Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,418
- Medium6,834
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-31836—35.5%
——11——CVE-2025-30097—35.5%
——11——CVE-2024-20737—35.5%
——11——CVE-2024-6565—35.5%
——11——CVE-2018-2845—35.5%
——11——CVE-2020-13409—35.5%
——11——CVE-2024-1445—35.5%
——11——CVE-2021-27117—35.5%
——11——CVE-2024-8155—35.5%
——11——CVE-2023-47622—35.5%
——11——CVE-2024-6499—35.5%
——11——CVE-2022-39403—35.5%
——11——CVE-2025-30828—35.5%
——11——CVE-2025-30113—35.5%
——11——CVE-2024-0792—35.5%
——11——CVE-2026-47346—35.5%
——11Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.65dCVE-2026-49292—35.5%
——11——CVE-2024-20956—35.5%
——11——CVE-2020-19886—35.5%
——11——CVE-2024-43282—35.5%
——11——CVE-2026-66724—35.5%
——11MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.057dCVE-2025-27445—35.5%
——11——CVE-2023-0566—35.5%
——11——CVE-2025-30115—35.5%
——11——CVE-2023-4960—35.5%
——11——CVE-2026-34744—35.5%
——11——CVE-2022-43363—35.5%
——11——CVE-2025-31765—35.5%
——11——CVE-2024-22377—35.5%
——11——CVE-2025-59452—35.5%
——11——CVE-2025-31810—35.5%
——11——CVE-2020-17901—35.5%
——11——CVE-2026-34579—35.5%
——11——CVE-2026-71192—35.5%
——11In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An
attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.16dCVE-2024-7415—35.5%
——11——CVE-2024-39323—35.5%
——11——CVE-2020-26922—35.5%
——11——CVE-2024-3974—35.5%
——11——CVE-2026-30662—35.5%
——11——CVE-2025-30096—35.5%
——11——