Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,297
- Medium6,569
- Low706
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-39811—30.2%
——9——CVE-2026-146986.3 MED30.2%
——9A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.74dCVE-2026-598775.3 MED30.2%
——9protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.70dCVE-2026-191673.1 LOW30.2%
——9Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)42dCVE-2026-147256.3 MED30.2%
——9A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.74dCVE-2026-156246.3 MED30.2%
——9A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.65dCVE-2025-58143—30.2%
——9——CVE-2026-26958—30.2%
——9——CVE-2026-20916—30.2%
——9——CVE-2017-2663—30.2%
——9——CVE-2010-5160—30.2%
——9——CVE-2009-2859—30.2%
——9——CVE-2026-162066.3 MED30.2%
——9A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.60dCVE-2017-7261—30.2%
——9——CVE-2016-2036—30.2%
——9——CVE-2024-39554—30.2%
——9——CVE-2024-57255—30.2%
——9——CVE-2026-276810.0 CRI30.2%
——9Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.66dCVE-2026-410144.3 MED30.2%
——9The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.59dCVE-2024-32770—30.2%
——9——CVE-2024-5619—30.2%
——9——CVE-2011-3515—30.2%
——9——CVE-2024-1937—30.2%
——9——CVE-2022-4456—30.2%
——9——CVE-2021-46701—30.2%
——9——CVE-2024-32767—30.2%
——9——CVE-2023-22428—30.2%
——9——CVE-2021-20450—30.2%
——9——CVE-2023-0577—30.2%
——9——CVE-2022-35646—30.2%
——9——CVE-2026-147766.3 MED30.2%
——9A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The name of the affected product appears to have a typo in it.74dCVE-2023-29188—30.2%
——9——CVE-2024-10276—30.2%
——9——CVE-2013-0218—30.2%
——9——CVE-2026-161216.3 MED30.2%
——9A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.60dCVE-2020-5984—30.2%
——9——CVE-2020-28045—30.2%
——9——CVE-2015-4820—30.2%
——9——CVE-2025-5412—30.2%
——9——CVE-2025-1447—30.2%
——9——