PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
CVE Watch379,124 in full archive

Vulnerabilities exploitable today

379,124in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654

Distribution · last window

  • Critical
    2,385
  • High
    8,590
  • Medium
    7,035
  • Low
    793
Filters
Filters

Window

Severity

Flags

Vulnerabilities379,041–379,080 · 379,124
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-23583
0Rejected reason: Withdrawn by requester.22d
CVE-2020-37264
0Rejected reason: This CVE ID has been rejected.43d
CVE-2026-17519
0Rejected reason: This is rejected.44d
CVE-2026-51236
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54d
CVE-2026-51234
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54d
CVE-2026-198546.1 MED
0.0%
0When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.23d
CVE-2026-76161
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.18d
CVE-2023-32640
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2025-36916
0.0%
0
CVE-2023-41370
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2023-28719
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2026-64841
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.24d
CVE-2023-45848
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2026-9052
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.33d
CVE-2026-85789
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.7d
CVE-2023-36852
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2023-54371
0Rejected reason: This CVE ID has been rejected.43d
CVE-2026-69125
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a duplicate of CVE-2026-67321. Notes: All CVE users should reference CVE-2026-67321 instead of this candidate.48d
CVE-2023-49720
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2021-48002
0Rejected reason: This CVE ID has been rejected.27d
CVE-2026-51285
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54d
CVE-2026-28534
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.44d
CVE-2026-35027
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.44d
CVE-2026-51249
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54d
CVE-2023-42432
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2025-2795
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.33d
CVE-2026-14286
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.75d
CVE-2026-10772
0Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration attribute rather than the Characteristic Value attribute, so the encryption/authentication requirements configured on the value are not enforced. Both identifiers describe the same root cause in subsys/bluetooth/host/gatt.c, fixed by the same commit (c3386f92fe81bd10dc23e6a115e6a80a7d863546). Use CVE-2026-2411 instead.53d
CVE-2026-28184
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.41d
CVE-2026-240907.1 HIG
0.0%
0Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.63d
CVE-2023-27299
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2026-285907.8 HIG
0.0%
0In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.8d
CVE-2023-49116
0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d
CVE-2026-51253
0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54d
CVE-2026-967559.8 CRI
0orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.3h
CVE-2026-967758.8 HIG
0MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.3h
CVE-2023-21178
0.0%
0
CVE-2026-968048.8 HIG
0MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.4h
CVE-2026-714614.3 MED
0HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.2h
CVE-2026-760897.7 HIG
0Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.2h