PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch369,575 in full archive

Vulnerabilities exploitable today

369,575in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638

Distribution · last window

  • Critical
    2,111
  • High
    7,598
  • Medium
    5,690
  • Low
    556
Filters

Window

Severity

Flags

Vulnerabilities290,521–290,560 · 369,575
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-3176
21.2%
6
CVE-2025-13036
21.2%
6
CVE-2026-579897.4 HIG
21.2%
6Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.35d
CVE-2025-20240
21.2%
6
CVE-2025-52081
21.2%
6
CVE-2025-27835
21.2%
6
CVE-2024-29958
21.2%
6
CVE-2025-53499
21.2%
6
CVE-2024-11352
21.2%
6
CVE-2026-656018.8 HIG
21.2%
6Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.32d
CVE-2025-2533
21.2%
6
CVE-2025-49860
21.2%
6
CVE-2025-22702
21.2%
6
CVE-2022-41302
21.2%
6
CVE-2020-4885
21.2%
6
CVE-2025-31889
21.2%
6
CVE-2026-76237
21.2%
6stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count queries and _get_quarantined_fact in routes/quarantine.py lacked a tenant_id predicate and the garden lookup was not tenant-scoped, allowing a tenant administrator with only a plain tenant write capability to list, read, and admit or reject quarantined facts belonging to other tenants via the /v1/quarantine endpoints. Default single-tenant deployments are not affected.18d
CVE-2024-29969
21.2%
6
CVE-2025-0245
21.2%
6
CVE-2026-2714
21.2%
6
CVE-2024-57773
21.2%
6
CVE-2024-45250
21.2%
6
CVE-2026-561008.1 HIG
21.2%
6SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing without verifying user roles or caller identity, and leverage a hardcoded JWT signing key embedded in publicly available JARs to forge tokens and escalate privileges from a low-privilege user to administrator, enabling cross-tenant data pollution and persistent backdoor access.10d
CVE-2024-40712
21.2%
6
CVE-2026-635215.5 MED
21.2%
6Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.24d
CVE-2021-1797
21.2%
6
CVE-2025-30893
21.2%
6
CVE-2025-60120
21.2%
6
CVE-2025-59014
21.2%
6
CVE-2026-77298
21.2%
6SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM role without enforcing that role's trust policy, so a federated user can assume a role they are not permitted to hold. The standard STS AssumeRoleWithWebIdentity path rejects such a token when the role's trust policy does not trust the token's federated provider, but the direct S3 bearer path validates only the token itself and then authenticates as the mapped role and evaluates that role's attached S3 permissions. As a result, a valid OIDC user whose token would be denied the role through STS can obtain the role's S3 access, including object read, write, and delete, by presenting the raw OIDC JWT directly to the S3 API. This issue is fixed in version 4.4011d
CVE-2019-0042
21.2%
6
CVE-2017-2702
21.2%
6
CVE-2010-2368
21.2%
6
CVE-2024-48238
21.2%
6
CVE-2025-58659
21.2%
6
CVE-2017-0355
21.2%
6
CVE-2025-58269
21.2%
6
CVE-2024-57822
21.2%
6
CVE-2011-2977
21.2%
6
CVE-2025-24737
21.2%
6