Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,418
- Medium6,834
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-1202—35.5%
——11——CVE-2022-4091—35.5%
——11——CVE-2023-25836—35.5%
——11——CVE-2026-815398.8 HIG35.5%
——11IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.1dCVE-2026-75215.5 MED35.5%
——11Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory from the server via the remove file endpoint.. Mattermost Advisory ID: MMSA-2026-0066658dCVE-2019-20677—35.5%
——11——CVE-2026-132488.8 HIG35.5%
——11An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal command interpreter.
An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.1dCVE-2024-7411—35.5%
——11——CVE-2020-11781—35.5%
——11——CVE-2022-43418—35.5%
——11——CVE-2024-5649—35.5%
——11——CVE-2024-7015—35.5%
——11——CVE-2026-485506.1 MED35.5%
——11Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary JavaScript in the victim's browser.17dCVE-2022-41958—35.5%
——11——CVE-2019-7874—35.5%
——11——CVE-2023-25169—35.5%
——11——CVE-2024-43252—35.5%
——11——CVE-2017-0786—35.5%
——11——CVE-2019-25401—35.5%
——11——CVE-2025-31782—35.5%
——11——CVE-2026-43924—35.5%
——11FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs before storing or issuing redirects. This allows arbitrary external URLs to be configured as redirect targets, creating an open redirect vulnerability exploitable for phishing attacks. Users following a legitimate FOSSBilling URL can be silently redirected to an attacker-controlled external site. The redirect is issued as a 301 (Moved Permanently) response, which browsers cache persistently, amplifying the impact. Exploitation requires administrator privileges to create or modify redirect entries, limiting practical attack scenarios to multi-admin environments or compromised admin accounts. Version 0.8.0 fixes the issue. Some workarounds are available. Restrict admin access to the Redirect module to trusted administrators only and/or audit existing redirect entries in the database (the `extension_meta` table with `extension = 'mod_redirect'`) for any unexpected or external target URLs.65dCVE-2023-52322—35.5%
——11——CVE-2022-41208—35.5%
——11——CVE-2026-199276.3 MED35.5%
——11A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 is sufficient to resolve this issue. The patch is named a599007325efe780a21b3537ecce3ca25635c926. It is suggested to upgrade the affected component.36dCVE-2025-66236—35.5%
——11——CVE-2022-45157—35.5%
——11——CVE-2008-0563—35.5%
——11——CVE-2023-47801—35.5%
——11——CVE-2020-11784—35.5%
——11——CVE-2024-32758—35.5%
——11——CVE-2025-31816—35.5%
——11——CVE-2020-21686—35.5%
——11——CVE-2020-10729—35.5%
——11——CVE-2019-20678—35.5%
——11——CVE-2024-23136—35.5%
——11——CVE-2021-40555—35.5%
——11——CVE-2025-30853—35.5%
——11——CVE-2025-141799.8 CRI35.5%
——11In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.62dCVE-2020-7810—35.5%
——11——CVE-2025-13630—35.5%
——11——