PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch371,523 in full archive

Vulnerabilities exploitable today

371,523in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637

Distribution · last window

  • Critical
    2,229
  • High
    8,605
  • Medium
    6,351
  • Low
    586
Filters

Window

Severity

Flags

Vulnerabilities287,321–287,360 · 371,523
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-45306
22.1%
7
CVE-2021-27046
22.1%
7
CVE-2025-36134
22.1%
7
CVE-2025-60595
22.1%
7
CVE-2026-27919
22.1%
7
CVE-2024-47610
22.1%
7
CVE-2017-8206
22.1%
7
CVE-2026-74906
22.1%
7
CVE-2010-0229
22.1%
7
CVE-2018-16665
22.1%
7
CVE-2002-2274
22.1%
7
CVE-2019-20662
22.1%
7
CVE-2026-1410
22.1%
7
CVE-2025-47081
22.1%
7
CVE-2025-32354
22.1%
7
CVE-2024-2301
22.1%
7
CVE-2025-53768
22.1%
7
CVE-2024-50353
22.1%
7
CVE-2025-13387
22.1%
7
CVE-2026-48743
22.1%
7
CVE-2026-40408
22.1%
7
CVE-2026-26161
22.1%
7
CVE-2026-404097.8 HIG
22.1%
7Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability48d
CVE-2026-503737.8 HIG
22.1%
7Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.49d
CVE-2026-504237.8 HIG
22.1%
7Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.49d
CVE-2025-384958.8 HIG
22.1%
7In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account for that extra byte, meaning that instead of having 8 guaranteed bytes for implement to be working, we only have 7.41d
CVE-2023-47666
22.1%
7
CVE-2021-33076
22.1%
7
CVE-2026-503337.8 HIG
22.1%
7Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.48d
CVE-2026-610497.1 HIG
22.1%
7Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Production Scheduling. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).34d
CVE-2026-117806.4 MED
22.1%
7The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.20d
CVE-2024-6064
22.1%
7
CVE-2025-2950
22.1%
7
CVE-2026-503467.8 HIG
22.1%
7Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.49d
CVE-2026-503447.8 HIG
22.1%
7Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.48d
CVE-2026-705925.5 MED
22.1%
7Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fixed in version 6.54.1.12h
CVE-2024-5440
22.1%
7
CVE-2024-52592
22.1%
7
CVE-2024-8851
22.1%
7
CVE-2026-27915
22.1%
7