PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
CVE Watch378,068 in full archive

Vulnerabilities exploitable today

378,068in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651

Distribution · last window

  • Critical
    2,293
  • High
    8,417
  • Medium
    6,703
  • Low
    757
Filters
Filters

Window

Severity

Flags

Vulnerabilities256,281–256,320 · 378,068
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-5759
32.1%
10
CVE-2026-18674
32.0%
10On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone. The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide. The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.21d
CVE-2026-22081
32.1%
10
CVE-2023-33968
32.1%
10
CVE-2022-4107
32.1%
10
CVE-2025-13596
32.1%
10
CVE-2024-53304
32.1%
10
CVE-2023-30471
32.1%
10
CVE-2023-20130
32.1%
10
CVE-2020-15862
32.1%
10
CVE-2023-47779
32.1%
10
CVE-2015-8222
32.1%
10
CVE-2025-52853
32.1%
10
CVE-2026-543478.7 HIG
32.1%
10Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML escaping, and templates/Froxlor/table/table.html.twig renders the callback result with the raw filter. An authenticated customer with DNS editor access can store JavaScript-bearing content in a TXT record. When an administrator views the affected domain's DNS configuration, the payload executes automatically in the administrator's browser session, which can expose session data or perform privileged panel actions. This issue is fixed in version 2.3.8.13d
CVE-2025-52858
32.1%
10
CVE-2024-8108
32.1%
10
CVE-2022-42370
32.1%
10
CVE-2017-7766
32.1%
10
CVE-2010-0960
32.1%
10
CVE-2025-14012
32.1%
10
CVE-2025-52857
32.1%
10
CVE-2023-4553
32.1%
10
CVE-2020-14714
32.1%
10
CVE-2025-52866
32.1%
10
CVE-2025-54785
32.1%
10
CVE-2011-3212
32.1%
10
CVE-2024-4433
32.1%
10
CVE-2025-24806
32.1%
10
CVE-2026-452238.8 HIG
32.1%
10Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.69d
CVE-2025-7210
32.1%
10
CVE-2023-38057
32.1%
10
CVE-2024-36378
32.1%
10
CVE-2024-8269
32.1%
10
CVE-2025-64181
32.1%
10
CVE-2024-5883
32.1%
10
CVE-2013-1766
32.1%
10
CVE-2010-0961
32.1%
10
CVE-2024-50955
32.1%
10
CVE-2020-3970
32.1%
10
CVE-2025-20360
32.1%
10