Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-2105—33.0%
——10——CVE-2026-940453.5 LOW33.0%
——10A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argument goodsName results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. ImageIO.read() is a format-agnostic read - it returns non-null for a polyglot PNG|<img onerror> payload, which is exactly why the "image-only" guard is bypassable; the attacker-controlled suffix + /upload/** static mapping is what turns the upload into persisted XSS rather than a one-shot. The project was informed of the problem early through an issue report but has not responded yet.1dCVE-2023-1903—33.0%
——10——CVE-2023-20074—33.0%
——10——CVE-2016-6833—33.0%
——10——CVE-2025-8187—33.0%
——10——CVE-2023-49446—33.0%
——10——CVE-2018-10955—33.0%
——10——CVE-2007-6417—33.0%
——10——CVE-2001-0496—33.0%
——10——CVE-2025-22540—33.0%
——10——CVE-2017-14300—33.0%
——10——CVE-2018-10977—33.0%
——10——CVE-2025-8930—33.0%
——10——CVE-2024-13844—33.0%
——10——CVE-2026-910914.3 MED33.0%
——10A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.7dCVE-2024-5232—33.0%
——10——CVE-2018-1650—33.0%
——10——CVE-2019-5543—33.0%
——10——CVE-2017-10748—33.0%
——10——CVE-2023-49383—33.0%
——10——CVE-2025-24664—33.0%
——10——CVE-2017-14291—33.0%
——10——CVE-2026-107006.5 MED33.0%
——10IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authentication or authorization checks, allowing unauthenticated remote attackers to retrieve image files associated with any flow by specifying a valid flow_id and file_name.Additionally, the /api/v1/files/download/{flow_id}/{file_name} endpoint requires authentication but fails to properly validate ownership of the requested resource. As a result, an authenticated user can access files belonging to other users by supplying arbitrary identifiers, leading to an authorization bypass (IDOR).Successful exploitation may result in unauthorized disclosure of sensitive data, including files stored in private flows. This issue breaks tenant isolation in multi-user deployments.49dCVE-2021-35078—33.0%
——10——CVE-2017-14690—33.0%
——10——CVE-2026-839468.2 HIG33.0%
——10Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.4dCVE-2023-45201—33.0%
——10——CVE-2017-14274—33.0%
——10——CVE-2024-12160—33.0%
——10——CVE-2024-20269—33.0%
——10——CVE-2026-46795—33.0%
——10——CVE-2024-11368—33.0%
——10——CVE-2007-0007—33.0%
——10——CVE-2017-10747—33.0%
——10——CVE-2017-14553—33.0%
——10——CVE-2017-14299—33.0%
——10——CVE-2025-26311—33.0%
——10——CVE-2025-14969—33.0%
——10——CVE-2017-14552—33.0%
——10——