PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,183 in full archive

Vulnerabilities exploitable today

378,183in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,332
  • High
    8,494
  • Medium
    6,769
  • Low
    765
Filters
Filters

Window

Severity

Flags

Vulnerabilities254,641–254,680 · 378,183
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-4036
32.5%
10
CVE-2019-16089
32.5%
10
CVE-2005-1751
32.5%
10
CVE-2006-1355
32.5%
10
CVE-2019-15347
32.5%
10
CVE-2010-0622
32.5%
10
CVE-2014-3811
32.5%
10
CVE-2024-49396
32.5%
10
CVE-2013-3496
32.5%
10
CVE-2015-1144
32.5%
10
CVE-2019-19056
32.5%
10
CVE-2020-35923
32.5%
10
CVE-2021-40829
32.5%
10
CVE-2020-35921
32.5%
10
CVE-2025-30475
32.5%
10
CVE-2024-50423
32.5%
10
CVE-2026-100755.3 MED
32.5%
10DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.62d
CVE-2023-20180
32.5%
10
CVE-2025-1830
32.5%
10
CVE-2022-3233
32.5%
10
CVE-2020-4497
32.5%
10
CVE-2026-818295.3 MED
32.5%
10A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.6h
CVE-2024-8189
32.5%
10
CVE-2026-33755
32.5%
10
CVE-2025-69227
32.5%
10
CVE-2025-59221
32.5%
10
CVE-2026-812707.5 HIG
32.5%
10Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.13d
CVE-2026-693445.5 MED
32.5%
10Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.4d
CVE-2024-57189
32.5%
10
CVE-2026-696275.5 MED
32.5%
10Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.6d
CVE-2026-692865.5 MED
32.5%
10Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.5d
CVE-2026-627405.5 MED
32.5%
10Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.36d
CVE-2014-1226
32.5%
10
CVE-2023-44148
32.5%
10
CVE-2021-1439
32.5%
10
CVE-2026-62672
32.5%
10Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). When security.twig_content.process_enabled is enabled, an authenticated page editor can publish a catastrophically backtracking pattern that consumes PHP worker CPU and denies service to site visitors. This issue is fixed in version 2.0.4.12d
CVE-2024-29471
32.5%
10
CVE-2025-34304
32.5%
10
CVE-2026-871788.7 HIG
32.5%
10Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).3d
CVE-2024-44019
32.5%
10