Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-3944—29.3%
——9——CVE-2019-4143—29.3%
——9——CVE-2023-4371—29.3%
——9——CVE-2000-1004—29.3%
——9——CVE-2005-0977—29.3%
——9——CVE-2025-45378—29.3%
——9——CVE-2025-9376—29.3%
——9——CVE-2025-23666—29.3%
——9——CVE-2025-23612—29.3%
——9——CVE-2025-23632—29.3%
——9——CVE-2025-23543—29.3%
——9——CVE-2025-23459—29.3%
——9——CVE-2026-186727.5 HIG29.3%
——9In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.9dCVE-2020-8157—29.3%
——9——CVE-2023-26442—29.3%
——9——CVE-2005-4761—29.3%
——9——CVE-2005-1151—29.3%
——9——CVE-2023-3542—29.3%
——9——CVE-2006-0482—29.3%
——9——CVE-2012-3116—29.3%
——9——CVE-2025-26542—29.3%
——9——CVE-2023-3540—29.3%
——9——CVE-2024-5929—29.3%
——9——CVE-2009-1984—29.3%
——9——CVE-2026-63889.1 CRI29.3%
——9A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting application integrity through unauthorized application updates.65dCVE-2007-4236—29.3%
——9——CVE-2023-1507—29.3%
——9——CVE-2019-16729—29.3%
——9——CVE-2023-3538—29.3%
——9——CVE-2023-3861—29.3%
——9——CVE-2026-551127.5 HIG29.3%
——9A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.70dCVE-2023-3860—29.3%
——9——CVE-2026-088110.0 CRI29.3%
——9Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.65dCVE-2023-3683—29.3%
——9——CVE-2025-0592—29.3%
——9——CVE-2023-3835—29.3%
——9——CVE-2025-23633—29.3%
——9——CVE-2026-164544.3 MED29.3%
——9In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller.
This vulnerability allows an authenticated device to escalate its permissions and bypass the strict boundaries of its assigned updates. Under normal operation, a device should be restricted strictly to the specific firmware artifacts explicitly assigned to it. However, this flaw enables any authenticated device to bypass this restriction and download any firmware artifact within the same tenant.
This is not an authentication bypass; the requesting device must possess valid credentials for its respective tenant. Instead, the issue stems from a flaw in object-level authorization validation.
A related, lower-severity helper issue exists in the listing software modules artifacts metadata endpoint. This endpoint does not enforce assignment checks, enabling an authenticated device to list and enumerate available firmware artifacts, which can facilitate targeted exfiltration using the main download authorization bypass.37dCVE-2026-43530—29.3%
——9——CVE-2023-3945—29.3%
——9——