Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,541
- Medium7,074
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15315—34.9%
——10——CVE-2022-41500—34.9%
——10——CVE-2023-45768—34.9%
——10——CVE-2023-45767—34.9%
——10——CVE-2024-1044—34.9%
——10——CVE-2024-56525—34.9%
——10——CVE-2022-3714—34.9%
——10——CVE-2024-8154—34.9%
——10——CVE-2024-54316—34.9%
——10——CVE-2026-755897.5 HIG34.9%
——10Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify.
Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings.
A client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret.29dCVE-2023-48410—34.9%
——10——CVE-2026-778147.5 HIG34.9%
——10is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore satisfies the comparison, so where /data/images is allowed a request for /data/images_private/secret.txt is treated as trusted and served by FileResponse, disclosing files the confinement was meant to exclude. Whether the check applies depends on get_enable_access_control in scripts/iib/tool.py: it returns true when IIB_ACCESS_CONTROL is set to enable, false when set to disable, and otherwise true when the host Stable Diffusion WebUI was started with share, ngrok, listen or server_name, falling back to false. Confinement is therefore active in the network-exposed WebUI deployments that rely on it, while a standalone run with no such option serves every readable file regardless of this flaw. The fix compares against parent_path joined with os.sep.34dCVE-2026-21726—34.9%
——10——CVE-2026-584516.5 MED34.9%
——10Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation by appending sequences such as traversal segments after the matching prefix, causing file_get_contents() to read sensitive files whose contents are then exfiltrated as MIME parts in outgoing email; unauthenticated exploitation is also achievable via CSRF against an active authenticated session.72dCVE-2019-19523—34.9%
——10——CVE-2023-46068—34.9%
——10——CVE-2025-0431—34.9%
——10——CVE-2026-821009.6 CRI34.9%
——10IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.8dCVE-2023-46613—34.9%
——10——CVE-2026-771098.6 HIG34.9%
——10Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.15dCVE-2022-22767—34.9%
——10——CVE-2023-24975—34.9%
——10——CVE-2024-39874—34.9%
——10——CVE-2019-25525—34.9%
——10——CVE-2022-23182—34.9%
——10——CVE-2025-69035—34.9%
——10——CVE-2026-43341—34.9%
——10——CVE-2023-46069—34.9%
——10——CVE-2023-45640—34.9%
——10——CVE-2024-36046—34.9%
——10——CVE-2025-51532—34.9%
——10——CVE-2026-584204.4 MED34.9%
——10Local File Inclusion via file:// URI in Migration Restore29dCVE-2024-44038—34.9%
——10——CVE-2024-30278—34.9%
——10——CVE-2025-7773—34.9%
——10——CVE-2023-51067—34.9%
——10——CVE-2024-5769—34.9%
——10——CVE-2023-28673—34.9%
——10——CVE-2024-12041—34.9%
——10——CVE-2026-713496.8 MED34.9%
——10Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.2d