Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-558856.3 MED29.3%
——9SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php74dCVE-2026-57642—29.4%
——9——CVE-2026-454263.1 LOW29.4%
——9Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested path segment when verifying the JWT's `sub` claim. `str.lstrip()` strips any of a *set* of characters from the left (not a prefix), so a JWT issued for a Dag named e.g. `dag_a` would authorize log access to any other Dag whose name began with any subset of the characters `{d, a, g, _}` (e.g. `dag_attacker`, `aaaa_target`, `_dag_secret`). Such an authenticated worker could enumerate and read worker logs of other Dags whose names happened to share that character-class prefix, leaking task output and error traces beyond the documented per-Dag isolation boundary. Affects deployments relying on per-Dag log-access scoping (multi-team, shared-executor, shared-worker topologies). Users are advised to upgrade to `apache-airflow` 3.2.2 or later.58dCVE-2026-191759.6 CRI29.4%
——9Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)41dCVE-2013-2224—29.4%
——9——CVE-2026-537769.1 CRI29.4%
——9Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indefinitely, bypassing force-expired sessions such as user logout or administrative revocation.65dCVE-2025-13384—29.4%
——9——CVE-2024-46482—29.4%
——9——CVE-2026-4233—29.4%
——9——CVE-2026-191448.8 HIG29.4%
——9Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)37dCVE-2025-10310—29.4%
——9——CVE-2026-189034.3 MED29.4%
——9A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.36dCVE-2026-57636—29.4%
——9——CVE-2010-2198—29.4%
——9——CVE-2015-4808—29.4%
——9——CVE-2022-35713—29.4%
——9——CVE-2023-47052—29.4%
——9——CVE-2018-13435—29.4%
——9——CVE-2026-550886.8 MED29.4%
——9Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTransfer/{uuid}. Although the record includes createdAt, the transfer has no expiration check, is not removed after successful redemption, and is returned by res.send(tokenData), including the raw author token. An unauthenticated attacker who obtains a transfer UUID can repeatedly redeem it, receive fresh author cookies, read the cleartext token, and impersonate the originating author for pad read and write operations. This issue is fixed in version 3.1.0.8dCVE-2026-655268.5 HIG29.4%
——9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection.
This issue affects Visualizer: from n/a through 4.0.1.46dCVE-2026-191698.8 HIG29.4%
——9Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)42dCVE-2026-0701—29.4%
——9——CVE-2025-54040—29.4%
——9——CVE-2025-6792—29.4%
——9——CVE-2025-3940—29.4%
——9——CVE-2026-577718.5 HIG29.4%
——9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.66dCVE-2026-54838—29.4%
——9——CVE-2023-42248—29.3%
——9——CVE-2023-28419—29.4%
——9——CVE-2014-1348—29.4%
——9——CVE-2023-34647—29.4%
——9——CVE-2022-25667—29.4%
——9——CVE-2012-2384—29.4%
——9——CVE-2026-22037—29.4%
——9——CVE-2025-7573—29.4%
——9——CVE-2023-23847—29.4%
——9——CVE-2026-191388.3 HIG29.4%
——9Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)42dCVE-2026-191649.6 CRI29.4%
——9Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)41dCVE-2025-8680—29.4%
——9——CVE-2021-34725—29.4%
——9——