Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,510
- Medium6,633
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-28217—30.7%
——9——CVE-2006-0037—30.7%
——9——CVE-2021-43937—30.7%
——9——CVE-2018-1711—30.7%
——9——CVE-2024-4769—30.7%
——9——CVE-2026-492705.9 MED30.7%
——9Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.59dCVE-2016-1572—30.6%
——9——CVE-2021-47857—30.7%
——9——CVE-2007-5087—30.7%
——9——CVE-2026-54761—30.7%
——9——CVE-2022-35097—30.7%
——9——CVE-2024-3868—30.7%
——9——CVE-2026-6879—30.7%
——9`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end of the sibling list, such as with `[last()]` or `[last()-N]`; `.//item[1]` short-circuits after the first match.37dCVE-2016-10351—30.7%
——9——CVE-2024-6378—30.7%
——9——CVE-2022-22191—30.7%
——9——CVE-2018-4168—30.7%
——9——CVE-2022-34101—30.7%
——9——CVE-2021-43056—30.7%
——9——CVE-2021-45517—30.7%
——9——CVE-2024-6231—30.7%
——9——CVE-2020-8681—30.7%
——9——CVE-2026-198838.8 HIG30.7%
——9The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access.25dCVE-2026-729486.7 MED30.7%
——9Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.10dCVE-2024-9211—30.7%
——9——CVE-2024-5669—30.7%
——9——CVE-2022-22155—30.7%
——9——CVE-2025-49083—30.7%
——9——CVE-2025-64332—30.7%
——9——CVE-2025-7947—30.7%
——9——CVE-2024-12845—30.7%
——9——CVE-2024-22220—30.7%
——9——CVE-2011-10014—30.7%
——9——CVE-2023-1188—30.7%
——9——CVE-2026-442824.8 MED30.7%
——9Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_title helper returns the translatable question body through html_safe without a sanitization boundary, causing stored script execution when visitors open public election pages or voting booth screens. The persisted script executes in visitors' browsers. The vulnerability is fixed in 0.32.0.3dCVE-2024-3636—30.7%
——9——CVE-2026-30702—30.7%
——9——CVE-2022-3156—30.7%
——9——CVE-2026-0490—30.7%
——9——CVE-2026-735626.5 MED30.7%
——9Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and Schema.prototype._getPathType can treat inherited properties of schema.paths and schema.nested as schema types, allowing the casting process to set $fullPath and $parentSchemaDocArray on Object.prototype before throwing. This prototype pollution makes those properties visible on newly created objects and can cause application integrity and availability impacts. This issue is fixed in versions 6.13.10, 7.8.10, 8.24.1, and 9.7.2.35d