PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,183 in full archive

Vulnerabilities exploitable today

378,183in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,332
  • High
    8,494
  • Medium
    6,769
  • Low
    765
Filters
Filters

Window

Severity

Flags

Vulnerabilities255,481–255,520 · 378,183
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1914
32.3%
10
CVE-2023-44435
32.3%
10
CVE-2021-4254
32.3%
10
CVE-2024-22248
32.3%
10
CVE-2007-5496
32.3%
10
CVE-2025-23850
32.3%
10
CVE-2025-63468
32.3%
10
CVE-2025-23586
32.3%
10
CVE-2012-4833
32.3%
10
CVE-2023-1419
32.3%
10
CVE-2025-24694
32.3%
10
CVE-2025-23616
32.3%
10
CVE-2025-24758
32.3%
10
CVE-2025-63465
32.3%
10
CVE-2025-26557
32.3%
10
CVE-2026-22737
32.3%
10
CVE-2025-26585
32.3%
10
CVE-2024-5149
32.3%
10
CVE-2023-36308
32.3%
10
CVE-2025-26586
32.3%
10
CVE-2024-48908
32.3%
10
CVE-2025-63459
32.3%
10
CVE-2025-25165
32.3%
10
CVE-2026-879768.1 HIG
32.3%
10Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.7h
CVE-2025-63461
32.3%
10
CVE-2025-23847
32.3%
10
CVE-2025-23883
32.3%
10
CVE-2025-25090
32.3%
10
CVE-2025-23852
32.3%
10
CVE-2026-5261
32.3%
10
CVE-2025-25161
32.3%
10
CVE-2025-23741
32.3%
10
CVE-2025-23718
32.3%
10
CVE-2025-1705
32.3%
10
CVE-2025-23726
32.3%
10
CVE-2024-3994
32.3%
10
CVE-2025-23813
32.3%
10
CVE-2015-2642
32.3%
10
CVE-2022-4581
32.3%
10
CVE-1999-0501
32.3%
10