Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-31240—31.1%
——9——CVE-2023-2241—31.1%
——9——CVE-2015-5850—31.1%
——9——CVE-2026-567478.8 HIG31.1%
——9Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.31dCVE-2022-34334—31.1%
——9——CVE-2026-49076—31.1%
——9——CVE-2026-42774—31.1%
——9——CVE-2022-40603—31.1%
——9——CVE-2026-858755.5 MED31.1%
——9Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2dCVE-2021-0089—31.1%
——9——CVE-2019-15034—31.1%
——9——CVE-2025-6569—31.1%
——9——CVE-2026-102135.4 MED31.1%
——9A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.60dCVE-2023-0322—31.1%
——9——CVE-2013-1976—31.1%
——9——CVE-2007-1086—31.1%
——9——CVE-2025-36070—31.1%
——9——CVE-2026-6301—31.1%
——9——CVE-2009-0439—31.1%
——9——CVE-2025-69633—31.1%
——9——CVE-2024-7460—31.1%
——9——CVE-2009-3624—31.1%
——9——CVE-2024-35344—31.1%
——9——CVE-2002-1543—31.1%
——9——CVE-2008-1901—31.1%
——9——CVE-2007-1217—31.1%
——9——CVE-2007-4432—31.1%
——9——CVE-2011-4028—31.1%
——9——CVE-2018-6239—31.1%
——9——CVE-2026-39596—31.1%
——9——CVE-2010-5329—31.1%
——9——CVE-2006-0837—31.1%
——9——CVE-2012-5560—31.1%
——9——CVE-2024-27950—31.1%
——9——CVE-2024-49782—31.1%
——9——CVE-2026-632219.4 CRI31.1%
——9CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4.11dCVE-2026-54885—31.1%
——9Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints.
Three code paths fetch remote URIs supplied by the requester without sufficient validation of the target. Boruta.Oauth.Request.Base.fetch_unsigned_request/1 in lib/boruta/oauth/request/base.ex dereferences the OAuth request_uri parameter from the authorization request via Finch.build(:get, request_uri) |> Finch.request(OpenIDHttpClient). Boruta.Openid.parse_registration_params/2 in lib/boruta/openid.ex dereferences the jwks_uri supplied in an OpenID Connect dynamic client registration request. Boruta.Ecto.Clients.refresh_jwk_from_jwks_uri/1 in lib/boruta/adapters/ecto/clients.ex later refreshes the stored jwks_uri for an existing client. In all three paths the only validation is that the URI parses with a scheme (and one of the two request_uri clauses does not even restrict the scheme to http or https). The implementations do not require HTTPS, do not enforce a host or IP allowlist, do not reject loopback, private, link-local, or other non-public ranges after DNS resolution, do not cap response size, and do not constrain redirects. An attacker can therefore steer the server's HTTP client at arbitrary network targets reachable from the Boruta host.
This issue affects boruta: from 2.3.2 before 2.3.7.51dCVE-2026-34065—31.1%
——9——CVE-2026-506358.8 HIG31.1%
——9LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.59dCVE-2023-38555—31.1%
——9——