Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,330
- High8,526
- Medium6,729
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40460—31.2%
——9——CVE-2023-1159—31.2%
——9——CVE-2026-134017.5 HIG31.2%
——9XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes.
The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever.
Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.65dCVE-2024-50655—31.2%
——9——CVE-2024-40691—31.2%
——9——CVE-2007-6385—31.2%
——9——CVE-2009-1276—31.2%
——9——CVE-2004-0969—31.2%
——9——CVE-2007-0006—31.2%
——9——CVE-2026-162544.3 MED31.2%
——9A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.60dCVE-2026-422038.8 HIG31.2%
——9LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the LiteLLM Proxy process. The endpoint only checks that the caller presents a valid proxy API key, so any authenticated user could reach it. Depending on how the proxy is deployed, this could expose secrets in the process environment (such as provider API keys or database credentials) and allow commands to be run on the host. This issue has been patched in version 1.83.7.67dCVE-2021-2282—31.2%
——9——CVE-2023-4369—31.2%
——9——CVE-2026-56307—31.2%
——9——CVE-2024-25700—31.2%
——9——CVE-2025-3166—31.2%
——9——CVE-2025-22918—31.2%
——9——CVE-2026-18918—31.2%
——9In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An attacked can create a provisional trusted client (valid use-case) but then it can be used as a trusted client immediately without requiring the administrator approval to clear the provisional status. The 3-legged path requiring user interaction is not vulnerable and rejects provisional clients.18dCVE-2014-0470—31.2%
——9——CVE-2024-37038—31.2%
——9——CVE-2013-1063—31.2%
——9——CVE-2024-13633—31.2%
——9——CVE-2021-2287—31.2%
——9——CVE-2026-78365—31.2%
——9Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.18dCVE-2026-472147.1 HIG31.2%
——9Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.80dCVE-2023-1646—31.2%
——9——CVE-2024-34240—31.2%
——9——CVE-2015-4155—31.2%
——9——CVE-2018-0122—31.2%
——9——CVE-2022-41847—31.2%
——9——CVE-2011-3245—31.2%
——9——CVE-2000-0928—31.2%
——9——CVE-2026-919307.5 HIG31.2%
——9Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.3hCVE-2026-117948.1 HIG31.2%
——9The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.80dCVE-2010-3293—31.2%
——9——CVE-2023-51511—31.2%
——9——CVE-2024-4214—31.2%
——9——CVE-2026-739518.1 HIG31.2%
——9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).3dCVE-2023-30322—31.2%
——9——CVE-2026-35320—31.2%
——9——