PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSS
CVE Watch372,403 in full archive

Vulnerabilities exploitable today

372,403in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644

Distribution · last window

  • Critical
    2,280
  • High
    8,398
  • Medium
    6,461
  • Low
    636
Filters

Window

Severity

Flags

Vulnerabilities283,881–283,920 · 372,403
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-30274
23.6%
7
CVE-2025-61820
23.6%
7
CVE-2026-1509
23.6%
7
CVE-2026-554616.1 MED
23.6%
7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is submitted, allowing Snipe-IT to be used as a trusted redirector after a legitimate user edit action. This issue is fixed in version 8.6.2.59d
CVE-2013-0411
23.6%
7
CVE-2020-6022
23.6%
7
CVE-2024-10777
23.6%
7
CVE-2023-41736
23.6%
7
CVE-2026-42197
23.6%
7
CVE-2024-56353
23.6%
7
CVE-2025-55138
23.6%
7
CVE-2018-8857
23.6%
7
CVE-2017-12553
23.6%
7
CVE-2025-36220
23.6%
7
CVE-2023-46091
23.6%
7
CVE-2025-4665
23.6%
7
CVE-2026-825894.3 MED
23.6%
7A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message Handler. Performing a manipulation of the argument N1N2MessageTransferReqData.n2InfoContainer.smInfo.n2InfoContent.ngapIeType results in denial of service. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.8.0 is recommended to address this issue. The patch is named abf8a836564b966b5141110fc25ed413c4f17522. It is advisable to upgrade the affected component.11d
CVE-2026-42551
23.6%
7
CVE-2024-1683
23.6%
7
CVE-2024-7848
23.6%
7
CVE-2026-20138
23.6%
7
CVE-2025-11379
23.6%
7
CVE-2024-12166
23.6%
7
CVE-2026-20188
23.6%
7
CVE-2008-4992
23.6%
7
CVE-2025-61824
23.6%
7
CVE-2025-30272
23.6%
7
CVE-2026-498409.1 CRI
23.6%
7FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no sign or magnitude check. A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process linked against libesl, before the client has authenticated to that peer. This issue has been patched in version 1.11.1.51d
CVE-2012-1683
23.6%
7
CVE-2021-29544
23.6%
7
CVE-2025-10061
23.5%
7
CVE-2026-368137.5 HIG
23.5%
7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50d
CVE-2025-53713
23.5%
7
CVE-2025-13409
23.5%
7
CVE-2023-22812
23.5%
7
CVE-2023-45608
23.5%
7
CVE-2022-42797
23.5%
7
CVE-2022-3567
23.5%
7
CVE-2025-54295
23.5%
7
CVE-2019-14562
23.5%
7