PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
CVE Watch377,882 in full archive

Vulnerabilities exploitable today

377,882in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651

Distribution · last window

  • Critical
    2,336
  • High
    8,527
  • Medium
    6,725
  • Low
    744
Filters
Filters

Window

Severity

Flags

Vulnerabilities260,561–260,600 · 377,882
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-22720
30.9%
9
CVE-2007-5971
30.9%
9
CVE-2023-40679
30.9%
9
CVE-2026-470948.8 HIG
30.9%
9SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.3d
CVE-2016-5604
30.9%
9
CVE-2023-23999
30.9%
9
CVE-2023-23828
30.9%
9
CVE-2020-8471
30.9%
9
CVE-2026-856208.6 HIG
30.9%
9Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.5d
CVE-2023-26013
30.9%
9
CVE-2025-1955
30.9%
9
CVE-2005-4068
30.9%
9
CVE-2003-0194
30.9%
9
CVE-2002-0113
30.9%
9
CVE-2023-48055
30.9%
9
CVE-2025-20166
30.9%
9
CVE-2024-6138
30.9%
9
CVE-2024-56317
30.9%
9
CVE-2026-911447.5 HIG
30.9%
9ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.2d
CVE-2023-0439
30.9%
9
CVE-2023-29387
30.9%
9
CVE-2026-257869.1 CRI
30.9%
9Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.68d
CVE-2023-26536
30.9%
9
CVE-2023-23717
30.9%
9
CVE-2014-1831
30.9%
9
CVE-2020-23249
30.9%
9
CVE-2026-789076.5 MED
30.9%
9Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)23d
CVE-2022-34262
30.9%
9
CVE-2026-628037.8 HIG
30.9%
9Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.17d
CVE-2015-3318
30.9%
9
CVE-2025-63154
30.9%
9
CVE-2023-50833
30.9%
9
CVE-2025-31425
30.9%
9
CVE-2024-45861
30.9%
9
CVE-2017-1468
30.9%
9
CVE-2023-0431
30.9%
9
CVE-2026-35524.3 MED
30.9%
9The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410, ajax_delete_410, ajax_bulk_410_delete, ajax_empty_410, ajax_export_410) properly implement both authorization and nonce checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action. Injected URLs will cause the site to return HTTP 410 Gone responses to all visitors accessing those paths, potentially causing denial of service for legitimate pages and SEO damage through search engine delisting.68d
CVE-2026-698325.6 MED
30.9%
9Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.3d
CVE-2024-33648
30.9%
9
CVE-2016-5551
30.9%
9