Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-927879.8 CRI31.3%
——9Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.2dCVE-2026-771047.5 HIG31.3%
——9CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.12dCVE-2022-36191—31.3%
——9——CVE-2025-22874—31.3%
——9——CVE-2026-156286.3 MED31.3%
——9A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.1.2 is capable of addressing this issue. The patch is named e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. The affected component should be upgraded.69dCVE-2023-33320—31.3%
——9——CVE-2026-54746.3 MED31.3%
——9A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.58dCVE-2026-891747.5 HIG31.3%
——9Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.10dCVE-2019-14353—31.3%
——9——CVE-2024-12061—31.3%
——9——CVE-2025-59029—31.3%
——9——CVE-2007-5201—31.3%
——9——CVE-2020-35899—31.3%
——9——CVE-2025-58592—31.3%
——9——CVE-2009-3851—31.3%
——9——CVE-2026-734947.4 HIG31.3%
——9blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.6dCVE-2025-46119—31.3%
——9——CVE-2016-2383—31.3%
——9——CVE-2010-4474—31.3%
——9——CVE-2025-24612—31.3%
——9——CVE-2024-2082—31.3%
——9——CVE-2008-0584—31.3%
——9——CVE-2025-22134—31.3%
——9——CVE-2007-4796—31.3%
——9——CVE-1999-1215—31.3%
——9——CVE-2007-4792—31.3%
——9——CVE-2026-54730—31.3%
——9authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage in an authentication flow. The device attestation occurs in a verification iframe that calls the Google Verified Access API and records the verified device on success, but the vulnerable stages treat the flow as passed as soon as the stage is submitted. An attacker who can reach such a stage, including after primary username and password authentication, can skip the verification iframe and authenticate from a device that was never verified. Where device trust is the only additional factor, that protection is fully bypassed, while other configured factors remain in force. This issue is fixed in versions 2026.2.6 and 2026.5.5.12dCVE-2024-38274—31.3%
——9——CVE-2021-35017.1 HIG31.3%
——9A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.46dCVE-2025-1196—31.3%
——9——CVE-2024-6070—31.3%
——9——CVE-2025-49417—31.3%
——9——CVE-2018-10498—31.3%
——9——CVE-2026-550117.8 HIG31.3%
——9Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.58dCVE-2025-42902—31.3%
——9——CVE-2007-6717—31.3%
——9——CVE-2009-2483—31.3%
——9——CVE-2021-28707—31.3%
——9——CVE-2016-8754—31.3%
——9——CVE-2020-35915—31.3%
——9——