PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
CVE Watch377,415 in full archive

Vulnerabilities exploitable today

377,415in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647

Distribution · last window

  • Critical
    2,355
  • High
    8,510
  • Medium
    6,633
  • Low
    715
Filters
Filters

Window

Severity

Flags

Vulnerabilities261,361–261,400 · 377,415
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-478556.0 MED
30.6%
9Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.18d
CVE-2020-4996
30.6%
9
CVE-2020-9100
30.6%
9
CVE-2024-41857
30.6%
9
CVE-2025-39595
30.6%
9
CVE-2026-33022
30.6%
9
CVE-2022-3399
30.6%
9
CVE-2025-21160
30.6%
9
CVE-2024-48915
30.6%
9
CVE-2025-143008.1 HIG
30.6%
9The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).35d
CVE-2026-571409.4 CRI
30.6%
9PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent names, roles, and instruction prefixes and can invoke a selected agent, potentially reaching its tools, memory, external APIs, credentials, and workflow state. An initial remediation was released in version 1.7.2.3d
CVE-2024-56430
30.6%
9
CVE-2025-57564
30.6%
9
CVE-2014-6195
30.6%
9
CVE-2012-3317
30.6%
9
CVE-2000-1208
30.6%
9
CVE-2026-54659
30.6%
9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.50d
CVE-2025-39471
30.6%
9
CVE-2023-1003
30.6%
9
CVE-2010-4706
30.6%
9
CVE-2024-37930
30.6%
9
CVE-2023-32980
30.6%
9
CVE-2025-10710
30.6%
9
CVE-2018-7687
30.6%
9
CVE-2022-42844
30.6%
9
CVE-2023-33534
30.6%
9
CVE-2021-1751
30.6%
9
CVE-2025-0693
30.6%
9
CVE-2025-41367
30.6%
9
CVE-2025-22620
30.6%
9
CVE-2024-45981
30.6%
9
CVE-2019-10343
30.6%
9
CVE-2014-5206
30.6%
9
CVE-2026-436636.5 MED
30.6%
9The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.32d
CVE-2025-1364
30.6%
9
CVE-2024-12271
30.6%
9
CVE-2024-9417
30.6%
9
CVE-2026-637568.1 HIG
30.6%
9SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.58d
CVE-2022-43528
30.6%
9
CVE-2023-35936
30.6%
9