Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,330
- High8,526
- Medium6,729
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-32821—31.2%
——9——CVE-2026-919307.5 HIG31.2%
——9Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.3hCVE-2026-78365—31.2%
——9Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to /api/supplier/{id} setting company_id in the body.18dCVE-2014-0470—31.2%
——9——CVE-2026-489597.5 HIG31.2%
——9IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.
fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.
Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.58dCVE-2023-1646—31.2%
——9——CVE-2013-1063—31.2%
——9——CVE-2021-2287—31.2%
——9——CVE-2024-37038—31.2%
——9——CVE-2026-472147.1 HIG31.2%
——9Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.80dCVE-2026-54515—31.2%
——9——CVE-2023-52430—31.2%
——9——CVE-2014-3450—31.2%
——9——CVE-2025-3763—31.2%
——9——CVE-2025-39413—31.2%
——9——CVE-2026-846708.8 HIG31.2%
——9Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.16dCVE-2025-0589—31.2%
——9——CVE-2006-5396—31.2%
——9——CVE-2023-2544—31.2%
——9——CVE-2021-3939—31.2%
——9——CVE-2016-5516—31.2%
——9——CVE-2026-566897.7 HIG31.2%
——9Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.65dCVE-2021-32622—31.2%
——9——CVE-2026-163237.5 HIG31.2%
——9Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass.
This issue affects ArchitectPanel Web Admin Panel: through 28072026.29dCVE-2018-15778—31.2%
——9——CVE-2026-40042—31.2%
——9——CVE-2023-5932—31.2%
——9——CVE-2022-47946—31.2%
——9——CVE-2024-13242—31.2%
——9——CVE-2021-2285—31.2%
——9——CVE-2024-10034—31.2%
——9——CVE-2019-25541—31.2%
——9——CVE-1999-1406—31.2%
——9——CVE-2025-47710—31.2%
——9——CVE-2026-464848.1 HIG31.2%
——9Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.59dCVE-2024-6559—31.2%
——9——CVE-2024-5097—31.2%
——9——CVE-2019-19058—31.2%
——9——CVE-2024-34442—31.2%
——9——CVE-2024-25697—31.2%
——9——