Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-543478.7 HIG32.1%
——10Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML escaping, and templates/Froxlor/table/table.html.twig renders the callback result with the raw filter. An authenticated customer with DNS editor access can store JavaScript-bearing content in a TXT record. When an administrator views the affected domain's DNS configuration, the payload executes automatically in the administrator's browser session, which can expose session data or perform privileged panel actions. This issue is fixed in version 2.3.8.13dCVE-2025-52853—32.1%
——10——CVE-2025-24806—32.1%
——10——CVE-2022-42370—32.1%
——10——CVE-2024-36378—32.1%
——10——CVE-2017-7766—32.1%
——10——CVE-2015-8222—32.1%
——10——CVE-2025-7210—32.1%
——10——CVE-2024-8269—32.1%
——10——CVE-2023-20130—32.1%
——10——CVE-2025-64181—32.1%
——10——CVE-2016-5759—32.1%
——10——CVE-2024-8108—32.1%
——10——CVE-2026-685706.5 MED32.1%
——10Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.
This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.7dCVE-2024-53304—32.1%
——10——CVE-2025-14011—32.1%
——10——CVE-2022-4107—32.1%
——10——CVE-2026-487266.5 MED32.1%
——10A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, so the JWT remained accepted by the API server until its natural expiry. An attacker holding a previously-issued JWT for a logged-out user could continue to make authenticated API calls as that user. Affects deployments configured with `FabAuthManager` or `KeycloakAuthManager` (the bug does not affect SimpleAuthManager). This is a residual gap in the fix for CVE-2025-57735, which addressed cookie-side invalidation in PR #57992 / PR #61339 but did not cover the provider-side `revoke_token()` reachability in the FAB / Keycloak code paths. Users who already upgraded for CVE-2025-57735 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the FAB / Keycloak logout paths.62dCVE-2026-22081—32.1%
——10——CVE-2016-1920—32.1%
——10——CVE-2005-0079—32.1%
——10——CVE-2025-29364—32.1%
——10——CVE-2026-18674—32.0%
——10On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone.
The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide.
The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.21dCVE-2023-41717—32.1%
——10——CVE-2023-33968—32.1%
——10——CVE-2025-52860—32.1%
——10——CVE-2026-122918.8 HIG32.1%
——10Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.68dCVE-2026-31151—32.1%
——10——CVE-2025-52859—32.1%
——10——CVE-2024-48195—32.1%
——10——CVE-2026-30701—32.1%
——10——CVE-2025-709627.5 HIG32.1%
——10Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.12dCVE-2025-7151—32.1%
——10——CVE-2021-25097—32.1%
——10——CVE-2025-13563—32.1%
——10——CVE-2018-7542—32.1%
——10——CVE-2023-41797—32.1%
——10——CVE-2025-52433—32.1%
——10——CVE-1999-0358—32.1%
——10——CVE-2026-157375.7 MED32.1%
——10AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform.
Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user prompts and agent responses containing sensitive data via span attributes. The SDK wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, exposing sensitive content to any principal with log read access.
We recommend you upgrade to version 1.5.1 or later. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups.66d