PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / Libuser
CVE Watch368,208 in full archive

Vulnerabilities exploitable today

368,208in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631

Distribution · last window

  • Critical
    2,140
  • High
    7,668
  • Medium
    5,506
  • Low
    542
Filters

Window

Severity

Flags

Vulnerabilities296,161–296,200 · 368,208
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-47889
19.4%
6
CVE-2025-61906
19.4%
6
CVE-2025-59192
19.4%
6
CVE-2025-46874
19.4%
6
CVE-2021-0314
19.4%
6
CVE-2025-30363
19.4%
6
CVE-2025-3862
19.4%
6
CVE-2025-46859
19.4%
6
CVE-2024-27048
19.4%
6
CVE-2025-36756
19.4%
6
CVE-2025-46851
19.4%
6
CVE-2026-411087.0 HIG
19.4%
6Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.43d
CVE-2025-3609
19.4%
6
CVE-2020-29383
19.4%
6
CVE-2024-54470
19.4%
6
CVE-2024-41037
19.4%
6
CVE-2020-7120
19.4%
6
CVE-2026-24529
19.4%
6
CVE-2002-2301
19.4%
6
CVE-2024-47134
19.4%
6
CVE-2025-57818
19.4%
6
CVE-2026-26417
19.4%
6
CVE-2026-746518.1 HIG
19.4%
6In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() rtw_get_wpa_ie() reads bytes at fixed offsets into a vendor-specific information element without checking that the element is long enough, causing an out-of-bounds read for a short trailing IE. The function locates a vendor-specific IE (EID 221) with rtw_get_ie() and then compares a 4-byte OUI+type at pbuf + 2 and reads a 2-byte version word at pbuf + 6. Those accesses require the IE body to be at least 6 bytes, but rtw_get_ie() only guarantees that the element fits within the buffer; it does not enforce a minimum body length. A vendor-specific IE whose length byte is 0 to 5, placed at the end of the buffer, therefore makes these reads run past the end of the IE and past the end of the buffer itself. The buffer holds information elements taken from received management frames and from the IE blob passed to rtw_cfg80211_set_wpa_ie(), which is kmemdup'd to its exact length, so the read can run off the end of the allocation. The sibling helpers rtw_get_sec_ie(), rtw_get_wapi_ie() and rtw_get_wps_ie() in this file already reject too-short vendor-specific IEs before their OUI memcmp(); rtw_get_wpa_ie() was never brought in line with them, and needs a minimum of 6 rather than 4 bytes because of the version word. Add the missing length check.10d
CVE-2024-49642
19.4%
6
CVE-2014-9914
19.4%
6
CVE-2026-44508
19.4%
6Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.45d
CVE-2023-52150
19.4%
6
CVE-2025-48067
19.4%
6
CVE-2023-41072
19.4%
6
CVE-2024-47136
19.4%
6
CVE-2025-46878
19.4%
6
CVE-2024-27955
19.4%
6
CVE-2024-48843
19.4%
6
CVE-2022-44937
19.4%
6
CVE-2024-44060
19.4%
6
CVE-2014-3940
19.4%
6
CVE-2025-607307.6 HIG
19.4%
6PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function61d
CVE-2026-31464
19.4%
6
CVE-2026-24440
19.4%
6
CVE-2023-1032
19.4%
6