Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,356
- High8,513
- Medium6,629
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-2894—30.1%
——9——CVE-2026-919967.5 HIG30.1%
——9lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths, operating system details, and startup secrets.1dCVE-2025-55474—30.1%
——9——CVE-2024-43331—30.1%
——9——CVE-2025-15003—30.1%
——9——CVE-2026-516427.5 HIG30.1%
——9Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-517269.1 CRI30.1%
——9Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2022-27573—30.1%
——9——CVE-2026-54443—30.1%
——9Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.65dCVE-2024-5459—30.1%
——9——CVE-1999-1530—30.1%
——9——CVE-2025-59580—30.1%
——9——CVE-2026-516167.5 HIG30.1%
——9Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2020-37066—30.1%
——9——CVE-2025-20678—30.1%
——9——CVE-2018-3566—30.1%
——9——CVE-2026-516207.5 HIG30.1%
——9Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2007-6208—30.1%
——9——CVE-2003-1224—30.1%
——9——CVE-2023-26349—30.1%
——9——CVE-2022-40080—30.1%
——9——CVE-2011-3542—30.1%
——9——CVE-2026-516729.1 CRI30.1%
——9Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-91377.5 HIG30.1%
——9The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.57dCVE-2025-8186—30.1%
——9——CVE-2025-46823—30.1%
——9——CVE-2022-42396—30.1%
——9——CVE-2026-517357.5 HIG30.1%
——9Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2025-22260—30.1%
——9——CVE-2026-516369.1 CRI30.1%
——9Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2025-2220—30.1%
——9——CVE-2026-516989.1 CRI30.1%
——9Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2017-6401—30.1%
——9——CVE-2026-516289.1 CRI30.1%
——9Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-555775.9 MED30.1%
——9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.78dCVE-2026-516197.5 HIG30.1%
——9Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2024-35710—30.1%
——9——CVE-2026-517369.1 CRI30.1%
——9Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.17dCVE-2026-545727.5 HIG30.1%
——9Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.64dCVE-2022-26373—30.1%
——9——