Vulnerabilities exploitable today
379,306in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,374
- High8,531
- Medium7,087
- Low799
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-36223—35.0%
——10——CVE-2022-45363—35.0%
——10——CVE-2025-32393—35.0%
——10——CVE-2026-171018.3 HIG35.0%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.36dCVE-2026-84361—35.0%
——10Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.21dCVE-2020-7260—35.0%
——10——CVE-2022-21819—35.0%
——10——CVE-2026-751656.5 MED35.0%
——10An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.15dCVE-2025-20254—34.9%
——10——CVE-2025-13915.4 MED35.0%
——10A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on these claims for authorization, it may incorrectly assume a user belongs to an organization they are not a member of, potentially granting unauthorized access or privileges.3dCVE-2024-11083—35.0%
——10——CVE-2026-44427—35.0%
——10——CVE-2023-3762—35.0%
——10——CVE-2026-27809—35.0%
——10——CVE-2022-42418—35.0%
——10——CVE-2026-72127.3 HIG35.0%
——10A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.62dCVE-2026-0885—35.0%
——10——CVE-2023-5676—35.0%
——10——CVE-2018-6260—35.0%
——10——CVE-2024-22194—35.0%
——10——CVE-2018-12176—35.0%
——10——CVE-2022-41880—35.0%
——10——CVE-2021-31609—35.0%
——10——CVE-2024-5322—35.0%
——10——CVE-2026-667949.3 CRI35.0%
——10A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.16dCVE-2022-1831—35.0%
——10——CVE-2023-44383—35.0%
——10——CVE-2017-10187—35.0%
——10——CVE-2023-45807—35.0%
——10——CVE-2019-20512—35.0%
——10——CVE-2024-5639—35.0%
——10——CVE-2026-33322—35.0%
——10——CVE-2024-47212—35.0%
——10——CVE-2026-814917.3 HIG35.0%
——10A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.27dCVE-2005-0207—35.0%
——10——CVE-2024-23293—35.0%
——10——CVE-2020-37097—35.0%
——10——CVE-2004-1138—35.0%
——10——CVE-2026-88587.5 HIG35.0%
——10IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.77dCVE-2026-28453—34.9%
——10——