PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
CVE Watch367,165 in full archive

Vulnerabilities exploitable today

367,165in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629

Distribution · last window

  • Critical
    2,263
  • High
    9,269
  • Medium
    5,274
  • Low
    508
Filters

Window

Severity

Flags

Vulnerabilities303,641–303,680 · 367,165
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-12929
17.2%
5
CVE-2024-49682
17.2%
5
CVE-2023-3488
17.2%
5
CVE-2023-52380
17.2%
5
CVE-2026-728577.7 HIG
17.2%
5Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.17d
CVE-2026-656717.8 HIG
17.2%
5Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.15d
CVE-2026-687586.5 MED
17.2%
5A low-privileged authenticated user may access restricted support information under specific conditions.3d
CVE-2024-49959
17.2%
5
CVE-2021-44900
17.2%
5
CVE-2026-583847.3 HIG
17.2%
5A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.46d
CVE-2026-657747.8 HIG
17.2%
5Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.14d
CVE-2022-20362
17.2%
5
CVE-2022-20283
17.2%
5
CVE-2026-762257.7 HIG
17.2%
5ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and return sensitive data from restricted services.10d
CVE-2026-6489
17.2%
5
CVE-2022-48730
17.2%
5
CVE-2024-53162
17.2%
5
CVE-2020-1707
17.2%
5
CVE-2009-2794
17.2%
5
CVE-2024-55907
17.2%
5
CVE-2026-32898
17.2%
5
CVE-2024-44183
17.2%
5
CVE-2026-48934
17.2%
5
CVE-2026-4830
17.2%
5
CVE-2026-448846.5 MED
17.2%
5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template file endpoint (GET /api/custom_templates/{id}/file) allows any authenticated user to read the file content of any custom template by enumerating sequential integer IDs, bypassing Resource Control access restrictions. Template files may contain environment-specific values such as connection strings, API tokens, or registry credentials that administrators would not expect standard users to read. This vulnerability is fixed in 2.33.8 and 2.39.1.41d
CVE-2026-583807.3 HIG
17.2%
5A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.46d
CVE-2026-656727.8 HIG
17.2%
5Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.17d
CVE-2023-29745
17.2%
5
CVE-2024-11261
17.2%
5
CVE-2022-48186
17.2%
5
CVE-2019-19346
17.2%
5
CVE-2026-108908.8 HIG
17.2%
5Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)40d
CVE-2025-14595
17.2%
5
CVE-2021-1106
17.2%
5
CVE-2025-22757
17.2%
5
CVE-2021-40013
17.2%
5
CVE-2026-45715
17.2%
5
CVE-2022-3728
17.2%
5
CVE-2021-47313
17.2%
5
CVE-2024-43794
17.2%
5