Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-35916—32.2%
——10——CVE-2022-42843—32.2%
——10——CVE-2016-5328—32.2%
——10——CVE-2026-80928.1 HIG32.2%
——10Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.55dCVE-2022-45542—32.2%
——10——CVE-2018-1564—32.2%
——10——CVE-2026-790386.5 MED32.2%
——10Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)26dCVE-2021-21599—32.2%
——10——CVE-2024-8586—32.2%
——10——CVE-2016-6310—32.2%
——10——CVE-2018-20941—32.2%
——10——CVE-2026-162176.3 MED32.2%
——10A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.63dCVE-2026-40346—32.2%
——10——CVE-2020-29571—32.2%
——10——CVE-2023-36093—32.2%
——10——CVE-2026-863215.3 MED32.2%
——10A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.13dCVE-2016-8659—32.2%
——10——CVE-2026-37712—32.2%
——10——CVE-2026-27406—32.2%
——10——CVE-2024-52505—32.2%
——10——CVE-2014-9903—32.2%
——10——CVE-2025-66274—32.2%
——10——CVE-2025-53644—32.2%
——10——CVE-2026-151916.3 MED32.2%
——10A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.19dCVE-2014-9904—32.2%
——10——CVE-2025-68841—32.2%
——10——CVE-2025-67274—32.2%
——10——CVE-2023-25749—32.2%
——10——CVE-2022-46862—32.2%
——10——CVE-2016-1570—32.2%
——10——CVE-2024-33930—32.2%
——10——CVE-2025-54997—32.2%
——10——CVE-2008-5366—32.2%
——10——CVE-2017-14770—32.2%
——10——CVE-2024-11497—32.2%
——10——CVE-2023-29020—32.2%
——10——CVE-2026-477438.7 HIG32.2%
——10Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. Second, `Customers/Create::store()` re-passed a `Hidden` `_password` form field straight into the create payload. The plaintext password was rendered into the HTML and transported through the Livewire snapshot in clear text, exposing credentials in the page DOM and in any logging that captures Livewire payloads. Finally, the product barcode field was rendered through `DNS1DFacade::getBarcodeHTML()` with `{!! !!}`. An attacker with `edit_products` permission could persist malicious payload in the barcode field that would execute in the browser of any admin user viewing that product, enabling session theft and privileged-action chaining. Starting in v2.8.0, all vulnerable Livewire model identifiers are now marked `#[Locked]`; `Customers/Create` no longer round-trips the password through a Hidden form field; the plaintext password is hashed at action boundary and never returned to the client; and the product barcode rendering now escapes the value before passing it to the barcode generator and the output is wrapped in an `<svg>` context that does not interpret event handlers. No known workarounds are available.60dCVE-2006-1830—32.2%
——10——CVE-2020-3473—32.2%
——10——CVE-2026-50161—32.2%
——10libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. The expression 4 + hdr->len can wrap when hdr->len is close to UINT64_MAX, causing the mbuf_get_left() bounds check to pass. The subsequent XOR unmasking loop then writes beyond the heap buffer. Applications using websock_accept() or websock_accept_proto() to implement a WebSocket server are affected, and exploitation can cause attacker-controlled heap corruption or denial of service after the HTTP WebSocket upgrade handshake. This issue is fixed in version 4.8.1.3d