Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,410
- Medium6,691
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2007-3532—31.5%
——9——CVE-2026-737518.8 HIG31.5%
——9An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.6dCVE-2026-30783—31.5%
——9——CVE-2018-1431—31.5%
——9——CVE-2019-13988—31.5%
——9——CVE-2026-40583—31.5%
——9——CVE-2016-0428—31.5%
——9——CVE-2011-0727—31.5%
——9——CVE-2013-1940—31.5%
——9——CVE-2024-12653—31.5%
——9——CVE-2025-12597—31.5%
——9——CVE-2016-1865—31.5%
——9——CVE-2025-0549—31.5%
——9——CVE-2026-599738.5 HIG31.5%
——9FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution to OpenAPIToolGenerator.fromURL() and OpenAPIToolGenerator.fromJSON(). The external $ref guard checks parsed hostname strings without resolving addresses, pinning validated addresses, revalidating redirect targets, or normalizing IPv4-mapped IPv6. An authenticated user who can import or configure an OpenAPI specification in a hosted or multi-user deployment can use DNS-to-loopback resolution, redirect-to-loopback behavior, or IPv4-mapped IPv6 loopback forms to cause backend-origin requests to internal services. This can expose internal administrative APIs, metadata-like services, and other private network endpoints. The practical impact is lower when only a trusted local administrator can configure OpenAPI specs, and disabling external reference protocols prevents the external $ref request. This issue is fixed in mcp-from-openapi 2.5.0 and frontmcp and @frontmcp/adapters 1.5.0.5dCVE-2025-22455—31.5%
——9——CVE-2026-786025.3 MED31.5%
——9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.13dCVE-2024-31464—31.5%
——9——CVE-2012-6648—31.5%
——9——CVE-2021-43566—31.5%
——9——CVE-2026-584786.5 MED31.5%
——9Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase 'opendoor' to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible.68dCVE-2018-3987—31.5%
——9——CVE-2015-2616—31.5%
——9——CVE-2023-31296—31.5%
——9——CVE-2024-48896—31.5%
——9——CVE-2023-5617—31.5%
——9——CVE-2025-49924—31.5%
——9——CVE-2023-37136—31.5%
——9——CVE-2023-37134—31.5%
——9——CVE-2023-51651—31.5%
——9——CVE-2024-32146—31.5%
——9——CVE-2020-8718—31.5%
——9——CVE-2024-12123—31.5%
——9——CVE-2022-422485.4 MED31.5%
——9QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.74dCVE-2026-20119—31.5%
——9——CVE-2025-0064—31.5%
——9——CVE-2024-31253—31.5%
——9——CVE-2025-63095—31.5%
——9——CVE-2025-56449—31.5%
——9——CVE-2026-39480—31.5%
——9——CVE-2026-737538.8 HIG31.5%
——9Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.11d