Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11348—33.3%
——10——CVE-2025-48724—33.3%
——10——CVE-2026-195059.8 CRI33.3%
——10Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.19dCVE-2026-878595.3 MED33.3%
——10morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to a quoted field, such as the User-Agent or Referer header, can include a double quote to close that field early, so a log consumer that parses the log by field position reads attacker-supplied text as the following field. In the built-in formats this makes the recorded value differ from the value that was sent, and in custom formats that quote an attacker-controlled token before a server-controlled one it can forge values such as the response status. No newline is injected, so record separation stays intact. The issue is fixed in morgan 1.12.1, which escapes the double quote. Users should upgrade to morgan 1.12.1 or later.6dCVE-2025-23583—33.3%
——10——CVE-2025-14310—33.3%
——10——CVE-2024-56377—33.3%
——10——CVE-2024-9109—33.3%
——10——CVE-2026-23535—33.3%
——10——CVE-2026-289466.5 MED33.3%
——10A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.70dCVE-2026-122969.6 CRI33.3%
——10Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.69dCVE-2025-23601—33.3%
——10——CVE-2026-21582—33.3%
——10This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center.
This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user.
Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2
See the release notes (https://confluence.atlassian.com/crowd/crowd-release-notes-199094.html). You can download the latest version of Crowd Data Center from the download center (https://www.atlassian.com/software/crowd/download-archive).
This vulnerability was reported via our Penetration Testing program.33dCVE-2023-28851—33.3%
——10——CVE-2025-22772—33.3%
——10——CVE-2024-10468—33.3%
——10——CVE-2024-27900—33.3%
——10——CVE-2023-37272—33.3%
——10——CVE-2025-23589—33.3%
——10——CVE-2024-11701—33.3%
——10——CVE-2026-41507—33.3%
——10——CVE-2026-549817.8 HIG33.3%
——10Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.32dCVE-2024-359987.5 HIG33.3%
——10In the Linux kernel, the following vulnerability has been resolved:
smb3: fix lock ordering potential deadlock in cifs_sync_mid_result
Coverity spotted that the cifs_sync_mid_result function could deadlock
"Thread deadlock (ORDER_REVERSAL) lock_order: Calling spin_lock acquires
lock TCP_Server_Info.srv_lock while holding lock TCP_Server_Info.mid_lock"
Addresses-Coverity: 1590401 ("Thread deadlock (ORDER_REVERSAL)")49dCVE-2024-34727—33.3%
——10——CVE-2026-5285—33.3%
——10——CVE-2026-34571—33.3%
——10——CVE-2025-23503—33.3%
——10——CVE-2026-795699.8 CRI33.3%
——10Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.13dCVE-2017-4898—33.3%
——10——CVE-2022-4172—33.3%
——10——CVE-2010-4081—33.3%
——10——CVE-2026-171205.3 MED33.3%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer overflow.28dCVE-2024-56376—33.3%
——10——CVE-2005-1764—33.3%
——10——CVE-2025-52870—33.3%
——10——CVE-2021-4032—33.3%
——10——CVE-2023-30741—33.3%
——10——CVE-2024-5036—33.3%
——10——CVE-2026-174257.5 HIG33.3%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow.28dCVE-2024-37040—33.3%
——10——