Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,376
- High8,709
- Medium6,727
- Low723
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-5153—30.0%
——9——CVE-2024-0628—30.0%
——9——CVE-2026-567848.1 HIG30.0%
——9OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. The removeAlarms() method in AlarmResourceImpl.java omits realm-scoping validation in its JPA query, enabling any user with alarm-write permissions to enumerate sequential auto-increment alarm IDs and delete cross-tenant alarm records without authorization.66dCVE-2026-39493—30.0%
——9——CVE-2010-4256—30.0%
——9——CVE-2020-1618—30.0%
——9——CVE-2001-1322—30.0%
——9——CVE-2010-2928—30.0%
——9——CVE-2024-43266—30.0%
——9——CVE-2016-3925—30.0%
——9——CVE-2023-36380—30.0%
——9——CVE-2026-6759—30.0%
——9——CVE-1999-1181—30.0%
——9——CVE-2025-503308.8 HIG30.0%
——9An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.56dCVE-2024-25119—30.0%
——9——CVE-2026-39492—30.0%
——9——CVE-2021-27194—30.0%
——9——CVE-2021-45521—30.0%
——9——CVE-2007-4574—30.0%
——9——CVE-2002-0911—30.0%
——9——CVE-2002-0377—30.0%
——9——CVE-1999-1040—30.0%
——9——CVE-2002-0762—30.0%
——9——CVE-2007-2040—30.0%
——9——CVE-2026-474169.6 CRI30.0%
——9PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_role(workspace_id, user_id, body.role)` which sets the target member's role to whatever the request body specifies, with no check that the caller has owner-or-admin privilege, no check that the new role is not higher than the caller's own, and no check that the caller is not silently promoting themselves. PraisonAI Platform version 0.1.4 patches the issue.58dCVE-2025-156874.3 MED30.0%
——9A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.37dCVE-2018-7094—30.0%
——9——CVE-2010-3584—30.0%
——9——CVE-2000-0269—30.0%
——9——CVE-2004-1356—30.0%
——9——CVE-2016-2150—30.0%
——9——CVE-2008-5152—30.0%
——9——CVE-2005-1126—30.0%
——9——CVE-2025-13035—30.0%
——9——CVE-2008-1142—30.0%
——9——CVE-2005-3701—30.0%
——9——CVE-2009-2796—30.0%
——9——CVE-2001-0734—30.0%
——9——CVE-2024-9364—30.0%
——9——CVE-2024-12731—30.0%
——9——