PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646

Distribution · last window

  • Critical
    2,199
  • High
    7,814
  • Medium
    6,363
  • Low
    706
Filters

Window

Severity

Flags

Vulnerabilities268,081–268,120 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-46880
28.2%
8
CVE-2025-46940
28.2%
8
CVE-2020-4083
28.2%
8
CVE-2025-51954
28.2%
8
CVE-2016-0432
28.2%
8
CVE-2024-28966
28.2%
8
CVE-2018-4395
28.2%
8
CVE-2025-2415
28.2%
8
CVE-2023-2870
28.2%
8
CVE-2026-3914
28.2%
8
CVE-2023-23457
28.2%
8
CVE-2016-8227
28.2%
8
CVE-2019-3715
28.2%
8
CVE-2026-582144.3 MED
28.2%
8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.65d
CVE-2023-6391
28.2%
8
CVE-2023-22037
28.2%
8
CVE-2024-58257
28.2%
8
CVE-2021-30677
28.2%
8
CVE-2025-44958
28.2%
8
CVE-2024-43397
28.2%
8
CVE-2023-1515
28.2%
8
CVE-2025-13675
28.2%
8
CVE-2025-68133
28.2%
8
CVE-2002-1711
28.2%
8
CVE-2023-44101
28.2%
8
CVE-2003-0420
28.2%
8
CVE-2024-28968
28.2%
8
CVE-2004-2611
28.2%
8
CVE-2026-600539.1 CRI
28.2%
8Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.40d
CVE-2026-33164
28.2%
8
CVE-2025-46954
28.2%
8
CVE-2026-528807.5 HIG
28.2%
8Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no ReadHeaderTimeout, ReadTimeout, or MaxHeaderBytes configured. As a result, incoming connections that never complete their request headers are held open indefinitely. When a REST listener is reachable beyond localhost through the documented all-interface bind or a Docker port-publish deployment, a single unauthenticated client can open many slow-header connections and hold them open until server file descriptors are exhausted, preventing the API from accepting new connections. This renders the REST API unavailable to legitimate clients. This issue is fixed in version 1.7.18.7d
CVE-2021-3581
28.2%
8
CVE-2022-29204
28.2%
8
CVE-2016-0406
28.2%
8
CVE-2024-5968
28.2%
8
CVE-2026-33207
28.2%
8
CVE-2023-51697
28.2%
8
CVE-2026-3916
28.2%
8
CVE-2025-13764
28.2%
8