PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET Professional
CVE Watch369,254 in full archive

Vulnerabilities exploitable today

369,254in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636

Distribution · last window

  • Critical
    2,146
  • High
    7,648
  • Medium
    5,614
  • Low
    537
Filters

Window

Severity

Flags

Vulnerabilities294,161–294,200 · 369,254
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-32501
20.1%
6
CVE-2026-152367.5 HIG
20.1%
6The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.11d
CVE-2024-6883
20.1%
6
CVE-2026-57942
20.1%
6
CVE-2026-39869
20.1%
6
CVE-2025-58006
20.1%
6
CVE-2023-34371
20.1%
6
CVE-2025-41681
20.1%
6
CVE-2024-2405
20.1%
6
CVE-2023-6491
20.1%
6
CVE-2025-27565
20.1%
6
CVE-2023-0468
20.1%
6
CVE-2017-13220
20.1%
6
CVE-2026-20408
20.1%
6
CVE-2025-57733
20.1%
6
CVE-2025-66468
20.1%
6
CVE-2024-8916
20.1%
6
CVE-2020-3209
20.1%
6
CVE-2024-9848
20.1%
6
CVE-2026-792668.8 HIG
20.1%
6Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)6d
CVE-2026-75830
20.1%
6
CVE-2026-63872
20.1%
6Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.26d
CVE-2026-324658.8 HIG
20.1%
6Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.17d
CVE-2015-2263
20.1%
6
CVE-2025-61183
20.1%
6
CVE-2024-51489
20.1%
6
CVE-2022-43980
20.1%
6
CVE-2025-32967
20.1%
6
CVE-2025-520267.5 HIG
20.1%
6An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.63d
CVE-2026-613058.3 HIG
20.1%
6Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).13d
CVE-2026-354599.1 CRI
20.1%
6pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks the hostname of the initial download URL. However, pycurl is configured with FOLLOWLOCATION=1 and MAXREDIRS=10, causing it to automatically follow HTTP redirects. Redirect targets are never validated against the SSRF filter. An authenticated user with ADD permission can bypass the SSRF fix by submitting a URL that redirects to an internal address.43d
CVE-2015-1200
20.1%
6
CVE-2021-31427
20.1%
6
CVE-2025-2580
20.1%
6
CVE-2025-22747
20.1%
6
CVE-2021-459698.2 HIG
20.1%
6An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the CommBuffer+8 location).26d
CVE-2024-4705
20.1%
6
CVE-2024-35739
20.1%
6
CVE-2022-4964
20.1%
6
CVE-2025-22743
20.1%
6