PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,226
  • High
    7,950
  • Medium
    6,438
  • Low
    714
Filters

Window

Severity

Flags

Vulnerabilities271,561–271,600 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1208
27.1%
8
CVE-2025-53408
27.1%
8
CVE-2024-4277
27.1%
8
CVE-2024-13318
27.1%
8
CVE-2024-7783
27.1%
8
CVE-2025-69195
27.1%
8
CVE-2026-729228.2 HIG
27.1%
8AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webhooks/{webhook_id}/ingress to use CompassWebhookManager's inherited no-op BaseWebhooksManager.verify_signature instead of GenericWebhooksManager.verify_signature, bypass X-Webhook-Secret for a configured secret_token, and execute a generic webhook graph as its owner. This issue is fixed in version 0.6.70.7d
CVE-2023-41068
27.1%
8
CVE-2025-13440
27.1%
8
CVE-2014-2485
27.1%
8
CVE-2022-25153
27.1%
8
CVE-2024-45453
27.1%
8
CVE-2020-4197
27.1%
8
CVE-2019-4112
27.1%
8
CVE-2025-10291
27.1%
8
CVE-2026-57319.8 CRI
27.1%
8Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.63d
CVE-2018-17502
27.1%
8
CVE-2024-12513
27.1%
8
CVE-2013-1425
27.1%
8
CVE-2024-1759
27.1%
8
CVE-2026-406118.8 HIG
27.1%
8Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fixed in 4.34.0.63d
CVE-2025-0368
27.1%
8
CVE-2010-1488
27.1%
8
CVE-2025-32599
27.1%
8
CVE-2024-2841
27.1%
8
CVE-2010-4819
27.1%
8
CVE-2024-10956
27.1%
8
CVE-2022-42851
27.1%
8
CVE-2024-442867.5 HIG
27.1%
8This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.54d
CVE-2020-21881
27.1%
8
CVE-2025-32600
27.1%
8
CVE-2024-47549
27.1%
8
CVE-2013-1958
27.1%
8
CVE-2024-56219
27.1%
8
CVE-2025-3471
27.1%
8
CVE-2016-6162
27.1%
8
CVE-2020-7453
27.1%
8
CVE-2024-12034
27.1%
8
CVE-2024-43384
27.1%
8
CVE-2010-3095
27.1%
8