PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,225
  • High
    7,948
  • Medium
    6,436
  • Low
    714
Filters

Window

Severity

Flags

Vulnerabilities270,561–270,600 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-739988.5 HIG
27.4%
8Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.27d
CVE-2025-2511
27.4%
8
CVE-2022-25662
27.4%
8
CVE-2026-341038.8 HIG
27.4%
8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23d
CVE-2024-27997
27.4%
8
CVE-2026-154017.2 HIG
27.4%
8The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vbfX custom-field value is stored via the public-facing saveorder task, which has no capability or authentication check enforced by default, enabling fully unauthenticated submission of malicious payloads.54d
CVE-2022-2449
27.4%
8
CVE-2018-4244
27.4%
8
CVE-2024-39094
27.4%
8
CVE-2026-341058.8 HIG
27.4%
8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23d
CVE-2017-2452
27.4%
8
CVE-2019-19350
27.4%
8
CVE-2026-44603
27.4%
8
CVE-2004-0515
27.4%
8
CVE-2018-12222
27.4%
8
CVE-2024-8433
27.4%
8
CVE-2024-34661
27.4%
8
CVE-2026-325648.5 HIG
27.4%
8Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.19d
CVE-2020-8002
27.4%
8
CVE-2026-172076.5 MED
27.4%
8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.8d
CVE-2026-325508.5 HIG
27.4%
8Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.19d
CVE-2024-5205
27.4%
8
CVE-2025-11624
27.4%
8
CVE-2025-65781
27.4%
8
CVE-2024-10527
27.4%
8
CVE-2024-9543
27.4%
8
CVE-2026-595606.5 MED
27.4%
8Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.51d
CVE-2023-21989
27.4%
8
CVE-2016-0235
27.4%
8
CVE-2004-1108
27.4%
8
CVE-2004-0517
27.4%
8
CVE-2004-0516
27.4%
8
CVE-2008-5843
27.4%
8
CVE-2026-257144.3 MED
27.4%
8Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.71d
CVE-2024-6539
27.4%
8
CVE-2026-33297
27.4%
8
CVE-2026-34158.7 HIG
27.4%
8The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges. Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.16d
CVE-2026-517425.9 MED
27.4%
8Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.15d
CVE-2026-558734.3 MED
27.4%
8SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.70d
CVE-2026-517485.9 MED
27.4%
8Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.15d