Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,319
- High8,273
- Medium6,559
- Low705
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47421—30.4%
——9——CVE-2025-59938—30.4%
——9——CVE-2024-9411—30.4%
——9——CVE-2025-363284.3 MED30.4%
——9IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.74dCVE-2026-18430—30.4%
——9HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason.21dCVE-2026-832689.1 CRI30.4%
——9Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).2dCVE-2026-79743—30.4%
——9MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, MCPB File Upload Handler extracts a ZIP file and reads manifest.json from it. The name field in the manifest is directly concatenated into a file path (line 107) without any sanitization or path traversal character validation. An attacker can craft a malicious MCPB file where manifest.name is set to something like ../../../etc/malicious, causing the file to be extracted to an arbitrary location on the file system. The cleanupOldMcpbServer function (line 110) also uses the unsanitized name, potentially allowing deletion of arbitrary directories. This issue has been patched in version 0.12.13.10dCVE-2023-47694—30.3%
——9——CVE-2026-27596—30.4%
——9——CVE-2025-54287—30.3%
——9——CVE-2026-8746—30.4%
——9——CVE-2024-28020—30.4%
——9——CVE-2026-40493—30.4%
——9——CVE-2024-34763—30.4%
——9——CVE-2020-199093.3 LOW30.4%
——9Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. This is not especially plausible because the overflow only happens if the user was trying to specify that curl should wait weeks (or longer) before trying to recover from a transient error.55dCVE-2026-650079.6 CRI30.4%
——9The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every panel user). This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover.57dCVE-2011-1784—30.4%
——9——CVE-2024-43322—30.4%
——9——CVE-2005-2991—30.4%
——9——CVE-2026-6457—30.4%
——9——CVE-2026-28785—30.4%
——9——CVE-2022-32864—30.4%
——9——CVE-2026-65407.5 HIG30.4%
——9Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.42dCVE-2019-25482—30.4%
——9——CVE-2001-0774—30.4%
——9——CVE-2025-2840—30.4%
——9——CVE-2007-0237—30.4%
——9——CVE-2025-4383—30.4%
——9——CVE-2024-12146—30.4%
——9——CVE-2024-2494—30.4%
——9——CVE-2016-5608—30.4%
——9——CVE-2020-22334—30.4%
——9——CVE-2025-41685—30.4%
——9——CVE-2026-629997.5 HIG30.4%
——9Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This issue is fixed in version 9.17.0.9dCVE-2025-13267—30.4%
——9——CVE-2026-6031—30.4%
——9——CVE-2016-3814—30.4%
——9——CVE-2024-45538—30.4%
——9——CVE-2026-789118.3 HIG30.4%
——9Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)22dCVE-2023-40306—30.4%
——9——