PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646

Distribution · last window

  • Critical
    2,210
  • High
    7,852
  • Medium
    6,391
  • Low
    708
Filters

Window

Severity

Flags

Vulnerabilities268,681–268,720 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-694787.8 HIG
28.1%
8Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.7d
CVE-2024-40277.5 HIG
28.1%
8A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.15d
CVE-2022-41843
28.1%
8
CVE-2023-22418
28.1%
8
CVE-2024-2656
28.1%
8
CVE-2020-37089
28.1%
8
CVE-2026-699217.8 HIG
28.1%
8Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.7d
CVE-2001-0984
28.1%
8
CVE-2001-1111
28.1%
8
CVE-1999-1025
28.1%
8
CVE-2026-52866
28.1%
8
CVE-2002-0973
28.1%
8
CVE-2025-4744
28.1%
8
CVE-2006-0386
28.1%
8
CVE-2025-54132
28.1%
8
CVE-1999-1562
28.1%
8
CVE-2025-53474
28.1%
8
CVE-2010-0119
28.1%
8
CVE-2026-702897.8 HIG
28.1%
8Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.1d
CVE-2014-4425
28.1%
8
CVE-2023-47727
28.1%
8
CVE-2024-12014
28.1%
8
CVE-2026-338967.4 HIG
28.1%
8Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.12d
CVE-2024-37157
28.1%
8
CVE-2026-59825
28.1%
8
CVE-2025-54854
28.1%
8
CVE-2026-101427.5 HIG
28.1%
8kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a specially crafted frame length through the receive_bytes() function to trigger either a multi-gigabyte memory allocation or an uncaught ValueError that leaves the connection in a broken state, causing requests to hang and consumers to stop heartbeating until restart.55d
CVE-2026-191728.3 HIG
28.0%
8Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)40d
CVE-2016-3676
28.0%
8
CVE-2006-2790
28.0%
8
CVE-2026-160746.3 MED
28.0%
8A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plugins of the file astrbot/dashboard/routes/plugin.py of the component Plugin Update Handler. The manipulation of the argument download_url/download_urls/proxy results in server-side request forgery. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.58d
CVE-2026-153746.3 MED
28.0%
8A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.65d
CVE-2022-22596
28.0%
8
CVE-2026-5289
28.0%
8
CVE-2024-32718
28.0%
8
CVE-2018-20893
28.0%
8
CVE-2026-28392
28.0%
8
CVE-2019-3593
28.0%
8
CVE-2017-18465
28.0%
8
CVE-2025-27583
28.0%
8