PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
CVE Watch373,020 in full archive

Vulnerabilities exploitable today

373,020in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644

Distribution · last window

  • Critical
    2,213
  • High
    8,121
  • Medium
    6,188
  • Low
    613
Filters

Window

Severity

Flags

Vulnerabilities280,281–280,320 · 373,020
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32945
24.6%
7
CVE-2026-178379.6 CRI
24.6%
7Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)40d
CVE-2025-10185
24.6%
7
CVE-2024-7011
24.6%
7
CVE-2022-2657
24.6%
7
CVE-2026-46684
24.6%
7DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses JWT.decode() without signature verification, allowing forged tokens with chosen uid and oid values to be accepted when licenseValid=true. This issue is fixed in version 2.10.23.57d
CVE-2004-1066
24.6%
7
CVE-2026-55237
24.6%
7
CVE-2024-47782
24.6%
7
CVE-2026-528318.0 HIG
24.6%
7Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This issue has been patched in version 1.16.4.10d
CVE-2025-14697
24.6%
7
CVE-2006-6618
24.6%
7
CVE-2026-843478.8 HIG
24.6%
7Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)10d
CVE-2026-33129
24.6%
7
CVE-2011-2145
24.6%
7
CVE-2021-0124
24.6%
7
CVE-2024-7251
24.6%
7
CVE-2026-3739
24.6%
7
CVE-2025-68002
24.6%
7
CVE-2023-6195
24.6%
7
CVE-2021-39780
24.6%
7
CVE-2023-1697
24.6%
7
CVE-2026-56027
24.6%
7
CVE-2026-24390
24.6%
7
CVE-2020-4492
24.6%
7
CVE-2010-2376
24.6%
7
CVE-2023-7012
24.6%
7
CVE-2025-36752
24.6%
7
CVE-2023-432325.4 MED
24.6%
7A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.66d
CVE-2026-26362
24.6%
7
CVE-2006-6623
24.6%
7
CVE-2025-49549
24.6%
7
CVE-2006-6621
24.6%
7
CVE-2026-40562
24.6%
7
CVE-2024-7252
24.6%
7
CVE-2021-36234
24.6%
7
CVE-2024-477218.8 HIG
24.6%
7In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: remove unused C2H event ID RTW89_MAC_C2H_FUNC_READ_WOW_CAM to prevent out-of-bounds reading The handler of firmware C2H event RTW89_MAC_C2H_FUNC_READ_WOW_CAM isn't implemented, but driver expects number of handlers is NUM_OF_RTW89_MAC_C2H_FUNC_WOW causing out-of-bounds access. Fix it by removing ID. Addresses-Coverity-ID: 1598775 ("Out-of-bounds read")40d
CVE-2026-8180
24.6%
7
CVE-2026-28452
24.6%
7
CVE-2026-34510
24.6%
7