PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,347
  • High
    8,411
  • Medium
    6,454
  • Low
    715
Filters

Window

Severity

Flags

Vulnerabilities274,921–274,960 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-0314
26.2%
8
CVE-2026-54715
26.2%
8GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.7d
CVE-2026-490896.5 MED
26.2%
8Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an unbounded amount of time evaluating it. An authenticated user with read-only privileges was able to send a single request that left Kibana unable to serve any user until the process was restarted.13d
CVE-2017-6254
26.2%
8
CVE-2025-15331
26.2%
8
CVE-2026-172487.1 HIG
26.2%
8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.33d
CVE-2017-0348
26.2%
8
CVE-2017-0323
26.2%
8
CVE-2017-0344
26.2%
8
CVE-2023-25873
26.2%
8
CVE-2026-54185
26.2%
8
CVE-2026-40766
26.2%
8
CVE-2025-2606
26.2%
8
CVE-2022-42376
26.2%
8
CVE-2023-25863
26.2%
8
CVE-2024-39838
26.2%
8
CVE-2017-0347
26.2%
8
CVE-2026-42400
26.2%
8
CVE-2026-281688.5 HIG
26.2%
8Subscriber SQL Injection in CubeWP <= 1.1.30 versions.32d
CVE-2017-6252
26.2%
8
CVE-2026-389679.8 CRI
26.2%
8CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.55d
CVE-2026-345038.1 HIG
26.2%
8OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.53d
CVE-2006-2464
26.2%
8
CVE-2025-7677
26.2%
8
CVE-2023-26348
26.2%
8
CVE-2017-6255
26.2%
8
CVE-2022-42387
26.2%
8
CVE-2006-5737
26.2%
8
CVE-2026-573776.5 MED
26.2%
8Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.64d
CVE-2024-35228
26.2%
8
CVE-2026-726796.5 MED
26.2%
8Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.14d
CVE-2023-26343
26.2%
8
CVE-2026-726786.5 MED
26.2%
8Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that causes the node to attempt an excessively large allocation. The resulting memory exhaustion raises a fatal error that terminates the Elasticsearch node process, causing a denial of service for the affected node and degrading cluster health. The defect is not volumetric, so a single request is sufficient regardless of the heap size configured on the target node.14d
CVE-2026-48967
26.2%
8
CVE-2022-42412
26.2%
8
CVE-2026-32524
26.2%
8
CVE-2026-48874
26.2%
8
CVE-2026-48964
26.2%
8
CVE-2023-26350
26.2%
8
CVE-2023-26351
26.2%
8