PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
CVE Watch378,183 in full archive

Vulnerabilities exploitable today

378,183in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649

Distribution · last window

  • Critical
    2,332
  • High
    8,494
  • Medium
    6,769
  • Low
    765
Filters
Filters

Window

Severity

Flags

Vulnerabilities255,801–255,840 · 378,183
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-15049
32.2%
10
CVE-2026-814005.5 MED
32.2%
10Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.4d
CVE-2025-3789
32.2%
10
CVE-2022-2758
32.2%
10
CVE-2010-1439
32.2%
10
CVE-2014-4228
32.2%
10
CVE-2023-37065
32.2%
10
CVE-2003-0631
32.2%
10
CVE-2003-1095
32.2%
10
CVE-2021-4410
32.2%
10
CVE-2003-0257
32.2%
10
CVE-2021-39044
32.2%
10
CVE-2026-309507.1 HIG
32.2%
10AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's session, they can take it over, reading any messages in it and locking the legitimate user out. The PATCH /sessions/{session_id}/assign-user endpoint authenticates the caller but never verifies session ownership: the service layer invokes the session lookup with user_id=None, which the data access layer interprets as a privileged/system call that bypasses the ownership filter, allowing any authenticated user to reassign an arbitrary session to themselves. This issue has been patched in version 0.6.51.59d
CVE-2024-12018
32.2%
10
CVE-2025-60553
32.2%
10
CVE-2015-6839
32.2%
10
CVE-2025-13280
32.2%
10
CVE-2026-819585.5 MED
32.2%
10Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.4d
CVE-2018-4172
32.2%
10
CVE-2004-1117
32.2%
10
CVE-2025-15077
32.2%
10
CVE-2021-4412
32.2%
10
CVE-2024-29858
32.2%
10
CVE-2025-53078
32.2%
10
CVE-2021-39024
32.2%
10
CVE-2020-18418
32.2%
10
CVE-2024-12021
32.2%
10
CVE-2007-3100
32.2%
10
CVE-2024-33587
32.2%
10
CVE-2024-6556
32.2%
10
CVE-2012-6114
32.2%
10
CVE-2023-37066
32.2%
10
CVE-2024-12747
32.2%
10
CVE-2025-514529.8 CRI
32.2%
10In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.79d
CVE-2026-226805.3 MED
32.2%
10OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.69d
CVE-2012-0813
32.2%
10
CVE-2012-1053
32.2%
10
CVE-2004-1116
32.2%
10
CVE-2025-27193
32.2%
10
CVE-2008-7292
32.2%
10