PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,226
  • High
    7,948
  • Medium
    6,437
  • Low
    714
Filters

Window

Severity

Flags

Vulnerabilities270,681–270,720 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-37073
27.4%
8
CVE-2025-1587
27.4%
8
CVE-2026-584277.5 HIG
27.4%
8Private org member list leaked via /members API endpoint — incomplete fix for PR #3814521d
CVE-2026-826674.7 MED
27.4%
8A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of the argument endpoint_url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.1 is recommended to address this issue. The name of the patch is 67abfd864a15d169a78429f3290c91cb3b93e849. It is advisable to upgrade the affected component.16d
CVE-2019-25573
27.4%
8
CVE-2026-464788.8 HIG
27.4%
8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2.55d
CVE-2024-3168
27.4%
8
CVE-2024-8288
27.4%
8
CVE-2026-841419.8 CRI
27.4%
8Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.13d
CVE-2026-5033
27.4%
8
CVE-2026-177734.3 MED
27.4%
8Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)43d
CVE-2023-20233
27.4%
8
CVE-2019-14402
27.4%
8
CVE-2026-42314
27.4%
8
CVE-2019-6566
27.4%
8
CVE-2025-5725
27.4%
8
CVE-2026-22615
27.4%
8
CVE-2024-9005
27.4%
8
CVE-1999-1297
27.4%
8
CVE-2024-25443
27.4%
8
CVE-2023-6805
27.4%
8
CVE-2020-36424
27.4%
8
CVE-2025-451565.3 MED
27.4%
8Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.73d
CVE-2019-25271
27.4%
8
CVE-2026-33307
27.4%
8
CVE-2024-20951
27.4%
8
CVE-2025-13631
27.4%
8
CVE-2010-3597
27.4%
8
CVE-2016-7664
27.4%
8
CVE-2022-1891
27.4%
8
CVE-2017-18458
27.4%
8
CVE-2003-0193
27.4%
8
CVE-2025-515439.8 CRI
27.4%
8An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.73d
CVE-2026-41680
27.4%
8
CVE-2005-1270
27.4%
8
CVE-2016-10772
27.4%
8
CVE-2026-177954.3 MED
27.4%
8Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)43d
CVE-2026-567509.1 CRI
27.4%
8Gitea Remember-Me Token Theft Not Invalidating Attacker Session21d
CVE-2016-6716
27.4%
8
CVE-2024-4668
27.4%
8