Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,412
- High8,681
- Medium6,983
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-7163—34.2%
——10——CVE-2024-22279—34.2%
——10——CVE-2024-11786—34.2%
——10——CVE-2024-46874—34.2%
——10——CVE-2025-62466—34.2%
——10——CVE-2026-841088.1 HIG34.2%
——10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.18hCVE-2026-41502—34.2%
——10——CVE-2026-477326.5 MED34.2%
——10Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0.69dCVE-2026-813905.5 MED34.2%
——10Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.6dCVE-2026-840829.8 CRI34.2%
——10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.10hCVE-2026-737128.1 HIG34.2%
——10A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.20dCVE-2025-60713—34.2%
——10——CVE-2022-28887—34.2%
——10——CVE-2014-6184—34.2%
——10——CVE-2026-925768.6 HIG34.2%
——10HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.7dCVE-2023-24031—34.2%
——10——CVE-2017-5688—34.2%
——10——CVE-2025-48742—34.2%
——10——CVE-2015-0530—34.2%
——10——CVE-2024-7132—34.2%
——10——CVE-2026-534476.5 MED34.2%
——10Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.69dCVE-2024-5143—34.2%
——10——CVE-2025-55233—34.2%
——10——CVE-2026-340447.7 HIG34.2%
——10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the current team, allowing an authenticated user to access logs for applications owned by other teams by supplying a victim resource UUID. This issue is fixed in version 4.0.0-beta.466.76dCVE-2018-18913—34.2%
——10——CVE-2022-1204—34.2%
——10——CVE-2014-2673—34.2%
——10——CVE-2024-11147—34.2%
——10——CVE-2025-12808—34.2%
——10——CVE-2025-22251—34.2%
——10——CVE-2017-18648—34.2%
——10——CVE-2026-579496.5 MED34.2%
——10ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.71dCVE-2026-2109—34.2%
——10——CVE-2026-940839.4 CRI34.2%
——10Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.18hCVE-2026-59853—34.2%
——10——CVE-2026-56695—34.2%
——10——CVE-2026-940849.4 CRI34.2%
——10Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.18hCVE-2024-12982—34.2%
——10——CVE-2024-47832—34.2%
——10——CVE-2017-6007—34.2%
——10——