PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / Libuser
CVE Watch368,208 in full archive

Vulnerabilities exploitable today

368,208in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631

Distribution · last window

  • Critical
    2,147
  • High
    7,679
  • Medium
    5,506
  • Low
    542
Filters

Window

Severity

Flags

Vulnerabilities296,841–296,880 · 368,208
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-49460
19.2%
6
CVE-2023-32546
19.2%
6
CVE-2026-28188.2 HIG
19.2%
6A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.51d
CVE-2026-219544.3 MED
19.2%
6Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).27d
CVE-2020-8320
19.2%
6
CVE-2024-8820
19.2%
6
CVE-2024-27202
19.2%
6
CVE-2024-8835
19.2%
6
CVE-2017-18829
19.2%
6
CVE-2023-42016
19.2%
6
CVE-2023-32093
19.2%
6
CVE-2025-5797
19.2%
6
CVE-2026-43828
19.2%
6
CVE-2024-3640
19.2%
6
CVE-2021-3659
19.2%
6
CVE-2024-41002
19.2%
6
CVE-2026-5721
19.2%
6
CVE-2023-23455
19.2%
6
CVE-2024-49606
19.2%
6
CVE-2024-13243
19.2%
6
CVE-2021-32993
19.2%
6
CVE-2023-33156
19.2%
6
CVE-2024-8819
19.2%
6
CVE-2026-137227.2 HIG
19.2%
6WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.7d
CVE-2023-34177
19.2%
6
CVE-2025-24810
19.2%
6
CVE-2021-21550
19.2%
6
CVE-2024-45269
19.2%
6
CVE-2024-39381
19.2%
6
CVE-2024-49323
19.2%
6
CVE-2023-5756
19.2%
6
CVE-2026-547847.4 HIG
19.2%
6CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.56d
CVE-2026-24853
19.2%
6
CVE-2026-24470
19.2%
6
CVE-2025-14202
19.2%
6
CVE-2025-26497
19.2%
6
CVE-2025-6425
19.2%
6
CVE-2022-26309
19.2%
6
CVE-2024-8828
19.2%
6
CVE-2024-47846
19.2%
6