PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,226
  • High
    7,950
  • Medium
    6,437
  • Low
    714
Filters

Window

Severity

Flags

Vulnerabilities271,081–271,120 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-0407
27.3%
8
CVE-2023-41137
27.3%
8
CVE-2026-3563
27.3%
8
CVE-2025-52996
27.3%
8
CVE-2007-3379
27.3%
8
CVE-2026-476528.2 HIG
27.3%
8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.55d
CVE-2026-839915.5 MED
27.3%
8Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.8d
CVE-2021-39027
27.3%
8
CVE-2016-0237
27.3%
8
CVE-2025-5690
27.3%
8
CVE-2012-5179
27.3%
8
CVE-2025-147326.4 MED
27.3%
8The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.53d
CVE-2022-42824
27.3%
8
CVE-2023-32712
27.3%
8
CVE-2025-8980
27.3%
8
CVE-2026-812118.8 HIG
27.3%
8IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.10h
CVE-2021-29073
27.3%
8
CVE-2023-22109
27.3%
8
CVE-2024-0130
27.3%
8
CVE-2026-163547.5 HIG
27.3%
8Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.54d
CVE-2024-12336
27.3%
8
CVE-2014-3423
27.3%
8
CVE-2011-1500
27.3%
8
CVE-2014-0249
27.3%
8
CVE-2007-5373
27.3%
8
CVE-2026-687566.6 MED
27.3%
8A party with write access to stored session data may affect JFrog Artifactory under specific conditions.14d
CVE-2006-3378
27.3%
8
CVE-2026-826644.3 MED
27.3%
8A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD Theme Handler. The manipulation of the argument Search leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.1.1 is able to mitigate this issue. The identifier of the patch is 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is recommended.15d
CVE-2026-87159.6 CRI
27.3%
8Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.18d
CVE-2024-12069
27.3%
8
CVE-2018-15807
27.3%
8
CVE-2015-7020
27.3%
8
CVE-2016-9378
27.3%
8
CVE-2024-7047
27.3%
8
CVE-2006-1814
27.3%
8
CVE-2011-3869
27.3%
8
CVE-2013-3236
27.3%
8
CVE-2024-1400
27.3%
8
CVE-2018-254338.2 HIG
27.3%
8Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernames and password hashes.56d
CVE-2011-1551
27.3%
8