Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13141—33.4%
——10——CVE-2025-28025—33.4%
——10——CVE-2026-61556—33.3%
——10LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an infinite loop when an input string contains <, includes at least one preceding character, and has no later >. In strip_html, the search for the next opener advances lt while the loop index remains unchanged when the closer search returns -1, and the equality-only stall guard does not exit because the loop index is less than lt. Reprocessing the same state indefinitely blocks template rendering and can cause denial of service with an input as short as a<. This issue is fixed in version 10.27.1.13dCVE-2004-0496—33.3%
——10——CVE-2024-46947—33.3%
——10——CVE-2005-4443—33.3%
——10——CVE-2026-905216.3 MED33.3%
——10A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.8dCVE-2006-0591—33.3%
——10——CVE-2004-0974—33.3%
——10——CVE-2026-856108.8 HIG33.3%
——10OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins and execute operating system commands with the privileges of the API process, bypassing organization authorization boundaries.12dCVE-2018-6249—33.3%
——10——CVE-2023-28820—33.3%
——10——CVE-2022-43323—33.3%
——10——CVE-2026-473737.5 HIG33.3%
——10Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.61dCVE-2008-1615—33.3%
——10——CVE-2022-4653—33.3%
——10——CVE-2026-64963—33.3%
——10A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of information about the filesystem structure.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.25dCVE-2025-0175—33.3%
——10——CVE-2026-41589—33.3%
——10——CVE-2024-12783—33.3%
——10——CVE-2024-5901—33.3%
——10——CVE-2023-35948—33.3%
——10——CVE-2016-9685—33.3%
——10——CVE-2025-1542—33.3%
——10——CVE-2025-60195—33.3%
——10——CVE-2026-199974.7 MED33.3%
——10A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."33dCVE-2023-23686—33.3%
——10——CVE-2024-34371—33.3%
——10——CVE-2024-6334—33.3%
——10——CVE-2024-43580—33.3%
——10——CVE-2026-33610—33.3%
——10——CVE-2022-41291—33.3%
——10——CVE-2022-4669—33.3%
——10——CVE-2023-23864—33.3%
——10——CVE-2022-45358—33.3%
——10——CVE-2022-45814—33.3%
——10——CVE-2008-2235—33.3%
——10——CVE-2026-44736—33.3%
——10——CVE-2025-538288.5 HIG33.3%
——10SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed version.77dCVE-2024-4106—33.3%
——10——