Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-50809—33.0%
——10——CVE-2024-21153—33.0%
——10——CVE-2025-8264—33.0%
——10——CVE-2015-2672—33.0%
——10——CVE-2015-3436—33.0%
——10——CVE-2022-20796—33.0%
——10——CVE-2025-31998—33.0%
——10——CVE-2025-5241—33.0%
——10——CVE-2025-60566—33.0%
——10——CVE-2024-2189—33.0%
——10——CVE-2026-905797.3 HIG33.0%
——10A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.8dCVE-2023-42106—33.0%
——10——CVE-2026-906207.3 HIG33.0%
——10A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.8dCVE-2023-42110—33.0%
——10——CVE-2023-42107—33.0%
——10——CVE-2023-42113—33.0%
——10——CVE-2026-1556—33.0%
——10——CVE-2026-300457.5 HIG33.0%
——10An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.22dCVE-2025-52895—33.0%
——10——CVE-2026-393108.6 HIG33.0%
——10Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposing endpoints such as /api/clipper/notes to the network with no password, API token, or CSRF protection. An attacker on a shared network (for example, a corporate LAN or public Wi-Fi) can scan for open high-range ports using a tool like nmap, since Trilium often binds to ports such as 37840. Once a candidate port is found, an unauthenticated request to the Clipper handshake endpoint, which also bypasses authentication, confirms a Trilium instance by returning the application name and protocol version. This facilitates unauthorized data access, phishing, and local system compromise. The issue has been fixed in version 0.102.2.61dCVE-2026-54311—33.0%
——10——CVE-2026-480756.5 MED33.0%
——10OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid `tunnelId` and any valid `emailHash` (the two need not belong to the same tunnel) results in an inserted appointment with `status = "CONFIRMED"`, attacker-controlled ciphertext fields, attacker-controlled date and duration, and an attacker-chosen agent. The endpoint validates only that some tunnel exists with the given `emailHash`, then writes the appointment using the attacker-supplied `tunnelId` directly. The `emailHash` lookup is effectively an existence check on the tenant; it does not authenticate the caller as the owner of the supplied `tunnelId`. Combined with the absence of any session, Authorization header, booking access token, or PoW, this makes the endpoint accept arbitrary appointment writes into arbitrary tunnels. By contrast, the sibling endpoint `create-new-client` (used to bootstrap a brand-new client tunnel) requires a Bearer bootstrap booking access token issued by the bootstrap-challenge / bootstrap-verify flow. The `add-to-tunnel` endpoint, intended for return-clients booking additional appointments, has no equivalent gate. The application's own middleware confirms this is intentional: `add-to-tunnel` is explicitly listed in the apiAuthHandle public-route allowlist alongside the bootstrap and challenge endpoints (which legitimately have no session). Version 1.0.5 fixes the issue.14dCVE-2024-54150—33.0%
——10——CVE-2021-35540—33.0%
——10——CVE-2007-3107—33.0%
——10——CVE-2025-63695—33.0%
——10——CVE-2020-24848—33.0%
——10——CVE-2020-10007—33.0%
——10——CVE-2026-728668.8 HIG33.0%
——10Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize access to the requested server. An authenticated user can connect to /terminal?serverId=local, select the special serverId=local branch, and obtain an interactive terminal on the Dokploy host without an organization role or server-access check. This issue is fixed in version 0.29.13.14dCVE-2026-92078.8 HIG33.0%
——10Tanium addressed an unauthorized code execution vulnerability in Connect.61dCVE-2024-36801—33.0%
——10——CVE-2026-22794—33.0%
——10——CVE-2023-5184—33.0%
——10——CVE-2024-1275—33.0%
——10——CVE-2021-37159—33.0%
——10——CVE-2024-45480—33.0%
——10——CVE-2026-862147.3 HIG33.0%
——10A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.14dCVE-2024-27813—33.0%
——10——CVE-2024-4333—33.0%
——10——CVE-2025-45471—33.0%
——10——