PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
CVE Watch372,980 in full archive

Vulnerabilities exploitable today

372,980in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644

Distribution · last window

  • Critical
    2,214
  • High
    8,131
  • Medium
    6,162
  • Low
    611
Filters

Window

Severity

Flags

Vulnerabilities281,481–281,520 · 372,980
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-46952
24.3%
7
CVE-2012-5564
24.3%
7
CVE-2023-44986
24.3%
7
CVE-2025-68515
24.3%
7
CVE-2010-4458
24.3%
7
CVE-2024-3277
24.3%
7
CVE-2025-0952
24.3%
7
CVE-2022-43040
24.3%
7
CVE-2023-35041
24.3%
7
CVE-2024-2578
24.3%
7
CVE-2023-4207
24.3%
7
CVE-2022-29211
24.3%
7
CVE-2021-45339
24.3%
7
CVE-2025-8032
24.3%
7
CVE-2025-67478
24.3%
7
CVE-2025-11168
24.3%
7
CVE-2024-30214
24.3%
7
CVE-2008-5746
24.3%
7
CVE-2026-88518.1 HIG
24.3%
7SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.51d
CVE-2026-554375.4 MED
24.3%
7Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters. Exploitation requires a victim to view attacker-controlled agent logs in the dashboard. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables `escapeXML: true` so HTML metacharacters are escaped before DOM insertion. No known workarounds are available.66d
CVE-2026-161847.0 HIG
24.3%
7IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.40d
CVE-2024-32745
24.3%
7
CVE-2024-6504
24.3%
7
CVE-2026-175417.5 HIG
24.3%
7The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.17d
CVE-2025-61775
24.3%
7
CVE-2024-51518
24.3%
7
CVE-2023-7306
24.3%
7
CVE-2026-4564
24.3%
7
CVE-2023-50830
24.3%
7
CVE-2026-110889.6 CRI
24.3%
7Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)51d
CVE-2022-22528
24.3%
7
CVE-2022-41686
24.3%
7
CVE-2022-47658
24.3%
7
CVE-2022-1524
24.3%
7
CVE-2018-4283
24.3%
7
CVE-2024-13801
24.3%
7
CVE-2026-25325
24.3%
7
CVE-2025-22561
24.3%
7
CVE-2024-13101
24.3%
7
CVE-2026-4949
24.3%
7