Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-11156—31.9%
——10——CVE-2026-570305.9 MED31.9%
——10A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
As part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds:
user@host> show security flow session | match timeout
Session ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid
This will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary':
user@host> show security flow session summary | match invalid
Invalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot.
This issue affects Junos OS on SRX Series:
* 24.2 versions before 24.2R2-S3,
* 24.4 versions before 24.4R2-S1, 24.4R2-S2,
* 25.2 versions before 25.2R1-S2, 25.2R2.
This issue does not affect releases earlier than 24.2R1;70dCVE-2023-40470—31.9%
——10——CVE-2025-10825—31.9%
——10——CVE-2025-105926.3 MED31.9%
——10A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.32dCVE-2026-687605.3 MED31.9%
——10An unauthenticated user may bypass authentication under specific cache conditions.19dCVE-2025-11592—31.9%
——10——CVE-2024-12333—31.9%
——10——CVE-2025-2691—31.9%
——10——CVE-2022-41844—31.9%
——10——CVE-2019-12203—31.9%
——10——CVE-2023-37357—31.9%
——10——CVE-2025-10420—31.9%
——10——CVE-2026-779039.0 CRI31.9%
——10Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.3dCVE-2025-10848—31.9%
——10——CVE-2025-37143—31.9%
——10——CVE-2021-43270—31.9%
——10——CVE-2026-92917.1 HIG31.9%
——10Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results.
We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.60dCVE-2017-6348—31.9%
——10——CVE-2025-10807—31.9%
——10——CVE-2010-4079—31.9%
——10——CVE-2026-27338—31.9%
——10——CVE-2007-3740—31.9%
——10——CVE-2026-673249.8 CRI31.9%
——10GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.18dCVE-2026-794077.5 HIG31.9%
——10A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME value with the settings directory and opens the resulting path without validating that the resolved path remains within the intended directory.13dCVE-2023-37359—31.9%
——10——CVE-2026-516627.5 HIG31.9%
——10Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.20dCVE-2025-10431—31.9%
——10——CVE-2024-28962—31.9%
——10——CVE-2025-66395—31.9%
——10——CVE-2017-7262—31.9%
——10——CVE-2025-10805—31.9%
——10——CVE-2025-11589—31.9%
——10——CVE-2025-11603—31.9%
——10——CVE-2026-919857.5 HIG31.9%
——10Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.5dCVE-2015-6315—31.9%
——10——CVE-2025-10804—31.9%
——10——CVE-2026-868045.3 MED31.9%
——10A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.10dCVE-2025-10828—31.9%
——10——CVE-2025-64227—31.9%
——10——