PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch369,346 in full archive

Vulnerabilities exploitable today

369,346in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636

Distribution · last window

  • Critical
    2,104
  • High
    7,540
  • Medium
    5,575
  • Low
    539
Filters

Window

Severity

Flags

Vulnerabilities292,281–292,320 · 369,346
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-1638
20.7%
6
CVE-2019-15358
20.7%
6
CVE-2019-15362
20.7%
6
CVE-2022-1760
20.7%
6
CVE-2025-0276
20.7%
6
CVE-2010-2525
20.7%
6
CVE-2026-179518.8 HIG
20.7%
6Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)34d
CVE-2025-66075
20.7%
6
CVE-2025-12904
20.7%
6
CVE-2025-1276
20.7%
6
CVE-2020-36207
20.7%
6
CVE-2026-40461
20.7%
6
CVE-2025-66947
20.7%
6
CVE-2026-42156
20.7%
6
CVE-2026-110276.5 MED
20.7%
6Insufficient validation of untrusted input in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)46d
CVE-2024-54485
20.7%
6
CVE-2026-478815.9 MED
20.7%
6Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader assembles those multi-line records to consume excessive CPU time and memory, causing the batch job to stall or run out of memory. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 Spring Batch 4.3.0 - 4.3.135d
CVE-2019-15391
20.7%
6
CVE-2019-15355
20.7%
6
CVE-2019-15374
20.7%
6
CVE-2026-683548.8 HIG
20.7%
6In the Linux kernel, the following vulnerability has been resolved: firewire: net: Fix fragmented datagram reassembly fwnet_frag_new() keeps a sorted list of received fragments for a partial datagram. When a new fragment is adjacent to an existing fragment, the code checks whether the new fragment also closes the gap to the next or previous list entry. Those neighbor lookups currently assume that the current fragment always has a real next or previous fragment. At a list edge, the next or previous entry is the list head, not a struct fwnet_fragment_info. The gap checks also compare against the old edge of the current fragment instead of the edge after adding the new fragment. As a result, a fragment that bridges two existing ranges may leave two adjacent ranges unmerged, so fwnet_pd_is_complete() can miss a complete datagram. Check for the list head before looking up the neighboring fragment, and compare the neighbor against the new fragment's far edge when deciding whether to merge all three ranges. This issue was found by a static analysis checker and confirmed by manual source review.18d
CVE-2019-15371
20.7%
6
CVE-2023-5839
20.7%
6
CVE-2023-51363
20.7%
6
CVE-2019-15359
20.7%
6
CVE-2025-55948
20.7%
6
CVE-2026-35647
20.7%
6
CVE-2000-0313
20.7%
6
CVE-2019-15392
20.7%
6
CVE-2019-15381
20.7%
6
CVE-2025-49292
20.7%
6
CVE-2025-33126
20.7%
6
CVE-2019-15369
20.7%
6
CVE-2025-33132
20.7%
6
CVE-2025-62906
20.7%
6
CVE-2025-5302
20.7%
6
CVE-2019-15352
20.7%
6
CVE-2025-0277
20.7%
6
CVE-2026-163137.6 HIG
20.7%
6A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.6d
CVE-2025-23405
20.7%
6