PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCentervulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2026-64849 — MLflow / MLflowvulnKEV agrega CVE-2026-33824 — Microsoft / Internet Key Exchange (IKE) Service ExtensionsvulnKEV agrega CVE-2026-59310 — Broadcom / VMware vCenter
CVE Watch365,633 in full archive

Vulnerabilities exploitable today

365,633in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626

Distribution · last window

  • Critical
    2,365
  • High
    10,105
  • Medium
    4,998
  • Low
    469
Filters

Window

Severity

Flags

Vulnerabilities310,641–310,680 · 365,633
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-49386
14.9%
4
CVE-2024-31955
14.9%
4
CVE-2025-6259
14.9%
4
CVE-2026-631406.5 MED
14.9%
4Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node.20d
CVE-2026-73829
14.9%
4Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence: check_hash_unused/2 reads the dedup store, an eth_getTransactionReceipt round trip verifies the payment on chain, and only then does mark_hash_used/2 write the mark. Concurrent requests carrying the same settled payment hash all pass the read before any of them writes, so each is issued a receipt. The store's atomic check_and_mark/2 primitive is available and used by the type="transaction" path, but the hash path calls plain get and put even when the configured store implements it. Exploitation requires a dedup store to be configured; the default nil store is stateless and documented as offering no replay protection at all. This issue affects mpp: from 0.2.0 before 0.6.1.7d
CVE-2026-740075.3 MED
14.9%
4Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.7d
CVE-2026-628767.8 HIG
14.9%
4Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.11d
CVE-2025-5336
14.9%
4
CVE-2020-37018
14.9%
4
CVE-2025-43410
14.9%
4
CVE-2026-627797.8 HIG
14.9%
4Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.14d
CVE-2026-1395
14.9%
4
CVE-2024-51587
14.9%
4
CVE-2024-51576
14.9%
4
CVE-2025-25269
14.9%
4
CVE-2023-26242
14.9%
4
CVE-2025-33124
14.9%
4
CVE-2026-627557.8 HIG
14.9%
4Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.11d
CVE-2026-628807.8 HIG
14.9%
4Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.11d
CVE-2024-50472
14.9%
4
CVE-2018-13811
14.9%
4
CVE-2021-29571
14.9%
4
CVE-2025-59398
14.9%
4
CVE-2026-25399
14.9%
4
CVE-2024-51583
14.9%
4
CVE-2025-57935
14.9%
4
CVE-2024-410227.0 HIG
14.9%
4In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq() The "instance" variable needs to be signed for the error handling to work.23d
CVE-2025-0272
14.9%
4
CVE-2024-51590
14.9%
4
CVE-2022-46706
14.9%
4
CVE-2026-417276.5 MED
14.9%
4Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.36d
CVE-2026-6936
14.9%
4
CVE-2026-763367.1 HIG
14.9%
4In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.6d
CVE-2024-51580
14.9%
4
CVE-2026-28833
14.9%
4
CVE-2024-9875
14.9%
4
CVE-2026-657867.8 HIG
14.9%
4Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.11d
CVE-2026-30791
14.9%
4
CVE-2026-627337.8 HIG
14.9%
4Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.11d
CVE-2023-52898
14.9%
4