Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34970—31.1%
——9——CVE-2024-49782—31.1%
——9——CVE-2024-27950—31.1%
——9——CVE-2009-3624—31.1%
——9——CVE-2026-6301—31.1%
——9——CVE-2024-7460—31.1%
——9——CVE-2025-69633—31.1%
——9——CVE-2026-31240—31.1%
——9——CVE-2009-0439—31.1%
——9——CVE-2025-36070—31.1%
——9——CVE-2007-1086—31.1%
——9——CVE-2025-6569—31.1%
——9——CVE-2013-1976—31.1%
——9——CVE-2023-0322—31.1%
——9——CVE-2019-15034—31.1%
——9——CVE-2026-102135.4 MED31.1%
——9A security flaw has been discovered in AstrBotDevs AstrBot 4.23.6. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.60dCVE-2021-0089—31.1%
——9——CVE-2023-24068—31.1%
——9——CVE-2025-13121—31.1%
——9——CVE-2026-26377—31.1%
——9——CVE-2024-5286—31.1%
——9——CVE-2022-27619—31.1%
——9——CVE-2026-858755.5 MED31.1%
——9Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2dCVE-2015-5850—31.1%
——9——CVE-2026-567478.8 HIG31.1%
——9Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.31dCVE-2023-2241—31.1%
——9——CVE-2022-34334—31.1%
——9——CVE-2022-40603—31.1%
——9——CVE-2026-42774—31.1%
——9——CVE-2026-49076—31.1%
——9——CVE-2024-49256—31.1%
——9——CVE-2026-12686—31.1%
——9An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. The application does not adequately verify whether the requested company ID belongs to the authenticated user’s session, resulting in a cross-tenant authorisation bypass. If this vulnerability is successfully exploited, it allows unauthorised access to sensitive customer information, including billing data, and may enable the unauthorised modification of third-party data.75dCVE-2015-0999—31.1%
——9——CVE-2026-60124—31.1%
——9An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.72dCVE-2012-6031—31.1%
——9——CVE-2018-17155—31.1%
——9——CVE-2020-11640—31.1%
——9——CVE-2025-628263.1 LOW31.1%
——9An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.40dCVE-2023-50614—31.1%
——9——CVE-2026-45819—31.1%
——9baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.10d