Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-10411—29.3%
——9——CVE-2024-2383—29.3%
——9——CVE-2025-8174—29.3%
——9——CVE-2026-615748.8 HIG29.3%
——9authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The endpoint listing does not apply the access controls governing the endpoints, and the connection flow does not confirm that an endpoint belongs to the Remote Access Control application through which it was launched. Any authenticated user can therefore read every endpoint together with its host and stored credentials and can open a connection to an endpoint belonging to another application. This exposes stored credentials for managed RDP, SSH, and VNC targets and grants interactive access to systems the user was never authorized to reach. Deployments that do not use the enterprise Remote Access Control provider are not affected. This issue is fixed in versions 2026.2.6 and 2026.5.5.9dCVE-2018-1796—29.3%
——9——CVE-2024-46951—29.3%
——9——CVE-2025-53782—29.3%
——9——CVE-2026-769407.5 HIG29.3%
——9The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deployments that rely on password based authentication.17dCVE-2023-38292—29.3%
——9——CVE-2026-58264.3 MED29.3%
——9A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.56dCVE-2026-61711—29.3%
——9BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.8dCVE-2018-9334—29.3%
——9——CVE-2017-16834—29.3%
——9——CVE-2023-0258—29.3%
——9——CVE-2024-2889—29.3%
——9——CVE-2023-24529—29.3%
——9——CVE-2024-12467—29.3%
——9——CVE-2024-29812—29.3%
——9——CVE-2023-38276—29.3%
——9——CVE-2026-54639—29.3%
——9——CVE-2024-31348—29.3%
——9——CVE-2023-1013—29.3%
——9——CVE-2024-56070—29.3%
——9——CVE-2026-633009.9 CRI29.3%
——9An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.7dCVE-2023-1060—29.3%
——9——CVE-2026-40655.4 MED29.3%
——9The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires unfiltered_html capability), and several controller actions only validate the nonce (validateToken()) without calling validatePermission(). This makes it possible for authenticated attackers, with Contributor-level access and above, to enumerate slider metadata and create, modify, and delete image storage records by obtaining the nextend_nonce exposed on post editor pages.55dCVE-2025-54364—29.3%
——9——CVE-2026-74904—29.3%
——9——CVE-2026-58254.3 MED29.3%
——9A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.56dCVE-2025-22306—29.3%
——9——CVE-2025-31122—29.3%
——9——CVE-2023-36137—29.3%
——9——CVE-2025-27954—29.3%
——9——CVE-2022-24505—29.3%
——9——CVE-2025-60633—29.3%
——9——CVE-2025-20285—29.3%
——9——CVE-2026-493537.5 HIG29.3%
——99Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process stdin paths.63dCVE-2023-38275—29.3%
——9——CVE-2026-170785.3 MED29.3%
——9IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.29dCVE-2022-43711—29.3%
——9——