PULSE
FEED
vulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE Watch376,337 in full archive

Vulnerabilities exploitable today

376,337in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646

Distribution · last window

  • Critical
    2,379
  • High
    8,743
  • Medium
    6,788
  • Low
    727
Filters
Filters

Window

Severity

Flags

Vulnerabilities263,721–263,760 · 376,337
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2010-5216
29.8%
9
CVE-2005-2660
29.8%
9
CVE-2004-1032
29.8%
9
CVE-2017-9868
29.8%
9
CVE-2004-0970
29.8%
9
CVE-2005-0099
29.8%
9
CVE-2026-777677.5 HIG
29.8%
9Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in apps/api/app/Controllers/ReportsController.cs carries [AllowAnonymous] and therefore opts out of that policy. PreviewReport loads the Project row named by the id path segment, loads the linked Organisation through the project's ClientId, and renders both into default-report-template.html, which prints the project name and description together with the client organisation's name, address and URL. No authentication, project membership or role check is performed. Because the id is the auto-increment primary key of the project table, an unauthenticated remote caller can walk sequential ids to retrieve the engagement details and client organisation of every project on the instance, and the 404 returned for a missing id reveals which project ids exist. Reconmap stores penetration-testing engagements, so the disclosed descriptions and client records are sensitive by nature.28d
CVE-2024-58264
29.8%
9
CVE-2011-5156
29.8%
9
CVE-2008-5298
29.8%
9
CVE-2006-5214
29.8%
9
CVE-2017-18427
29.8%
9
CVE-2013-7461
29.8%
9
CVE-2013-7460
29.8%
9
CVE-2004-1377
29.8%
9
CVE-2010-5199
29.8%
9
CVE-2004-0422
29.8%
9
CVE-2005-2663
29.8%
9
CVE-2026-828776.5 MED
29.8%
9ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.8d
CVE-2026-843066.5 MED
29.8%
9Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-code cache key derived from both the app authentication secret and the submitted TOTP code. This isolates the newest accepted timestep by code instead of by secret, allowing a previously issued app-based MFA code to be accepted after a newer code has already been used. Reuse of the exact same code was already prevented, but another code inside the accepted time window remained usable. An attacker who obtains the target account's password and one app-based MFA code can use that code for the remainder of the configured window, which is approximately four minutes with the default settings, even after the legitimate account holder logs in with a newer code. Email-based MFA is not affected. This issue is fixed in versions 4.12.6 and 5.7.6.14d
CVE-2025-47905
29.8%
9
CVE-2023-22857
29.8%
9
CVE-2024-29071
29.8%
9
CVE-2025-14933
29.8%
9
CVE-2020-1739
29.8%
9
CVE-2026-56326
29.8%
9
CVE-2002-1392
29.8%
9
CVE-2005-3111
29.8%
9
CVE-2010-5222
29.8%
9
CVE-2006-0055
29.8%
9
CVE-2005-2992
29.8%
9
CVE-2026-30241
29.8%
9
CVE-2005-0990
29.8%
9
CVE-2026-870766.5 MED
29.8%
9Tanium addressed an information disclosure vulnerability in Discover.2d
CVE-2024-54443
29.8%
9
CVE-2025-53604
29.8%
9
CVE-2023-23939
29.8%
9
CVE-2025-5835
29.8%
9
CVE-2019-9530
29.8%
9
CVE-2024-28277
29.8%
9