Vulnerabilities exploitable today
379,234in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,394
- High8,623
- Medium7,065
- Low795
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-10953—34.7%
——10——CVE-2026-789388.8 HIG34.7%
——10Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)27dCVE-2017-18241—34.7%
——10——CVE-2008-5743—34.7%
——10——CVE-2025-54246—34.7%
——10——CVE-2024-41238—34.7%
——10——CVE-2023-34433—34.7%
——10——CVE-2024-47412—34.7%
——10——CVE-2024-8642—34.7%
——10——CVE-2021-25699—34.7%
——10——CVE-2023-3729—34.7%
——10——CVE-2024-9668—34.7%
——10——CVE-2026-328578.6 HIG34.7%
——10Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy validation is applied only to the initial user-supplied URL and not to subsequent redirect destinations. Attackers can supply an externally valid URL that passes validation and returns an HTTP redirect to an internal or restricted resource, allowing the browser to follow the redirect and fetch the final destination without revalidation, thereby gaining access to internal network services and sensitive endpoints. This issue is distinct from CVE-2024-56800, which describes redirect-based SSRF generally. This vulnerability specifically arises from a post-redirect enforcement gap in implemented SSRF protections, where validation is applied only to the initial request and not to the final redirected destination.71dCVE-2025-66115—34.7%
——10——CVE-2024-47413—34.7%
——10——CVE-2009-4004—34.7%
——10——CVE-2007-3513—34.7%
——10——CVE-2023-34286—34.7%
——10——CVE-2021-47797—34.7%
——10——CVE-2020-10002—34.7%
——10——CVE-2018-10975—34.7%
——10——CVE-2008-4968—34.7%
——10——CVE-2026-256996.1 MED34.7%
——10Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.63dCVE-2025-3470—34.7%
——10——CVE-2004-0229—34.7%
——10——CVE-2004-1398—34.7%
——10——CVE-2008-4946—34.7%
——10——CVE-2026-256886.1 MED34.7%
——10Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.63dCVE-2026-147824.9 MED34.7%
——10The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with wpamelia-manager role, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.69dCVE-2026-8379—34.7%
——10——CVE-2018-10974—34.7%
——10——CVE-2023-38087—34.7%
——10——CVE-2025-48722—34.7%
——10——CVE-2023-480567.5 HIG34.7%
——10PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.77dCVE-2024-1870—34.7%
——10——CVE-2023-32820—34.7%
——10——CVE-2022-22447—34.7%
——10——CVE-2024-52788—34.7%
——10——CVE-2023-49771—34.7%
——10——CVE-2022-36313—34.7%
——10——