Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-504697.8 HIG30.9%
——9Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.59dCVE-2025-23682—30.9%
——9——CVE-2013-1700—30.9%
——9——CVE-2020-29292—30.9%
——9——CVE-2026-86590—30.9%
——9In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with no host filtering. An authenticated user can exploit this server-side request forgery (SSRF) to read responses from internal network addresses, including the cloud instance metadata service (169.254.169.254), loopback interfaces, RFC-1918 private ranges, and in-cluster Kubernetes services. The operator-configured allowlist (spec.devEnvironments.allowedSources.urls) is not consulted. The vulnerability is fixed in version 7.122.0, which adds private-address blocking, IPv4-mapped IPv6 bypass prevention, operator allowlist enforcement, and disables HTTP redirects on the outbound request.11dCVE-2021-27778—30.9%
——9——CVE-2026-27588—30.9%
——9——CVE-2026-425075.3 MED30.9%
——9When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.59dCVE-2021-0928—30.9%
——9——CVE-2025-65125—30.9%
——9——CVE-2026-281978.8 HIG30.9%
——9An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Successful exploitation grants the attacker
unrestricted control over the Flex appliance host and all hosted
containers, fully compromising confidentiality, integrity, and
availability.1dCVE-2025-23630—30.9%
——9——CVE-2022-44561—30.9%
——9——CVE-2026-586367.8 HIG30.9%
——9Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.65dCVE-2022-22762—30.9%
——9——CVE-2026-48525—30.9%
——9——CVE-2023-28733—30.9%
——9——CVE-2025-23683—30.9%
——9——CVE-2025-23701—30.9%
——9——CVE-2026-350808.1 HIG30.9%
——9The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.59dCVE-2026-24894—30.9%
——9——CVE-2026-591365.5 MED30.9%
——9Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.34dCVE-2024-33148—30.9%
——9——CVE-2025-23631—30.9%
——9——CVE-2025-11173—30.9%
——9——CVE-2026-759106.5 MED30.9%
——9Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.25dCVE-2025-2876—30.9%
——9——CVE-2025-23746—30.9%
——9——CVE-2025-23678—30.9%
——9——CVE-2025-23706—30.9%
——9——CVE-2026-48114—30.9%
——9——CVE-2023-4552—30.9%
——9——CVE-2017-5683—30.9%
——9——CVE-2026-350818.1 HIG30.9%
——9The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.59dCVE-2024-1775—30.9%
——9——CVE-2025-14855—30.9%
——9——CVE-2025-23672—30.9%
——9——CVE-2026-504388.8 HIG30.9%
——9Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.61dCVE-2026-350778.1 HIG30.9%
——9The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.59dCVE-2024-32990—30.9%
——9——