PULSE
FEED
vulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE Watch376,337 in full archive

Vulnerabilities exploitable today

376,337in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646

Distribution · last window

  • Critical
    2,382
  • High
    8,758
  • Medium
    6,800
  • Low
    733
Filters
Filters

Window

Severity

Flags

Vulnerabilities265,361–265,400 · 376,337
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8680
29.4%
9
CVE-2024-25446
29.4%
9
CVE-2026-654518.5 HIG
29.4%
9Contributor SQL Injection in MapSVG <= 8.14.0 versions.57d
CVE-2026-654548.5 HIG
29.4%
9Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.57d
CVE-2020-23738
29.4%
9
CVE-2015-7076
29.4%
9
CVE-2024-13119
29.4%
9
CVE-2017-15129
29.4%
9
CVE-2026-22235
29.4%
9
CVE-2014-5233
29.4%
9
CVE-2026-56012
29.4%
9
CVE-2026-909825.3 MED
29.4%
9@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restriction can be bypassed by altering the letter case of a path segment. The route matcher is case-sensitive while the filesystem is not, so a request that changes the case of a protected segment does not match the guarded route and falls through to the static handler, yet the filesystem resolves it to the same protected file. As a result, an unauthenticated request can read a file that a route guard or allowedPath was configured to protect. The issue does not affect case-sensitive filesystems and is not a directory traversal, since nothing is served from outside the configured root. The issue is fixed in @fastify/static 10.1.4, which validates the requested path against its actual on-disk spelling and rejects case-aliased paths before authorization. As a workaround, serve static files from a case-sensitive filesystem, or ensure route guards and allowedPath rules account for every letter-case variant of the protected paths.21h
CVE-2025-15423
29.4%
9
CVE-2025-46911
29.4%
9
CVE-2026-784274.3 MED
29.4%
9The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.18h
CVE-2026-165315.3 MED
29.4%
9An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.28d
CVE-2026-191649.6 CRI
29.4%
9Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)41d
CVE-2021-34725
29.4%
9
CVE-2026-254058.5 HIG
29.4%
9Contributor SQL Injection in eRoom <= 1.7.1 versions.57d
CVE-2020-3417
29.4%
9
CVE-2026-578108.5 HIG
29.4%
9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.66d
CVE-2025-32164
29.4%
9
CVE-2003-1295
29.4%
9
CVE-2025-27094
29.4%
9
CVE-2023-2171
29.4%
9
CVE-2023-47054
29.4%
9
CVE-2012-2384
29.4%
9
CVE-2022-25667
29.4%
9
CVE-2026-22037
29.4%
9
CVE-2026-576878.5 HIG
29.4%
9Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.77d
CVE-2026-57667
29.4%
9
CVE-2022-491148.8 HIG
29.4%
9In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix use after free in fc_exch_abts_resp() fc_exch_release(ep) will decrease the ep's reference count. When the reference count reaches zero, it is freed. But ep is still used in the following code, which will lead to a use after free. Return after the fc_exch_release() call to avoid use after free.45d
CVE-2026-703777.5 HIG
29.4%
9imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.20d
CVE-2025-46884
29.4%
9
CVE-2025-63914
29.4%
9
CVE-2026-545938.1 HIG
29.3%
9Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse one of those tokens (for example a WebSocket token obtained with only the websocket.connect permission) by replaying it against /upload/file to write arbitrary files to the same server, despite never being granted the file.create permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2.49d
CVE-2023-27927
29.4%
9
CVE-2025-7572
29.4%
9
CVE-2024-31975
29.4%
9
CVE-2025-690948.5 HIG
29.4%
9Subscriber SQL Injection in Unicamp <= 2.2.2 versions.78d