Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-39494—32.8%
——10——CVE-2026-484366.5 MED32.8%
——10CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.26dCVE-2026-44956—32.8%
——10——CVE-2020-10369—32.8%
——10——CVE-2006-1836—32.8%
——10——CVE-2026-5997110.0 CRI32.8%
——10MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and /messages/ have no authentication and the service binds to 0.0.0.0 by default. A network attacker can directly reach execute_sql, or can use DNS rebinding to make a victim's browser relay same-origin requests to a locally bound service, and supply a query that reaches cursor.execute(query). This allows unauthenticated disclosure and modification of the configured database; when the MySQL account has FILE privileges, the same access can read or write server files and may enable code execution. The default stdio transport is not affected. This issue is fixed in 0.4.2.7dCVE-2025-14741—32.8%
——10——CVE-2025-2162—32.8%
——10——CVE-2020-36995—32.8%
——10——CVE-2026-8728—32.8%
——10——CVE-2026-22475—32.8%
——10——CVE-2025-43762—32.8%
——10——CVE-2012-6336—32.8%
——10——CVE-2026-109568.8 HIG32.8%
——10Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)62dCVE-2026-31282—32.8%
——10——CVE-2026-289026.5 MED32.8%
——10The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.70dCVE-2023-36637—32.8%
——10——CVE-2023-0766—32.8%
——10——CVE-2026-520217.5 HIG32.8%
——10An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components.19dCVE-2024-0434—32.8%
——10——CVE-2023-1570—32.8%
——10——CVE-2025-9608—32.8%
——10——CVE-2012-2679—32.8%
——10——CVE-2026-409209.8 CRI32.8%
——10Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.36dCVE-2015-4325—32.8%
——10——CVE-2011-1548—32.8%
——10——CVE-2025-22408—32.8%
——10——CVE-2026-44960—32.8%
——10——CVE-2023-26516—32.8%
——10——CVE-2026-676134.9 MED32.8%
——10CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request body, which is passed directly to open() in cloudManager.py without validation or allowlisting, enabling traversal to any file readable by the root-privileged CyberPanel process including credential files, SSL and SSH private keys, and JWT secret files.14dCVE-2022-43708—32.8%
——10——CVE-2025-10910—32.8%
——10——CVE-2023-0710—32.8%
——10——CVE-2018-15368—32.8%
——10——CVE-2024-13209—32.8%
——10——CVE-2025-22512—32.8%
——10——CVE-2023-6953—32.8%
——10——CVE-2026-732285.3 MED32.8%
——10Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.11dCVE-2019-14358—32.8%
——10——CVE-2011-2498—32.8%
——10——