Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,354
- High8,500
- Medium6,881
- Low783
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-28023—34.4%
——10——CVE-2026-28022—34.4%
——10——CVE-2026-91039—34.4%
——10Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different connection.
The strategy is meant to keep each connection in its own identity namespace by writing every UserIdentity row's strategy field as "<name>/<connection_id>", but that namespacing never takes effect. __connection_id__ is populated only on the ephemeral runtime struct built per request in dynamic_oidc/plug.ex, and DynamicOidc.IdentityChange.change/3 re-fetches the strategy from the compile-time DSL through Info.strategy_for_action, yielding the persisted struct whose __connection_id__ is its defstruct default of nil. OAuth2.identity_strategy_name/1 therefore falls back to the bare strategy name for both the identity write and the reads in oauth2/user_resolver.ex and oauth2/sign_in_preparation.ex. Since the identity resource's unique key is (uid, strategy), one row exists per sub across every connection, and the identity-match branch runs before any email check. Neither strategy handles iss, so nothing else distinguishes the issuers: OpenID Connect Core section 5.7 makes sub unique only within an issuer, so two connections numbering subjects independently share one subject space.
This issue affects ash_authentication: from 5.0.0-rc.10 before 5.0.0-rc.14.5dCVE-2026-734987.7 HIG34.4%
——10MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling validate_safe_path. An authenticated MCP client can read any file accessible to the server process and exfiltrate it to Confluence as an attachment. If an AI agent can be induced to call the tool through untrusted content, the same flaw can disclose server environment variables such as CONFLUENCE_API_TOKEN and other credentials. This issue is fixed in version 0.22.0.5dCVE-2004-1346—34.4%
——10——CVE-2024-7554—34.4%
——10——CVE-2026-679609.8 CRI34.4%
——10An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components23dCVE-1999-1323—34.4%
——10——CVE-2026-27326—34.4%
——10——CVE-2026-663916.5 MED34.4%
——10Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0.
Users are recommended to upgrade to version 10.10.0, which fixes the issue.49dCVE-2014-2678—34.4%
——10——CVE-2026-28066—34.4%
——10——CVE-2026-215507.5 HIG34.4%
——10In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed26dCVE-2024-7762—34.4%
——10——CVE-2024-45056—34.4%
——10——CVE-2026-193517.3 HIG34.4%
——10A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.41dCVE-2025-59482—34.4%
——10——CVE-2024-21152—34.4%
——10——CVE-2026-27993—34.4%
——10——CVE-2023-47867—34.4%
——10——CVE-2026-843975.4 MED34.4%
——10Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.7dCVE-2023-1067—34.4%
——10——CVE-2026-28028—34.4%
——10——CVE-2022-3015—34.4%
——10——CVE-2025-38676—34.4%
——10——CVE-2011-2327—34.4%
——10——CVE-2026-27336—34.4%
——10——CVE-2026-749369.8 CRI34.4%
——10Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.33dCVE-2023-2327—34.4%
——10——CVE-2026-28059—34.4%
——10——CVE-2003-0932—34.4%
——10——CVE-2023-43876—34.4%
——10——CVE-2026-28092—34.4%
——10——CVE-2023-26266—34.4%
——10——CVE-2026-27339—34.4%
——10——CVE-2025-5253—34.4%
——10——CVE-2025-32018—34.4%
——10——CVE-2026-22477—34.4%
——10——CVE-2026-28056—34.4%
——10——CVE-2017-1000147—34.4%
——10——