Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-10468—33.3%
——10——CVE-2024-27900—33.3%
——10——CVE-2025-22772—33.3%
——10——CVE-2023-30946—33.3%
——10——CVE-2025-23578—33.3%
——10——CVE-2016-5749—33.3%
——10——CVE-2023-23539—33.3%
——10——CVE-2023-47042—33.3%
——10——CVE-2026-21582—33.3%
——10This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.
This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.
Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2
See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive).
This vulnerability was reported via our Penetration Testing program.33dCVE-2025-52044—33.3%
——10——CVE-2016-5870—33.3%
——10——CVE-2023-28851—33.3%
——10——CVE-2024-24703—33.3%
——10——CVE-2024-11535—33.3%
——10——CVE-2024-47530—33.3%
——10——CVE-2026-122959.6 CRI33.3%
——10Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.69dCVE-2019-2807—33.3%
——10——CVE-2016-6490—33.3%
——10——CVE-2025-23610—33.3%
——10——CVE-2017-14014—33.3%
——10——CVE-2024-7085—33.3%
——10——CVE-2024-11556—33.3%
——10——CVE-2022-33202—33.3%
——10——CVE-2025-23606—33.3%
——10——CVE-2025-23592—33.3%
——10——CVE-2025-23611—33.3%
——10——CVE-2025-23604—33.3%
——10——CVE-2026-856246.5 MED33.3%
——10Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags.12dCVE-2026-38812—33.3%
——10——CVE-2026-289466.5 MED33.3%
——10A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.70dCVE-2024-11544—33.3%
——10——CVE-2025-11538—33.3%
——10——CVE-2026-436248.2 HIG33.3%
——10F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized user-supplied project names directly to os.path.join() without validating the resulting path stays within the intended base directory. Attackers can supply absolute path arguments such as /tmp/EVIL to override the base directory entirely and create arbitrary directories with attacker-controlled JSON content at any filesystem path writable by the server process.63dCVE-2023-31168—33.3%
——10——CVE-2024-11554—33.3%
——10——CVE-2024-11549—33.3%
——10——CVE-2024-11526—33.3%
——10——CVE-2010-4081—33.3%
——10——CVE-2005-1764—33.3%
——10——CVE-2026-171205.3 MED33.3%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer overflow.28d