PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
CVE Watch377,896 in full archive

Vulnerabilities exploitable today

377,896in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651

Distribution · last window

  • Critical
    2,337
  • High
    8,543
  • Medium
    6,730
  • Low
    747
Filters
Filters

Window

Severity

Flags

Vulnerabilities259,961–260,000 · 377,896
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34970
31.1%
9
CVE-2024-49782
31.1%
9
CVE-2024-27950
31.1%
9
CVE-2009-3624
31.1%
9
CVE-2026-6301
31.1%
9
CVE-2024-7460
31.1%
9
CVE-2025-69633
31.1%
9
CVE-2026-31240
31.1%
9
CVE-2009-0439
31.1%
9
CVE-2025-36070
31.1%
9
CVE-2007-1086
31.1%
9
CVE-2025-6569
31.1%
9
CVE-2013-1976
31.1%
9
CVE-2023-0322
31.1%
9
CVE-2019-15034
31.1%
9
CVE-2026-102135.4 MED
31.1%
9A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.60d
CVE-2021-0089
31.1%
9
CVE-2023-24068
31.1%
9
CVE-2025-13121
31.1%
9
CVE-2026-26377
31.1%
9
CVE-2024-5286
31.1%
9
CVE-2022-27619
31.1%
9
CVE-2026-858755.5 MED
31.1%
9Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2d
CVE-2015-5850
31.1%
9
CVE-2026-567478.8 HIG
31.1%
9Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.31d
CVE-2023-2241
31.1%
9
CVE-2022-34334
31.1%
9
CVE-2022-40603
31.1%
9
CVE-2026-42774
31.1%
9
CVE-2026-49076
31.1%
9
CVE-2024-49256
31.1%
9
CVE-2026-12686
31.1%
9An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. The application does not adequately verify whether the requested company ID belongs to the authenticated user’s session, resulting in a cross-tenant authorisation bypass. If this vulnerability is successfully exploited, it allows unauthorised access to sensitive customer information, including billing data, and may enable the unauthorised modification of third-party data.75d
CVE-2015-0999
31.1%
9
CVE-2026-60124
31.1%
9An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.72d
CVE-2012-6031
31.1%
9
CVE-2018-17155
31.1%
9
CVE-2020-11640
31.1%
9
CVE-2025-628263.1 LOW
31.1%
9An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.40d
CVE-2023-50614
31.1%
9
CVE-2026-45819
31.1%
9baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.10d