE-2001-0920
32.5%
10
CVE-2014-2292
32.5%
10
CVE-2019-25444
32.5%
10
CVE-2025-64481
32.5%
10
CVE-2024-47302
32.5%
10
CVE-2011-0794
32.5%
10
CVE-2016-5729
32.5%
10
CVE-2026-339976.8 MED
32.5%
10Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.12d
CVE-2015-0767
32.5%
10
CVE-2024-47657
32.5%
10
CVE-2021-37177
32.5%
10
CVE-2023-30497
32.5%
10
CVE-2026-487638.2 HIG
32.5%
10TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact key. Because the endpoint only checks that the referenced typebot is public and that the referenced block is a file input block, an unauthenticated attacker who knows a valid public `typebotId` and `blockId` can request presigned upload URLs for arbitrary objects in the shared bucket, including `private/...` and other tenants' `public/...` paths. Version 3.17.0 fixes this issue.12d
CVE-2014-2173
32.5%
10
CVE-2025-54152
32.5%
10
CVE-2014-3811
32.5%
10
CVE-2025-2340
32.5%
10
CVE-2024-26132
32.5%
10
CVE-2026-29046
32.5%
10
CVE-2025-1972
32.5%
10
CVE-2026-693435.5 MED
32.5%
10Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally.5d
CVE-2023-35097
32.5%
10
CVE-2023-40601
32.5%
10
CVE-2026-449467.4 HIG
32.5%
10A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,81d
CVE-2016-4036
32.5%
10
CVE-2018-8883
32.5%
10
CVE-2019-16089
32.5%
10
CVE-2026-627405.5 MED
32.5%
10Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.36d
CVE-2026-696275.5 MED
32.5%
10Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.6d