PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,347
  • High
    8,428
  • Medium
    6,470
  • Low
    715
Filters

Window

Severity

Flags

Vulnerabilities273,961–274,000 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-45010
26.5%
8
CVE-2023-5427
26.5%
8
CVE-2026-22097
26.5%
8The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.64d
CVE-2026-775007.8 HIG
26.5%
8Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.7d
CVE-2025-9587
26.5%
8
CVE-2025-14926
26.5%
8
CVE-2024-53842
26.5%
8
CVE-2023-48682
26.5%
8
CVE-2025-7103
26.5%
8
CVE-2016-3484
26.5%
8
CVE-2026-631025.4 MED
26.5%
8rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected.27d
CVE-2024-5554
26.5%
8
CVE-2026-503024.2 MED
26.5%
8Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.55d
CVE-2025-61595
26.5%
8
CVE-2026-759205.3 MED
26.5%
8phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.14d
CVE-2024-4486
26.5%
8
CVE-2026-39308
26.5%
8
CVE-2026-180228.8 HIG
26.5%
8Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.27d
CVE-2026-6201
26.5%
8
CVE-2024-43758
26.5%
8
CVE-2024-56363
26.5%
8
CVE-2025-1496
26.5%
8
CVE-2024-47425
26.5%
8
CVE-2025-40605
26.5%
8
CVE-2025-22682
26.5%
8
CVE-2023-4104
26.5%
8
CVE-2024-21284
26.5%
8
CVE-2024-47424
26.5%
8
CVE-2016-6249
26.5%
8
CVE-2025-53535
26.5%
8
CVE-2024-9118
26.5%
8
CVE-2025-22684
26.5%
8
CVE-2025-45009
26.5%
8
CVE-2019-25640
26.5%
8
CVE-2023-527698.8 HIG
26.5%
8In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix htt mlo-offset event locking The ath12k active pdevs are protected by RCU but the htt mlo-offset event handling code calling ath12k_mac_get_ar_by_pdev_id() was not marked as a read-side critical section. Mark the code in question as an RCU read-side critical section to avoid any potential use-after-free issues. Compile tested only.43d
CVE-2025-59039
26.5%
8
CVE-2026-6302
26.5%
8
CVE-2024-28224
26.5%
8
CVE-2025-24620
26.5%
8
CVE-2026-44319.1 CRI
26.5%
8The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter.34d