Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-35205—32.3%
——10——CVE-2014-8923—32.3%
——10——CVE-2026-24953—32.3%
——10——CVE-2026-165446.5 MED32.3%
——10A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe to these unmapped websocket event groups for any object ID and receive real-time stdout output from jobs belonging to organizations they have no access to. This is an incomplete remediation of CVE-2020-10698.61dCVE-2024-11094—32.3%
——10——CVE-2023-44077—32.3%
——10——CVE-2024-6540—32.3%
——10——CVE-2011-1126—32.3%
——10——CVE-2023-0024—32.3%
——10——CVE-2026-484926.5 MED32.3%
——10Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API token or elevated permissions are required. This exposes usernames, display names, employee numbers, and user IDs for every active account in the system if FMCS is not enabled, and within the company they belong to if FMCS is enabled. Version 8.6.1 contains a patch.73dCVE-2025-7543—32.3%
——10——CVE-2020-36744—32.3%
——10——CVE-2024-32827—32.3%
——10——CVE-2024-11942—32.3%
——10——CVE-2025-7904—32.3%
——10——CVE-2026-33735—32.3%
——10——CVE-2020-12356—32.3%
——10——CVE-2022-29779—32.3%
——10——CVE-2024-20507—32.3%
——10——CVE-2023-1904—32.3%
——10——CVE-2020-36741—32.3%
——10——CVE-2020-36750—32.3%
——10——CVE-2026-25326—32.3%
——10——CVE-2024-10126—32.3%
——10——CVE-2023-4893—32.3%
——10——CVE-2024-2608—32.3%
——10——CVE-2026-40197—32.3%
——10——CVE-2024-50826—32.3%
——10——CVE-2025-31487—32.3%
——10——CVE-2021-4416—32.3%
——10——CVE-2024-11351—32.3%
——10——CVE-2024-50828—32.3%
——10——CVE-2024-6470—32.3%
——10——CVE-2024-32803—32.3%
——10——CVE-2024-214057.0 HIG32.2%
——10Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability42dCVE-2026-551875.8 MED32.2%
——10Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard library classification helpers and does not block IPv6 transition mechanisms or prefixes such as NAT64, 6to4, IPv4-compatible IPv6, ISATAP, fec0::/10, and 2001:db8::/32. An attacker who can deliver email and invoke POST /api/v1/message/{ID}/link-check can coerce the Link Check API's safeDialContext path into dialing internal destinations and can use status-code and error feedback to map internal service reachability, including cloud metadata endpoints. This issue is fixed in version 1.30.2.70dCVE-2026-2471—32.2%
——10——CVE-2026-813915.5 MED32.2%
——10Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.4dCVE-2010-1641—32.2%
——10——CVE-2026-18675—32.2%
——10The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.
The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token
A single request is a transient interruption; sustaining an outage requires repeated requests.21d