PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
CVE Watch367,165 in full archive

Vulnerabilities exploitable today

367,165in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629

Distribution · last window

  • Critical
    2,263
  • High
    9,269
  • Medium
    5,274
  • Low
    508
Filters

Window

Severity

Flags

Vulnerabilities303,681–303,720 · 367,165
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-6326
17.2%
5
CVE-2024-48023
17.2%
5
CVE-2025-6074
17.2%
5
CVE-2025-24789
17.2%
5
CVE-2026-828749.9 CRI
17.2%
5ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.5h
CVE-2024-35984
17.2%
5
CVE-2019-19348
17.2%
5
CVE-2026-6119
17.2%
5
CVE-2026-248749.1 CRI
17.2%
5Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.1h
CVE-2024-43280
17.2%
5
CVE-2024-33682
17.2%
5
CVE-2023-38960
17.2%
5
CVE-2025-6142
17.2%
5
CVE-2024-49963
17.2%
5
CVE-2024-50966
17.2%
5
CVE-2022-1651
17.2%
5
CVE-2026-41585
17.2%
5
CVE-2019-25627
17.2%
5
CVE-2006-6477
17.2%
5
CVE-2024-40560
17.2%
5
CVE-2022-45190
17.2%
5
CVE-2021-30845
17.2%
5
CVE-2005-1727
17.2%
5
CVE-2025-0982
17.2%
5
CVE-2026-7292
17.2%
5
CVE-2024-13687
17.2%
5
CVE-2026-40882
17.2%
5
CVE-2022-22566
17.2%
5
CVE-2024-32612
17.2%
5
CVE-2026-41153
17.2%
5
CVE-2025-8880
17.2%
5
CVE-2026-80227
17.2%
5Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse). string_trim/1 compiles to REGEXP_REPLACE patterns built from an Elixir string in which \s is the escape for a single space (codepoint 32), not a regex whitespace class. The generated SQL therefore removes only literal spaces and leaves tabs, newlines, carriage returns, and form feeds in place, whereas String.trim/1 in Elixir removes them all. Any Ash filter, validation, or identity that relies on string_trim/1 then behaves differently depending on whether Ash pushes the expression down to SQL or evaluates it in memory, so padded input can register a near-duplicate value or slip past a trimmed comparison. This issue affects ash_sql: from 0.1.0 before 0.7.1.1d
CVE-2026-822408.1 HIG
17.2%
5Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.3d
CVE-2024-58007
17.2%
5
CVE-2026-45548
17.2%
5
CVE-2024-49892
17.2%
5
CVE-2026-27835
17.2%
5
CVE-2026-538687.5 HIG
17.2%
5Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can permanently lock legitimate users out of the platform for 30 days by exploiting unverified email ownership in account lifecycle operations.39d
CVE-2024-32616
17.2%
5
CVE-2025-23361
17.2%
5