Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-855079.8 CRI32.7%
——10ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).8dCVE-2026-557439.6 CRI32.7%
——10The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.43dCVE-2023-49216—32.7%
——10——CVE-2025-30543—32.7%
——10——CVE-2015-3159—32.7%
——10——CVE-2026-22922—32.7%
——10——CVE-2024-1744—32.7%
——10——CVE-2025-52736.5 MED32.7%
——10Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.68dCVE-2026-55455—32.7%
——10——CVE-2018-5082—32.7%
——10——CVE-2025-45805—32.7%
——10——CVE-2023-41172—32.7%
——10——CVE-2024-9629—32.7%
——10——CVE-2025-31732—32.7%
——10——CVE-2022-4638—32.7%
——10——CVE-2018-6628—32.7%
——10——CVE-2023-41171—32.7%
——10——CVE-2026-29047—32.7%
——10——CVE-2026-540529.9 CRI32.7%
——10n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.66dCVE-2026-56215—32.7%
——10——CVE-2026-12473—32.7%
——10——CVE-2013-3234—32.7%
——10——CVE-2026-826307.3 HIG32.7%
——10A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/TestController.java of the component Transport Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.22dCVE-2026-855089.8 CRI32.7%
——10ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).14dCVE-2005-0204—32.7%
——10——CVE-2018-5242—32.7%
——10——CVE-2013-2548—32.7%
——10——CVE-2013-3228—32.7%
——10——CVE-2024-7737—32.7%
——10——CVE-2025-43211—32.7%
——10——CVE-2026-735655.3 MED32.7%
——10@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request's IncomingMessage in waiterMap and leave waitForWebSocket pending because ws.handleUpgrade emits no connection event. The aborted handshake therefore has no cleanup path, allowing an unauthenticated attacker to flood a public route, cause unbounded memory growth, and eventually make the service unavailable. This issue is fixed in version 2.0.10.12dCVE-2018-6205—32.7%
——10——CVE-2026-474198.3 HIG32.7%
——10PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agent_id}`) gate access on `require_workspace_member(workspace_id)` only, then resolve `agent_id` through `AgentService.get(agent_id)` which is a primary-key lookup with no workspace constraint. A user who is a member of any workspace `W1` can read, modify, or delete agents that belong to a different workspace `W2` by guessing or harvesting an agent UUID and calling `…/workspaces/W1/agents/<W2-agent-id>`. PraisonAI Platform version 0.1.4 patches the issue.62dCVE-2024-37630—32.7%
——10——CVE-2019-16638—32.7%
——10——CVE-2025-66560—32.7%
——10——CVE-2024-10940—32.7%
——10——CVE-2026-855049.8 CRI32.7%
——10FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.14dCVE-2026-39462—32.7%
——10——CVE-2026-864377.2 HIG32.7%
——10Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.14d