PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
CVE Watch373,020 in full archive

Vulnerabilities exploitable today

373,020in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644

Distribution · last window

  • Critical
    2,213
  • High
    8,121
  • Medium
    6,188
  • Low
    613
Filters

Window

Severity

Flags

Vulnerabilities280,161–280,200 · 373,020
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41088
24.6%
7
CVE-2016-7620
24.6%
7
CVE-2026-768868.1 HIG
24.6%
7C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service15d
CVE-2026-100138.8 HIG
24.6%
7Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)54d
CVE-2016-8774
24.6%
7
CVE-2025-58095
24.6%
7
CVE-2026-2490
24.6%
7
CVE-2024-55891
24.6%
7
CVE-2025-45586
24.6%
7
CVE-2025-54761
24.6%
7
CVE-2019-25451
24.6%
7
CVE-2020-4382
24.6%
7
CVE-2006-1166
24.6%
7
CVE-2023-47081
24.6%
7
CVE-2018-3661
24.6%
7
CVE-2019-4298
24.6%
7
CVE-2026-44257
24.6%
7
CVE-2014-4225
24.6%
7
CVE-2024-47097
24.6%
7
CVE-2025-12285
24.6%
7
CVE-2025-9241
24.6%
7
CVE-2014-7251
24.6%
7
CVE-2025-2544
24.6%
7
CVE-2026-735606.5 MED
24.6%
7vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, requests.get, and Image.open instead of MediaConnector, bypassing allowed_media_domains and allowed_local_media_path protections and allowing server-side requests and reads of arbitrary files accessible to the vLLM process. This issue is fixed in version 0.26.0.26d
CVE-2025-2836
24.6%
7
CVE-2025-8938
24.6%
7
CVE-2025-54474
24.6%
7
CVE-2026-95287.3 HIG
24.6%
7A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.52d
CVE-2012-5303
24.6%
7
CVE-2024-21961
24.6%
7
CVE-2024-12597
24.6%
7
CVE-2023-48636
24.6%
7
CVE-2022-35867
24.6%
7
CVE-2026-21530
24.6%
7
CVE-2024-38351
24.6%
7
CVE-2026-95257.3 HIG
24.6%
7A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.52d
CVE-2025-48929
24.6%
7
CVE-2008-4993
24.6%
7
CVE-2026-672135.9 MED
24.6%
7nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.26d
CVE-2026-56401
24.6%
7Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.60d