PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,183 in full archive

Vulnerabilities exploitable today

378,183in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,332
  • High
    8,494
  • Medium
    6,769
  • Low
    765
Filters
Filters

Window

Severity

Flags

Vulnerabilities255,001–255,040 · 378,183
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-54329
32.4%
10
CVE-2026-729804.4 MED
32.4%
10Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.4d
CVE-2023-42547
32.4%
10
CVE-2024-6286
32.4%
10
CVE-2023-1981
32.4%
10
CVE-2024-34590
32.4%
10
CVE-2019-18897
32.4%
10
CVE-2023-40271
32.4%
10
CVE-2023-1732
32.4%
10
CVE-2021-24618
32.4%
10
CVE-2006-1506
32.4%
10
CVE-2026-825388.8 HIG
32.4%
10ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.7d
CVE-1999-1197
32.4%
10
CVE-2004-0831
32.4%
10
CVE-2025-503278.8 HIG
32.4%
10An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism59d
CVE-2020-4005
32.4%
10
CVE-2024-48783
32.4%
10
CVE-2015-0665
32.4%
10
CVE-1999-1396
32.4%
10
CVE-2023-42551
32.4%
10
CVE-2024-51257
32.4%
10
CVE-2024-28823
32.4%
10
CVE-2023-38826
32.4%
10
CVE-2023-21949
32.4%
10
CVE-2024-13403
32.4%
10
CVE-2014-1929
32.4%
10
CVE-2016-5242
32.4%
10
CVE-2023-47543
32.4%
10
CVE-2022-41919
32.4%
10
CVE-2025-51534
32.4%
10
CVE-2026-125604.4 MED
32.4%
10The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Link URL' Field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The WordPress unfiltered_html capability exemption does not apply here because the payload is stored in post meta (_wpas_er_options via update_post_meta) rather than in post_content or post_excerpt, meaning the restriction affects all administrators regardless of their unfiltered_html status.82d
CVE-2018-20944
32.4%
10
CVE-1999-1252
32.4%
10
CVE-2024-1272
32.4%
10
CVE-2024-20789
32.4%
10
CVE-1999-1253
32.4%
10
CVE-2024-50615
32.4%
10
CVE-2013-2096
32.4%
10
CVE-2018-20939
32.4%
10
CVE-2014-2894
32.4%
10