PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,347
  • High
    8,428
  • Medium
    6,470
  • Low
    715
Filters

Window

Severity

Flags

Vulnerabilities273,041–273,080 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-4493
26.7%
8
CVE-2003-1034
26.7%
8
CVE-2006-0178
26.7%
8
CVE-2024-34374
26.7%
8
CVE-2024-7038
26.7%
8Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.62d
CVE-2004-0125
26.7%
8
CVE-2022-36244
26.7%
8
CVE-2006-3373
26.7%
8
CVE-2025-377768.8 HIG
26.7%
8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use read lock to protect whole loop.48d
CVE-2025-69806
26.7%
8
CVE-2003-1291
26.7%
8
CVE-2006-3634
26.7%
8
CVE-2025-54092
26.7%
8
CVE-2026-40480
26.7%
8
CVE-2021-1840
26.7%
8
CVE-2024-30185
26.7%
8
CVE-2026-549928.4 HIG
26.7%
8Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.58d
CVE-2025-22524
26.7%
8
CVE-2026-861807.3 HIG
26.7%
8A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.8d
CVE-2025-9399
26.7%
8
CVE-2004-0134
26.7%
8
CVE-2024-29811
26.7%
8
CVE-2024-31448
26.7%
8
CVE-2006-4787
26.7%
8
CVE-2024-32593
26.7%
8
CVE-2025-58012
26.7%
8
CVE-2026-24139
26.7%
8
CVE-2025-67564
26.7%
8
CVE-2022-2719
26.7%
8
CVE-2026-21949
26.7%
8
CVE-2026-697134.4 MED
26.7%
8Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.6d
CVE-2025-23828
26.7%
8
CVE-2019-4448
26.7%
8
CVE-2026-584685.5 MED
26.7%
8NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attackers can target loopback addresses, RFC-1918 private ranges, and cloud instance metadata endpoints to perform internal network port enumeration, host discovery, and retrieval of IAM role credentials from the instance metadata service. v2.1.18 added a warning message for when SERVER_REQUEST_WHITELIST is not configured.63d
CVE-2026-44566
26.7%
8
CVE-2025-54290
26.7%
8
CVE-2025-5721
26.7%
8
CVE-2025-66435
26.7%
8
CVE-2024-29935
26.7%
8
CVE-2008-2312
26.7%
8