Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,385
- High10,082
- Medium5,024
- Low463
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-1025—87.6%
——26——CVE-2021-24329—87.6%
——26——CVE-2019-7977—87.6%
——26——CVE-2014-1944—87.5%
——26——CVE-2016-9019—87.6%
——26——CVE-2017-0180—87.6%
——26——CVE-2017-15094—87.6%
——26——CVE-2026-628327.8 HIG87.5%
——26Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.12dCVE-2013-1026—87.6%
——26——CVE-2016-1559—87.6%
——26——CVE-2021-25949—87.6%
——26——CVE-2019-7635—87.6%
——26——CVE-2018-1296—87.6%
——26——CVE-2007-3161—87.6%
——26——CVE-2007-1011—87.6%
——26——CVE-2008-3805—87.6%
——26——CVE-2014-4033—87.6%
——26——CVE-2017-5563—87.6%
——26——CVE-2024-0566—87.6%
——26——CVE-2024-2024—87.6%
——26——CVE-2018-6608—87.6%
——26——CVE-2019-15051—87.6%
——26——CVE-2010-1524—87.6%
——26——CVE-2018-3938—87.6%
——26——CVE-2008-5696—87.6%
——26——CVE-2008-6659—87.6%
——26——CVE-2004-1953—87.6%
——26——CVE-2008-1958—87.6%
——26——CVE-2007-2273—87.6%
——26——CVE-2023-27638—87.6%
——26——CVE-2019-6471—87.6%
——26——CVE-2022-30158—87.6%
——26——CVE-2026-5357610.0 CRI87.6%
——26Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace}, /api/v1/{tenant}/executions/{namespace}/{id}, /api/v1/{tenant}/namespaces/{namespace}/kv/{key}). An anonymous caller picks the literal configs as the final segment, and the request bypasses Basic-Auth entirely. Because the bypass reaches the flow-create and execution-trigger routes, an unauthenticated caller creates a flow containing a Shell or Process task and runs it. The task executes as root inside the kestra container. The official docker-compose.yml mounts /var/run/docker.sock, so root in the container reaches the host Docker daemon. This vulnerability is fixed in 1.0.45 and 1.3.21.55dCVE-2018-19615—87.6%
——26——CVE-2019-7987—87.6%
——26——CVE-2007-3949—87.6%
——26——CVE-2009-0290—87.6%
——26——CVE-2006-6942—87.6%
——26——CVE-2023-2822—87.6%
——26——CVE-2017-7562—87.6%
——26——