PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,347
  • High
    8,428
  • Medium
    6,470
  • Low
    715
Filters

Window

Severity

Flags

Vulnerabilities273,321–273,360 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-95274.3 MED
26.7%
8A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.55d
CVE-2026-31971
26.7%
8
CVE-2024-45985
26.7%
8
CVE-2021-45660
26.7%
8
CVE-2025-13618
26.7%
8
CVE-2023-44266
26.7%
8
CVE-2026-905608.2 HIG
26.7%
8zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.1d
CVE-2025-53637
26.7%
8
CVE-2023-20003
26.7%
8
CVE-2025-29496
26.7%
8
CVE-2026-555155.0 MED
26.7%
8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptance records for another company. This issue is fixed in version 8.6.2.64d
CVE-2026-95184.3 MED
26.7%
8A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.55d
CVE-2017-5703
26.7%
8
CVE-2024-1434
26.7%
8
CVE-2024-7618
26.7%
8
CVE-2021-28705
26.7%
8
CVE-2019-11276
26.7%
8
CVE-2022-3879
26.7%
8
CVE-2026-726428.8 HIG
26.7%
8The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process.15d
CVE-2023-51370
26.7%
8
CVE-2019-18388
26.7%
8
CVE-2015-0663
26.7%
8
CVE-2026-628977.0 HIG
26.7%
8Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.33d
CVE-2021-4150
26.7%
8
CVE-2019-3688
26.7%
8
CVE-2023-51534
26.7%
8
CVE-2026-23484
26.7%
8
CVE-2026-2199
26.7%
8
CVE-2026-2217
26.7%
8
CVE-2002-0303
26.7%
8
CVE-2024-7241
26.7%
8
CVE-2025-29489
26.7%
8
CVE-2023-26930
26.7%
8
CVE-2026-54011
26.7%
8
CVE-2023-51536
26.7%
8
CVE-2026-736116.8 MED
26.7%
8File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.7d
CVE-2024-39698
26.7%
8
CVE-2025-29490
26.7%
8
CVE-2023-51691
26.7%
8
CVE-2025-29491
26.7%
8