Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-664659.8 CRI33.1%
——10Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.39dCVE-2025-32161—33.1%
——10——CVE-2024-50565—33.1%
——10——CVE-2026-43584—33.1%
——10——CVE-2024-29126—33.1%
——10——CVE-2025-10587—33.1%
——10——CVE-2004-0881—33.1%
——10——CVE-2023-23553—33.1%
——10——CVE-2023-32275—33.1%
——10——CVE-2025-15434—33.1%
——10——CVE-2025-32193—33.1%
——10——CVE-2021-47844—33.1%
——10——CVE-2025-32197—33.1%
——10——CVE-2026-33991—33.1%
——10——CVE-2009-0149—33.1%
——10——CVE-2000-1137—33.1%
——10——CVE-2025-32169—33.1%
——10——CVE-2025-32192—33.1%
——10——CVE-2026-44895—33.1%
——10GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint that is backed by the operator's GITLAB_PERSONAL_ACCESS_TOKEN without any inbound credential check, then advertises itself to every cross-origin browser context via the wildcard CORS header. The httpServer.listen(port) call at line 97 also passes no host argument, so the bind defaults to 0.0.0.0 and exposes the auth-less surface on every interface. This vulnerability is fixed in 0.6.0.61dCVE-2023-29424—33.1%
——10——CVE-2025-32186—33.1%
——10——CVE-2020-6992—33.1%
——10——CVE-2025-12593—33.1%
——10——CVE-2024-21114—33.1%
——10——CVE-2025-32170—33.1%
——10——CVE-2016-8472—33.1%
——10——CVE-2024-7045—33.1%
——10Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.40dCVE-2025-32162—33.1%
——10——CVE-2025-701499.8 CRI33.1%
——10CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.14dCVE-2026-444849.8 CRI33.1%
——10PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.70dCVE-2008-4554—33.1%
——10——CVE-2026-664539.8 CRI33.1%
——10Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.39dCVE-2003-0440—33.1%
——10——CVE-2024-10483—33.1%
——10——CVE-2021-36189—33.1%
——10——CVE-2018-5497—33.1%
——10——CVE-2026-31223—33.1%
——10——CVE-2025-32175—33.1%
——10——CVE-2025-32190—33.1%
——10——CVE-2008-3929—33.1%
——10——