PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
CVE Watch378,004 in full archive

Vulnerabilities exploitable today

378,004in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651

Distribution · last window

  • Critical
    2,292
  • High
    8,399
  • Medium
    6,682
  • Low
    748
Filters
Filters

Window

Severity

Flags

Vulnerabilities258,681–258,720 · 378,004
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-47831
31.4%
9
CVE-2023-50928
31.4%
9
CVE-2016-3488
31.4%
9
CVE-2025-27614
31.4%
9
CVE-2023-38018
31.4%
9
CVE-2019-19536
31.4%
9
CVE-2026-703235.5 MED
31.4%
9Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.38d
CVE-2006-0741
31.4%
9
CVE-2008-5690
31.4%
9
CVE-2025-45610
31.4%
9
CVE-2024-12657
31.4%
9
CVE-2019-11773
31.4%
9
CVE-2024-13240
31.4%
9
CVE-2000-0365
31.4%
9
CVE-2024-53350
31.4%
9
CVE-2013-3952
31.4%
9
CVE-2025-32021
31.4%
9
CVE-2017-2622
31.4%
9
CVE-2018-4004
31.4%
9
CVE-2005-0969
31.4%
9
CVE-2024-36359
31.4%
9
CVE-2024-20904
31.4%
9
CVE-2025-15185
31.4%
9
CVE-2025-5590
31.4%
9
CVE-2026-593176.5 MED
31.4%
9DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier16d
CVE-2025-43450
31.4%
9
CVE-2022-25728
31.4%
9
CVE-2009-3035
31.4%
9
CVE-2009-3897
31.4%
9
CVE-2023-50566
31.4%
9
CVE-2005-2456
31.4%
9
CVE-2002-0788
31.4%
9
CVE-2026-472537.3 HIG
31.4%
9Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A low-privileged bearer-token holder can invoke the function through the /v1/query HTTP endpoint, causing path.Join to resolve .. segments outside $XDG_CACHE_HOME/anyquery/plugins/ and os.RemoveAll to recursively delete any reachable directory writable by the Anyquery server process. This causes permanent data loss and denial of service without disclosing file contents. This issue is fixed in version 0.4.5.6d
CVE-2026-608256.6 MED
31.4%
9Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).53d
CVE-2024-9413
31.4%
9
CVE-2023-21936
31.4%
9
CVE-2026-290048.1 HIG
31.4%
9BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.68d
CVE-2022-25738
31.4%
9
CVE-2018-1410
31.4%
9
CVE-2026-703165.5 MED
31.4%
9Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.38d