PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,226
  • High
    7,949
  • Medium
    6,437
  • Low
    714
Filters

Window

Severity

Flags

Vulnerabilities270,881–270,920 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-0460
27.3%
8
CVE-2025-10045
27.3%
8
CVE-2026-25406
27.3%
8
CVE-2024-10147
27.3%
8
CVE-2025-8344
27.3%
8
CVE-2026-73219
27.3%
8CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation request to RequestViewSet.create with inconsistent task and job IDs, and because the task ID determines the single active request slot, block automatic annotation for another task whose ID is known. This issue is fixed in version 2.72.0.6d
CVE-2026-851768.8 HIG
27.3%
8DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.13d
CVE-2016-1722
27.3%
8
CVE-2025-1278
27.3%
8
CVE-2026-770029.8 CRI
27.3%
8The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.24d
CVE-2026-750275.3 MED
27.3%
8The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling data (padding and margin properties) of arbitrary posts, including private and draft posts, by supplying an attacker-controlled post ID and JSON styling payload. The nonce required by the handler is automatically emitted to all frontend pages rendered by the builder via wp_localize_script, meaning any unauthenticated visitor can trivially retrieve a valid nonce from page source and satisfy the only access control in place.23d
CVE-2026-20433
27.3%
8
CVE-2023-5771
27.3%
8
CVE-2026-56212
27.3%
8
CVE-2020-28044
27.3%
8
CVE-2012-3457
27.3%
8
CVE-2022-37084
27.3%
8
CVE-2021-1057
27.3%
8
CVE-2022-38229
27.3%
8
CVE-2026-758609.8 CRI
27.3%
8The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.27d
CVE-2026-25357
27.3%
8
CVE-2022-37075
27.3%
8
CVE-2025-65007
27.3%
8
CVE-2026-706226.5 MED
27.3%
8tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that resolved targets remain within the source root, causing out-of-bounds files to be included in the archive as regular files and disclosed to the attacker.36d
CVE-2020-14759
27.3%
8
CVE-2025-30575
27.3%
8
CVE-2022-37821
27.3%
8
CVE-2025-43932
27.3%
8
CVE-2025-30527
27.3%
8
CVE-2023-32396
27.3%
8
CVE-2025-30792
27.3%
8
CVE-2026-696087.8 HIG
27.3%
8Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.6d
CVE-2026-3334
27.3%
8
CVE-2024-42678
27.3%
8
CVE-2021-25138
27.3%
8
CVE-2026-597147.1 HIG
27.3%
8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0.33d
CVE-2026-800937.0 HIG
27.3%
8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.6d
CVE-2026-6316
27.3%
8
CVE-2023-22128
27.3%
8
CVE-2026-694477.8 HIG
27.3%
8Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.7d