Vulnerabilities exploitable today
380,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,640
Distribution · last window
- Critical2,265
- High8,376
- Medium6,848
- Low754
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40733—35.2%
——11——CVE-2024-54546—35.2%
——11——CVE-2024-11514—35.2%
——11——CVE-2004-0341—35.2%
——11——CVE-2026-395558.1 HIG35.2%
——11Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
This issue affects Askka: from n/a through 1.3.1.65dCVE-2025-12925—35.2%
——11——CVE-2023-37445—35.2%
——11——CVE-2009-4150—35.2%
——11——CVE-2023-38623—35.2%
——11——CVE-2026-592858.1 HIG35.2%
——11Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.
Spring for GraphQL 2.0.0 - 2.0.423dCVE-2022-27961—35.2%
——11——CVE-2024-54221—35.2%
——11——CVE-2026-40760—35.2%
——11——CVE-2026-40759—35.2%
——11——CVE-2026-40757—35.2%
——11——CVE-2022-3657—35.2%
——11——CVE-2025-662807.2 HIG35.2%
——11An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3410 build 20260214 and later
QuTS hero h5.2.9.3410 build 20260214 and later
QuTS hero h5.3.4.3500 build 20260520 and later
QuTS hero h6.0.0.3397 build 20260206 and later64dCVE-2026-39443—35.2%
——11——CVE-2025-49188—35.2%
——11——CVE-2023-39234—35.2%
——11——CVE-2026-822726.5 MED35.2%
——11Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.2dCVE-2025-2357—35.2%
——11——CVE-2026-413725.8 MED35.2%
——11OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.63dCVE-2026-40736—35.2%
——11——CVE-2017-0708—35.2%
——11——CVE-2025-36521—35.2%
——11——CVE-2023-48248—35.2%
——11——CVE-2020-21386—35.2%
——11——CVE-2023-33228—35.2%
——11——CVE-2026-538276.5 MED35.2%
——11OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can intercept Gateway tokens and action payloads by providing malicious loopback targets through model-controlled action metadata.64dCVE-2025-49378—35.2%
——11——CVE-2026-27369—35.2%
——11——CVE-2007-4824—35.2%
——11——CVE-2023-36861—35.2%
——11——CVE-2026-856936.5 MED35.2%
——11Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests.21hCVE-2018-0428—35.2%
——11——CVE-2026-27096—35.2%
——11——CVE-2024-11518—35.2%
——11——CVE-2024-37166—35.2%
——11——CVE-2023-37419—35.2%
——11——