Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-1062—29.4%
——9——CVE-2023-40605—29.4%
——9——CVE-2024-45606—29.4%
——9——CVE-2025-41366—29.4%
——9——CVE-2026-42737—29.4%
——9——CVE-2026-178167.5 HIG29.4%
——9Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-876469.6 CRI29.4%
——9Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)8dCVE-2026-6032—29.4%
——9——CVE-2026-7852—29.4%
——9——CVE-2026-239605.4 MED29.4%
——9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another user’s browser under the Argo Server origin, enabling API actions with the victim’s privileges. Versions 3.6.17 and 3.7.8 fix the issue.65dCVE-2023-28885—29.4%
——9——CVE-2026-41157—29.4%
——9——CVE-2026-739969.8 CRI29.4%
——9Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.29dCVE-2024-43937—29.4%
——9——CVE-2026-341493.3 LOW29.4%
——9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell commands without adequate escaping, allowing an authenticated user with database management permissions to execute commands on managed servers. This issue is fixed in version 4.0.0-beta.471.73dCVE-2026-27664—29.4%
——9——CVE-2025-50528—29.4%
——9——CVE-2026-712319.8 CRI29.4%
——9IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string.22dCVE-2024-43229—29.4%
——9——CVE-2026-6442—29.4%
——9——CVE-2024-6104—29.4%
——9——CVE-2026-55730—29.4%
——9Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.52dCVE-2026-22471—29.4%
——9——CVE-2026-712789.8 CRI29.4%
——9rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.22dCVE-2022-38435—29.4%
——9——CVE-2017-17852—29.4%
——9——CVE-2024-11873—29.4%
——9——CVE-2025-4316—29.4%
——9——CVE-2022-22454—29.4%
——9——CVE-2025-63212—29.4%
——9——CVE-2024-0427—29.4%
——9——CVE-2005-2231—29.4%
——9——CVE-2015-0990—29.4%
——9——CVE-2023-4227—29.4%
——9——CVE-2024-456153.9 LOW29.4%
——9A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).80dCVE-2026-121448.8 HIG29.4%
——9The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_options')`. This makes it possible for authenticated attackers with author-level access and above to escalate their privileges to administrator by supplying `administrator` as the `user_role_set` value in a crafted request. The function is gated only by a nonce (`request_user_role_nonce`) that is rendered in the meta box on the `wwp_requests` post edit screen; because the post type is registered with `capability_type => 'post'`, any author-level user who has authored a `wwp_requests` post — such as one created via the wholesale registration form — can access this nonce and submit the role-assignment request.50dCVE-2003-0455—29.4%
——9——CVE-2026-864789.8 CRI29.4%
——9In JetBrains YouTrack before 2025.3.161254,
2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address9dCVE-2025-55886—29.4%
——9——CVE-2017-14102—29.4%
——9——