Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-39596—31.1%
——9——CVE-2018-6239—31.1%
——9——CVE-2012-5560—31.1%
——9——CVE-2010-5329—31.1%
——9——CVE-2023-22122—31.1%
——9——CVE-2026-39385—31.1%
——9Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.59dCVE-2021-36535—31.1%
——9——CVE-2026-42773—31.1%
——9——CVE-2008-1901—31.1%
——9——CVE-2007-4432—31.1%
——9——CVE-2011-4028—31.1%
——9——CVE-2025-6126—31.1%
——9——CVE-2024-56802—31.1%
——9——CVE-2026-57494—31.1%
——9AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be used with the capability-style task mutation endpoints (`/tasks/:id/claim`, `/tasks/:id/result`, `/tasks/:id/complete`, `/tasks/:id/fail`) to claim, complete, or fail tasks assigned to a different agent. Because ordinary authenticated agents can discover agent names through `GET /api/agenticmail/accounts/directory`, the task ID effectively stops being a secret capability. This turns the intended capability model into a cross-agent authorization bypass. Version 0.9.64 contains a fix.58dCVE-2024-9712—31.1%
——9——CVE-2017-15822—31.1%
——9——CVE-2024-9723—31.1%
——9——CVE-2026-102135.4 MED31.1%
——9A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.60dCVE-2023-0322—31.1%
——9——CVE-2013-1976—31.1%
——9——CVE-2007-1086—31.1%
——9——CVE-2019-15034—31.1%
——9——CVE-2025-36070—31.1%
——9——CVE-2025-6569—31.1%
——9——CVE-2009-3624—31.1%
——9——CVE-2024-7460—31.1%
——9——CVE-2025-69633—31.1%
——9——CVE-2026-6301—31.1%
——9——CVE-2009-0439—31.1%
——9——CVE-2021-0089—31.1%
——9——CVE-2022-27619—31.1%
——9——CVE-2023-24068—31.1%
——9——CVE-2025-13121—31.1%
——9——CVE-2018-17155—31.1%
——9——CVE-2026-664469.3 CRI31.1%
——9Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.36dCVE-2022-22179—31.1%
——9——CVE-2024-9721—31.1%
——9——CVE-2025-9776—31.1%
——9——CVE-2024-49782—31.1%
——9——CVE-2024-27950—31.1%
——9——