PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch369,332 in full archive

Vulnerabilities exploitable today

369,332in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636

Distribution · last window

  • Critical
    2,107
  • High
    7,541
  • Medium
    5,581
  • Low
    536
Filters

Window

Severity

Flags

Vulnerabilities292,601–292,640 · 369,332
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25124
20.6%
6
CVE-2026-140524.3 MED
20.6%
6Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)67d
CVE-2024-48021
20.6%
6
CVE-2026-563653.7 LOW
20.6%
6ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.66d
CVE-2025-611639.8 CRI
20.6%
6Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.3d
CVE-2018-25381
20.6%
6
CVE-2025-68033
20.6%
6
CVE-2025-64185
20.6%
6
CVE-2025-12461
20.6%
6
CVE-2026-480608.1 HIG
20.6%
6Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.38d
CVE-2024-3124
20.6%
6
CVE-2025-445266.5 MED
20.6%
6Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.63d
CVE-2026-52796
20.6%
6
CVE-2011-0532
20.6%
6
CVE-2023-44385
20.6%
6
CVE-2026-55409
20.6%
6
CVE-2026-658799.8 CRI
20.6%
6Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.40d
CVE-2024-47624
20.6%
6
CVE-2025-41016
20.6%
6
CVE-2022-42309
20.6%
6
CVE-2022-49350
20.6%
6
CVE-2026-718456.3 MED
20.6%
6A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.1d
CVE-2026-35716.5 MED
20.6%
6The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registration form status.44d
CVE-2026-5494
20.6%
6
CVE-2025-14896
20.6%
6
CVE-2012-4508
20.6%
6
CVE-2021-47969
20.6%
6
CVE-2025-21561
20.6%
6
CVE-2025-67931
20.6%
6
CVE-2025-3964
20.6%
6
CVE-2026-584398.1 HIG
20.6%
6Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag11d
CVE-2025-13381
20.6%
6
CVE-2023-28072
20.6%
6
CVE-2023-31669
20.6%
6
CVE-2025-25127
20.6%
6
CVE-2025-30464
20.6%
6
CVE-2021-47970
20.6%
6
CVE-2026-567109.8 CRI
20.6%
6Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.6d
CVE-2025-23530
20.6%
6
CVE-2024-49201
20.6%
6