PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch369,638 in full archive

Vulnerabilities exploitable today

369,638in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638

Distribution · last window

  • Critical
    2,121
  • High
    7,610
  • Medium
    5,709
  • Low
    559
Filters

Window

Severity

Flags

Vulnerabilities289,761–289,800 · 369,638
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-126958.1 HIG
21.4%
6The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.13d
CVE-2014-6873
21.4%
6
CVE-2025-66201
21.4%
6
CVE-2026-30078
21.4%
6
CVE-2022-4549
21.4%
6
CVE-2026-48904
21.4%
6
CVE-2014-6909
21.4%
6
CVE-2025-69430
21.4%
6
CVE-2024-48898
21.4%
6
CVE-2017-11747
21.4%
6
CVE-2026-163628.8 HIG
21.4%
6Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.46d
CVE-2024-2211
21.4%
6
CVE-2026-624845.9 MED
21.4%
6Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).43d
CVE-2026-843249.0 CRI
21.4%
6Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)5d
CVE-2014-7467
21.4%
6
CVE-2014-7334
21.4%
6
CVE-2025-48448
21.4%
6
CVE-2026-53537
21.4%
6
CVE-2025-37881
21.4%
6
CVE-2025-33023
21.4%
6
CVE-2025-9452
21.4%
6
CVE-2026-0912
21.4%
6
CVE-2024-45400
21.4%
6
CVE-2024-7863
21.4%
6
CVE-2026-671815.4 MED
21.4%
6Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desynchronization attacks where attackers control where the backend believes the request body ends.40d
CVE-2023-25526
21.4%
6
CVE-2026-58638.8 HIG
21.4%
6Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)46d
CVE-2014-6855
21.4%
6
CVE-2026-10831
21.4%
6
CVE-2014-7585
21.4%
6
CVE-2025-31876
21.4%
6
CVE-2014-7310
21.4%
6
CVE-2025-2352
21.4%
6
CVE-2025-26159
21.4%
6
CVE-2014-7341
21.4%
6
CVE-2025-47651
21.4%
6
CVE-2014-7798
21.4%
6
CVE-2026-47244
21.4%
6
CVE-2026-26079
21.4%
6
CVE-2025-15606
21.4%
6