Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-39044—32.2%
——10——CVE-2022-2758—32.2%
——10——CVE-2025-514529.8 CRI32.2%
——10In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.79dCVE-2023-37063—32.2%
——10——CVE-2017-20196—32.2%
——10——CVE-2014-1950—32.2%
——10——CVE-2020-36743—32.2%
——10——CVE-2021-4414—32.2%
——10——CVE-2024-12714—32.2%
——10——CVE-2024-8756—32.2%
——10——CVE-2010-1439—32.2%
——10——CVE-2026-26416—32.2%
——10——CVE-2023-37067—32.2%
——10——CVE-2026-474147.6 HIG32.2%
——10PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .../labels/{label_id}`, `POST .../issues/{issue_id}/labels/{label_id}`, `DELETE .../issues/{issue_id}/labels/{label_id}`, `GET .../issues/{issue_id}/labels` — gate access on `require_workspace_member(workspace_id)` only and pass URL-supplied `label_id` and `issue_id` straight through to `LabelService` without verifying either belongs to the workspace. PraisonAI Platform version 0.1.4 patches the issue.60dCVE-2023-48202—32.2%
——10——CVE-2023-28376—32.2%
——10——CVE-2024-11106—32.2%
——10——CVE-2021-20224—32.2%
——10——CVE-2025-69052—32.2%
——10——CVE-2026-1190—32.2%
——10——CVE-2022-22346—32.2%
——10——CVE-2019-10165—32.2%
——10——CVE-2025-15078—32.2%
——10——CVE-2024-45512—32.2%
——10——CVE-2023-28168—32.2%
——10——CVE-2016-1851—32.2%
——10——CVE-2021-3899—32.2%
——10——CVE-2016-0202—32.2%
——10——CVE-2026-67286—32.2%
——10Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.26dCVE-2025-64435—32.2%
——10——CVE-2026-715187.5 HIG32.2%
——10Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.5dCVE-2024-56212—32.2%
——10——CVE-2026-18675—32.2%
——10The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.
The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token
A single request is a transient interruption; sustaining an outage requires repeated requests.21dCVE-2020-9451—32.2%
——10——CVE-2025-14959—32.2%
——10——CVE-2010-1641—32.2%
——10——CVE-2023-4779—32.2%
——10——CVE-2026-813935.5 MED32.2%
——10Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.4dCVE-2025-60548—32.2%
——10——CVE-2024-33596—32.2%
——10——