PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646

Distribution · last window

  • Critical
    2,211
  • High
    7,860
  • Medium
    6,394
  • Low
    708
Filters

Window

Severity

Flags

Vulnerabilities268,961–269,000 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-12217
28.0%
8
CVE-2017-14730
28.0%
8
CVE-2010-5223
28.0%
8
CVE-2026-41230
28.0%
8
CVE-2025-26487
28.0%
8
CVE-2016-10297
28.0%
8
CVE-2010-5225
28.0%
8
CVE-2025-2267
28.0%
8
CVE-2010-5197
28.0%
8
CVE-2025-9422
28.0%
8
CVE-2019-18943
28.0%
8
CVE-2026-20883
28.0%
8
CVE-2025-58337
28.0%
8
CVE-2014-7989
28.0%
8
CVE-2010-5215
28.0%
8
CVE-2017-6899
28.0%
8
CVE-2020-6789
28.0%
8
CVE-2025-1532
28.0%
8
CVE-2025-10753
28.0%
8
CVE-2022-0634
28.0%
8
CVE-2019-5689
28.0%
8
CVE-2010-5198
28.0%
8
CVE-2010-5208
28.0%
8
CVE-2010-5206
28.0%
8
CVE-2024-369228.8 HIG
28.0%
8In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: read txq->read_ptr under lock If we read txq->read_ptr without lock, we can read the same value twice, then obtain the lock, and reclaim from there to two different places, but crucially reclaim the same entry twice, resulting in the WARN_ONCE() a little later. Fix that by reading txq->read_ptr under lock.43d
CVE-1999-0303
28.0%
8
CVE-2023-33203
28.0%
8
CVE-2023-25586
28.0%
8
CVE-2026-40396
28.0%
8
CVE-2002-2127
28.0%
8
CVE-2025-65409
28.0%
8
CVE-2026-766407.5 HIG
28.0%
8Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, corrupting an adjacent mainloop function pointer dispatch entry that is subsequently invoked by the cleanup path passing attacker-controlled data to system() as uid 0.8d
CVE-2024-3917
28.0%
8
CVE-2010-5218
28.0%
8
CVE-2010-5219
28.0%
8
CVE-2012-0114
28.0%
8
CVE-2024-20391
28.0%
8
CVE-2026-54136
28.0%
8Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{workspace}/scripts/list_search. The route-level scope middleware validated the token domain and action but did not enforce the resource/path segment, and the list_search_scripts handler had no additional check_scopes call or per-row filtering before returning script path and content fields. A token such as scripts:read:f/allowed/* could therefore receive source code for unrelated paths in the same workspace, potentially disclosing internal automation logic, integration details, business logic, inline configuration, or hardcoded secrets and credentials. Exploitation required possession of a valid scoped API token for the workspace but did not require administrator privileges. This issue is fixed in version 1.715.0.26d
CVE-2021-24836
28.0%
8
CVE-2025-62699
28.0%
8