PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / Libuser
CVE Watch368,208 in full archive

Vulnerabilities exploitable today

368,208in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631

Distribution · last window

  • Critical
    2,147
  • High
    7,679
  • Medium
    5,506
  • Low
    542
Filters

Window

Severity

Flags

Vulnerabilities296,401–296,440 · 368,208
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15340
19.3%
6
CVE-2022-49663
19.3%
6
CVE-2025-27500
19.3%
6
CVE-2026-708878.2 HIG
19.3%
6Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).14d
CVE-2024-22880
19.3%
6
CVE-2026-5252
19.3%
6
CVE-2022-42331
19.3%
6
CVE-2024-7963
19.3%
6
CVE-2026-822398.1 HIG
19.3%
6Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.6d
CVE-2021-29415
19.3%
6
CVE-2024-27814
19.3%
6
CVE-2024-4546
19.3%
6
CVE-2020-36431
19.3%
6
CVE-2020-9855
19.3%
6
CVE-2022-49723
19.3%
6
CVE-2020-33525.5 MED
19.3%
6A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the hidden commands accessible. A successful exploit could allow the attacker to make configuration changes to various sections of an affected device that should not be exposed to CLI access.23d
CVE-2026-42725
19.3%
6
CVE-2025-24117
19.3%
6
CVE-2020-2154
19.3%
6
CVE-2020-27211
19.3%
6
CVE-2025-58249
19.3%
6
CVE-2024-37408
19.3%
6
CVE-2026-45301
19.3%
6
CVE-2026-137005.9 MED
19.3%
6The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.9d
CVE-2026-29069
19.3%
6
CVE-2022-32877
19.3%
6
CVE-2019-25605
19.3%
6
CVE-2022-39199
19.3%
6
CVE-2024-21456
19.3%
6
CVE-2024-45679
19.3%
6
CVE-2024-2115
19.3%
6
CVE-2022-49063
19.3%
6
CVE-2025-27914
19.3%
6
CVE-2023-49883
19.3%
6
CVE-2025-58252
19.3%
6
CVE-2026-64536.5 MED
19.3%
6The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a raw SQL query without using $wpdb->prepare(). The wp_unslash() call explicitly removes the backslash escaping that WordPress's wp_magic_quotes() adds to all $_POST data, neutralizing the only layer of SQL injection protection. The sanitize_text_field() function applied afterward offers no SQL protection. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries to the existing query.22d
CVE-2025-50866
19.3%
6
CVE-2024-39643
19.3%
6
CVE-2021-1071
19.3%
6
CVE-2025-0865
19.3%
6