PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,347
  • High
    8,411
  • Medium
    6,453
  • Low
    715
Filters

Window

Severity

Flags

Vulnerabilities274,481–274,520 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-541147.8 HIG
26.4%
8Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.55d
CVE-2026-585327.8 HIG
26.4%
8Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.55d
CVE-2026-561757.8 HIG
26.4%
8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.56d
CVE-2026-504127.8 HIG
26.4%
8Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.57d
CVE-2025-49726
26.4%
8
CVE-2026-504937.8 HIG
26.4%
8Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.55d
CVE-2026-476358.4 HIG
26.4%
8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.55d
CVE-2026-503157.8 HIG
26.4%
8Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.55d
CVE-2024-13451
26.4%
8
CVE-2026-502937.8 HIG
26.4%
8Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.55d
CVE-2022-29836
26.4%
8
CVE-2026-1193
26.4%
8
CVE-2025-2491
26.4%
8
CVE-2026-504417.8 HIG
26.4%
8Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.55d
CVE-2026-504337.8 HIG
26.4%
8Use after free in Windows Media allows an authorized attacker to elevate privileges locally.55d
CVE-2017-18669
26.4%
8
CVE-2025-15351
26.4%
8
CVE-2024-5829
26.4%
8
CVE-2026-503637.8 HIG
26.4%
8Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.55d
CVE-2026-504947.8 HIG
26.4%
8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.56d
CVE-2026-503828.8 HIG
26.4%
8Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.55d
CVE-2020-27123
26.4%
8
CVE-2026-504357.8 HIG
26.4%
8Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.55d
CVE-2019-10476
26.4%
8
CVE-2026-506928.8 HIG
26.4%
8Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.55d
CVE-2025-53076
26.4%
8
CVE-2020-12039
26.4%
8
CVE-2026-585367.8 HIG
26.4%
8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.55d
CVE-2021-38204
26.4%
8
CVE-2025-36354
26.4%
8
CVE-2026-549877.8 HIG
26.4%
8Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.55d
CVE-2026-33659
26.4%
8
CVE-2024-37603
26.3%
8
CVE-2026-147976.3 MED
26.3%
8A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.71d
CVE-2012-4948
26.3%
8
CVE-2026-162617.5 HIG
26.3%
8The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.20d
CVE-2026-504997.8 HIG
26.3%
8Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.55d
CVE-2026-482086.5 MED
26.3%
8An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP). This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected56d
CVE-2004-2258
26.3%
8
CVE-2026-147676.3 MED
26.3%
8A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.71d