PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSS
CVE Watch372,403 in full archive

Vulnerabilities exploitable today

372,403in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644

Distribution · last window

  • Critical
    2,230
  • High
    8,254
  • Medium
    6,232
  • Low
    617
Filters

Window

Severity

Flags

Vulnerabilities283,441–283,480 · 372,403
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-42908
23.7%
7
CVE-2025-42603
23.7%
7
CVE-2026-839547.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d
CVE-2018-1000423
23.7%
7
CVE-2021-35549
23.7%
7
CVE-2026-156474.4 MED
23.7%
7The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.50d
CVE-2023-43090
23.7%
7
CVE-2026-825368.8 HIG
23.7%
7Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component with the agent's auto-execute privileges on the developer's machine.3d
CVE-2026-839727.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d
CVE-2026-839797.8 HIG
23.7%
7Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1d
CVE-2026-839867.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d
CVE-2026-839807.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d
CVE-2026-839817.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.1d
CVE-2026-839787.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d
CVE-2026-839707.8 HIG
23.7%
7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2d
CVE-2026-18323
23.7%
7
CVE-2026-4061
23.7%
7
CVE-2025-8616
23.7%
7
CVE-2025-66205
23.7%
7
CVE-2023-34130
23.7%
7
CVE-2026-56317.3 HIG
23.7%
7A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.50d
CVE-2025-31071
23.7%
7
CVE-2021-0168
23.7%
7
CVE-2025-31065
23.7%
7
CVE-2026-39871
23.7%
7
CVE-2026-24364
23.7%
7
CVE-2023-42904
23.7%
7
CVE-2026-825987.3 HIG
23.7%
7A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.10d
CVE-2026-6603
23.7%
7
CVE-2026-732258.1 HIG
23.7%
7electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recursive transfers in src/client/components/file-transfer/transfer.jsx pass server-supplied file.name and folder.name values to resolve without sanitization. This issue is fixed in version 3.15.120.2d
CVE-2026-7703
23.7%
7
CVE-2025-6778
23.7%
7
CVE-2026-732238.1 HIG
23.7%
7electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-controlled filename name used by editWithSystemEditor in src/client/components/sftp/file-item.jsx is interpolated into path.resolve without sanitization. This issue is fixed in version 3.15.120.2d
CVE-2025-24026
23.7%
7
CVE-2023-42903
23.7%
7
CVE-2025-11369
23.7%
7
CVE-2025-4375
23.7%
7
CVE-2026-24850
23.7%
7
CVE-2026-627117.8 HIG
23.7%
7Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.26d
CVE-2026-3658
23.7%
7