Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-0455—29.6%
——9——CVE-2026-82874.3 MED29.6%
——9Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation.
This issue affects Online Pre-Accounting Software: through 17072026.57dCVE-2022-35895—29.6%
——9——CVE-2026-256045.4 MED29.6%
——9In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.
This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances.
You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.78dCVE-2018-17488—29.6%
——9——CVE-2024-50575—29.6%
——9——CVE-2024-37255—29.6%
——9——CVE-2024-5809—29.6%
——9——CVE-2024-3181—29.6%
——9——CVE-2026-65633—29.6%
——9Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification.
The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an Authorization: Bearer JWT's signature and rejects tokens containing an act claim, but performs no check that the token's purpose claim equals user at the bearer boundary. When the resource is configured with require_token_presence_for_authentication?: false (the DSL default), the follow-on validate_token/3 helper returns {:ok, nil} without consulting the token resource, so no downstream check on purpose takes place either. As a result, any valid, non-expired JWT the library itself issued for a narrow, single-purpose flow (most notably the purpose: sign_in token that WebAuthn always emits during sign-in, and that the Password strategy emits when sign-in tokens are enabled) is accepted directly as a general-purpose bearer credential and resolves to a full current_user assignment.
This bypasses the library's intended token-exchange contract, in which the sign_in token is meant to be presented exactly once to a preparation that validates the purpose claim and immediately revokes the token. The first use of a still-valid sign-in token presented directly in the Authorization header succeeds because the stateless bearer path never scopes it to purpose == "user".
An attacker who obtains a not-yet-exchanged sign-in token for a target subject (for example via log or referrer leakage, an intercepted magic-link delivery channel, or a partially compromised intermediary) can present it as a bearer token and be authenticated as that subject, fully bypassing the intended one-time-use and revocation semantics. Exploitation additionally requires that the host application wire up retrieve_from_bearer/3 on a reachable route and uses either WebAuthn (sign-in tokens are always issued) or the Password strategy with sign_in_tokens_enabled?: true. Resources configured with require_token_presence_for_authentication?: true (including applications scaffolded by the Igniter installer since v4.5.0) and the session-based path (authenticate_resource_from_session/4) enforce purpose == "user" against the stored token record and are not affected.
This issue affects ash_authentication: from 3.10.5 before 4.14.2 and from 5.0.0-rc.0 before 5.0.0-rc.13.16dCVE-2026-497897.3 HIG29.6%
——9Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.58dCVE-2017-17565—29.6%
——9——CVE-2018-17487—29.6%
——9——CVE-2025-23732—29.6%
——9——CVE-2026-482615.4 MED29.6%
——9Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.21dCVE-2025-69226—29.6%
——9——CVE-2024-3180—29.6%
——9——CVE-2024-6226—29.6%
——9——CVE-2024-37571—29.6%
——9——CVE-2024-45793—29.6%
——9——CVE-2024-3754—29.6%
——9——CVE-2022-44575—29.6%
——9——CVE-2026-116628.8 HIG29.6%
——9Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)57dCVE-2024-39654—29.5%
——9——CVE-2024-3179—29.6%
——9——CVE-2026-33693—29.6%
——9——CVE-2024-24850—29.6%
——9——CVE-2024-1350—29.5%
——9——CVE-2024-45204—29.6%
——9——CVE-2026-72916—29.6%
——9Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses but did not recognize IPv4-compatible IPv6 addresses with IPAddr#ipv4_compat?. An attacker could supply an address in the omitted range to bypass the ALLOWED_PRIVATE_ADDRESSES protection and make Mastodon send HTTP requests to loopback interfaces, potentially accessing private resources and services. Exploitation requires a system that supports the obsolete IPv4-compatible IPv6 mechanism. This issue is fixed in versions 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1.8dCVE-2024-13608—29.6%
——9——CVE-2026-2261—29.6%
——9——CVE-2019-0090—29.6%
——9——CVE-2022-42809—29.6%
——9——CVE-2026-88547.5 HIG29.6%
——9IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.57dCVE-2023-37744—29.6%
——9——CVE-2020-5981—29.6%
——9——CVE-2026-278527.5 HIG29.6%
——9An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No publicly available exploits are known.15dCVE-2013-4217—29.6%
——9——CVE-2025-64213—29.6%
——9——