Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-21597—31.4%
——9——CVE-2026-766478.8 HIG31.4%
——9Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer methods, allowing an authenticated user to call methods or act on resources outside their intended permissions. For example, the editOwn method accepts a user-supplied user ID without verifying that it belongs to the caller, allowing an attacker to modify another user's account and set a new password, resulting in account takeover. This vulnerability is distinct from CVE-2026-59712 and CVE-2026-15509 because the root cause is the lack of centralized authorization enforcement in the JSON-RPC dispatcher rather than the behavior of an individual exposed method.13dCVE-2025-0538—31.4%
——9——CVE-2026-24489—31.4%
——9——CVE-2025-13587—31.4%
——9——CVE-2020-8722—31.4%
——9——CVE-2023-42532—31.4%
——9——CVE-2025-5830—31.4%
——9——CVE-2025-53260—31.4%
——9——CVE-2024-24879—31.4%
——9——CVE-2024-38517—31.4%
——9——CVE-2017-1000387—31.4%
——9——CVE-2024-24833—31.4%
——9——CVE-2019-16230—31.4%
——9——CVE-2025-137875.4 MED31.4%
——9A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.18dCVE-2023-32101—31.4%
——9——CVE-2019-18361—31.4%
——9——CVE-2025-6841—31.4%
——9——CVE-2024-29508—31.4%
——9——CVE-2015-5832—31.4%
——9——CVE-2026-455006.1 MED31.4%
——9Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.54dCVE-2016-9084—31.4%
——9——CVE-2024-9670—31.4%
——9——CVE-2013-1066—31.4%
——9——CVE-2024-38866—31.4%
——9——CVE-2026-2822—31.4%
——9——CVE-2026-492237.6 HIG31.4%
——9Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a low-privileged Vendor to manage reviews under another Vendor's products. The admin/sql/sqlite/product_review.sql queries accept a caller-controlled product_review_id and do not verify product_review.product_id against product.admin_id for the current admin_id. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4.12dCVE-2024-9344—31.4%
——9——CVE-2009-0912—31.4%
——9——CVE-2025-61784—31.4%
——9——CVE-2025-49659—31.4%
——9——CVE-2024-29470—31.4%
——9——CVE-2012-6033—31.4%
——9——CVE-2024-7691—31.4%
——9——CVE-2025-10976—31.4%
——9——CVE-2015-1106—31.4%
——9——CVE-2025-8435—31.4%
——9——CVE-2024-24881—31.4%
——9——CVE-2026-778834.9 MED31.4%
——9Exposure of sensitive information through data queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.6dCVE-2024-6344—31.4%
——9——