Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-124847.8 HIG33.3%
——10A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the absence of an ambient safe mode state permits unsafe deserialization by default. This issue can lead to arbitrary code execution if untrusted Keras layer configurations are processed using this method. The vulnerability arises because the method does not enforce safe deserialization practices unless explicitly guarded by Keras safe mode.61dCVE-2026-732119.8 CRI33.3%
——10PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.13dCVE-2025-49128—33.3%
——10——CVE-2021-36852—33.3%
——10——CVE-2022-29587—33.3%
——10——CVE-2020-11626—33.3%
——10——CVE-2024-11539—33.3%
——10——CVE-2025-61958—33.3%
——10——CVE-2023-45670—33.3%
——10——CVE-2026-137798.1 HIG33.3%
——10Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)83dCVE-2023-24030—33.3%
——10——CVE-2018-14646—33.3%
——10——CVE-2025-12978—33.3%
——10——CVE-2025-50182—33.3%
——10——CVE-2026-26705—33.3%
——10——CVE-2001-0739—33.3%
——10——CVE-2022-25629—33.3%
——10——CVE-2025-54421—33.3%
——10——CVE-2010-4163—33.3%
——10——CVE-2005-2520—33.3%
——10——CVE-2025-1930—33.3%
——10——CVE-2023-23728—33.3%
——10——CVE-2026-48970—33.3%
——10——CVE-2024-56276—33.3%
——10——CVE-2023-24003—33.3%
——10——CVE-2026-15639—33.3%
——10An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.4dCVE-2026-628168.8 HIG33.3%
——10Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.37dCVE-2024-7318—33.3%
——10——CVE-2024-8258—33.3%
——10——CVE-2021-24837—33.3%
——10——CVE-2023-27319—33.3%
——10——CVE-2017-5857—33.3%
——10——CVE-2025-66263—33.3%
——10——CVE-2026-409647.5 HIG33.3%
——10Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token.
Affected versions:
- log-cache_release: all versions through v3.2.6 (inclusive); fixed in v3.2.7 or later
- CF Deployment: all versions through v55.?.0 (inclusive); fixed in v55.?.0 or later (bundles log-cache_release v3.2.7)62dCVE-2024-13316—33.3%
——10——CVE-2010-4162—33.3%
——10——CVE-2022-3763—33.3%
——10——CVE-2026-160935.4 MED33.3%
——10Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.6dCVE-2026-4723—33.3%
——10——CVE-2015-8345—33.3%
——10——