Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,418
- Medium6,834
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-45824—35.6%
——11——CVE-2025-8573—35.6%
——11——CVE-2024-3317—35.6%
——11——CVE-2023-54328—35.6%
——11——CVE-2025-61246—35.6%
——11——CVE-2023-48296—35.6%
——11——CVE-2023-7046—35.6%
——11——CVE-2024-34343—35.6%
——11——CVE-2011-10038—35.6%
——11——CVE-2022-23169—35.6%
——11——CVE-2024-28978—35.6%
——11——CVE-2011-1842—35.6%
——11——CVE-2026-23892—35.6%
——11——CVE-2024-24832—35.6%
——11——CVE-2026-704228.1 HIG35.6%
——11Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.35dCVE-2026-936855.4 MED35.6%
——11A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.4dCVE-2017-3617—35.6%
——11——CVE-2023-46967—35.6%
——11——CVE-2026-30813—35.6%
——11——CVE-2026-492537.1 HIG35.6%
——11electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/zmodem.js, prepareReceiveFile() joins the filename to the user-selected save path, and in src/app/server/trzsz.js, getUniqueFilePath(), the openSaveFile() callback, and the savedFilePaths mapping construct destinations without sanitization. A malicious SSH server or remote shell can provide a filename containing traversal components such as ../escaped.txt or ../../.bashrc. When the victim accepts the transfer and selects a download directory, electerm can write outside that directory and overwrite files accessible to the desktop user, potentially changing sensitive configuration or impairing availability. This issue is fixed in version 3.11.11.16dCVE-2017-16673—35.6%
——11——CVE-2026-560887.1 HIG35.6%
——11Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.35dCVE-2023-31163—35.6%
——11——CVE-2018-1635—35.6%
——11——CVE-2026-575706.5 MED35.6%
——11backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling through attachManyRelation during CRUD create and update operations accepts submitted child primary keys without consistently restricting updates to records belonging to the current parent or permitted by the developer-defined relation scope. An authenticated low-privilege administrator who can edit a parent form exposing an affected multiple-relation field can cause unrelated child records to be reassigned, detached, nulled, or deleted across ownership or tenant boundaries. Exploitation requires related records that should not be attachable or removable by that administrator and the absence of additional application-level authorization around submitted relation values. This issue is distinct from earlier direct main-entity CRUD scoping fixes because it affects secondary models modified by relationship-saving logic. This issue is fixed in versions 6.8.15 and 7.0.47.11dCVE-2026-215797.5 HIG35.6%
——11This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.
This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability.
Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22
Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.14
See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).
This vulnerability was reported via our Atlassian (Internal) program.46dCVE-2026-74566.5 MED35.6%
——11The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all versions up to, and including, 3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's six configuration options — including the API key, connected Udimi user email, and tracking-script payload — effectively disconnecting the site from the configured Udimi account. The companion `ajax_connect()` handler is missing the same checks, allowing the same low-privilege attackers to overwrite those options with an attacker-supplied API key.44dCVE-2026-711768.8 HIG35.6%
——11Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.35dCVE-2026-24680—35.6%
——11——CVE-2025-11093—35.6%
——11——CVE-2026-27832—35.6%
——11——CVE-2023-31164—35.6%
——11——CVE-2026-33316—35.6%
——11——CVE-2024-41164—35.6%
——11——CVE-2026-35569—35.6%
——11——CVE-2025-21568—35.6%
——11——CVE-2021-20635—35.6%
——11——CVE-2023-42946—35.6%
——11——CVE-2026-41478—35.6%
——11——CVE-2026-44271—35.6%
——11——