PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
CVE Watch374,209 in full archive

Vulnerabilities exploitable today

374,209in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645

Distribution · last window

  • Critical
    2,347
  • High
    8,411
  • Medium
    6,454
  • Low
    715
Filters

Window

Severity

Flags

Vulnerabilities276,001–276,040 · 374,209
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12109
26.0%
8
CVE-2019-4349
26.0%
8
CVE-2017-1190
25.9%
8
CVE-2025-28169
25.9%
8
CVE-2021-43940
25.9%
8
CVE-2026-43899
25.9%
8
CVE-2026-73156
25.9%
8Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types, relationship_type, pattern prefixes, and MISP category/type values. Since ECharts interprets the formatter return value as HTML, crafted values can inject markup or script-capable content into the tooltip. An attacker who can cause malicious conversion data to be processed can therefore inject content that executes when another user views the visualization and hovers over the affected slice. The patch replaces direct interpolation with dedicated formatter functions that call escapeHtml() on p.name, p.data.value, and p.value.20d
CVE-2026-878217.1 HIG
25.9%
8Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions.6d
CVE-2026-22247
25.9%
8
CVE-2026-48945
25.9%
8
CVE-2020-37175
25.9%
8
CVE-2014-6133
25.9%
8
CVE-2023-1937
25.9%
8
CVE-2021-1757
25.9%
8
CVE-2014-8537
25.9%
8
CVE-2025-64134
25.9%
8
CVE-2023-6693
25.9%
8
CVE-2026-826044.3 MED
25.9%
8A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.15d
CVE-2024-35679
25.9%
8
CVE-2025-58207
25.9%
8
CVE-2024-11708
25.9%
8
CVE-2026-57633
25.9%
8
CVE-2025-36137
25.9%
8
CVE-2025-67575
25.9%
8
CVE-2025-8526
25.9%
8
CVE-2025-64327
25.9%
8
CVE-2025-47910
25.9%
8
CVE-2026-654905.3 MED
25.9%
8Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.54d
CVE-2024-11200
25.9%
8
CVE-2024-447976.1 MED
25.9%
8A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.73d
CVE-2013-5440
25.9%
8
CVE-2021-30676
25.9%
8
CVE-2026-1267
25.9%
8
CVE-2024-0137
25.9%
8
CVE-2015-4834
25.9%
8
CVE-2022-20370
25.9%
8
CVE-2025-30744
25.9%
8
CVE-2024-36377
25.9%
8
CVE-2024-36376
25.9%
8
CVE-2023-1643
25.9%
8