PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
CVE Watch377,415 in full archive

Vulnerabilities exploitable today

377,415in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647

Distribution · last window

  • Critical
    2,355
  • High
    8,511
  • Medium
    6,637
  • Low
    715
Filters
Filters

Window

Severity

Flags

Vulnerabilities261,521–261,560 · 377,415
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-7995
30.6%
9
CVE-2026-1651
30.6%
9
CVE-2015-0858
30.6%
9
CVE-2025-0339
30.6%
9
CVE-2023-20106
30.6%
9
CVE-2024-12077
30.6%
9
CVE-2022-33859
30.6%
9
CVE-2026-21949
30.6%
9
CVE-2021-41496
30.6%
9
CVE-2024-12717
30.6%
9
CVE-2024-12435
30.6%
9
CVE-2021-22553
30.6%
9
CVE-2005-2306
30.6%
9
CVE-1999-1073
30.6%
9
CVE-2024-12290
30.6%
9
CVE-2026-732478.6 HIG
30.6%
9Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that accesses internal services or cloud metadata.9d
CVE-1999-0296
30.6%
9
CVE-2019-4654
30.6%
9
CVE-2025-1279
30.6%
9
CVE-2025-15106
30.6%
9
CVE-2024-5281
30.6%
9
CVE-2026-39424
30.6%
9
CVE-2025-23434
30.6%
9
CVE-2014-8819
30.6%
9
CVE-2026-46897
30.6%
9
CVE-2019-2872
30.6%
9
CVE-2023-47726
30.6%
9
CVE-2012-1054
30.6%
9
CVE-2024-2762
30.6%
9
CVE-2001-1550
30.6%
9
CVE-2025-47907
30.6%
9
CVE-2020-0583
30.6%
9
CVE-2023-0834
30.6%
9
CVE-2017-0803
30.6%
9
CVE-2026-25947
30.6%
9
CVE-2025-24036
30.6%
9
CVE-2011-0716
30.6%
9
CVE-2026-130156.1 MED
30.6%
9The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is URL-decoded, stripslashes()'d, and echoed directly into an HTML value attribute with no esc_attr() call when the supplied place is not already a stored key in the wprev_google_crawls option. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.79d
CVE-2026-127546.1 MED
30.6%
9The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted page to render the [vikbooking view="roomslist"] shortcode, as the vulnerable layoutstyle parameter is only processed in that view context.79d
CVE-2024-3318
30.6%
9