Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-0699—29.2%
——9——CVE-2026-49738—29.2%
——9The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be incorrectly accepted as valid when the project root was /var/www/html. Administrator users with access to the File Abstraction Layer were able to create new file storage definitions pointing to directories outside the project root, bypassing this path check. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.57dCVE-2026-576986.5 MED29.2%
——9Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.66dCVE-2026-603258.0 HIG29.2%
——9Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).52dCVE-2024-1078—29.2%
——9——CVE-2004-0622—29.2%
——9——CVE-2024-4286—29.2%
——9——CVE-2026-713199.6 CRI29.2%
——9Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and openInEditor() methods do not enforce the ensureDevAuthToken check that the other mutating methods use. openInEditor() reads the persisted behavior.openInEditor value and passes it to the launch-editor package, which spawns it as a child process. That value is settable through the equally unauthenticated updateOptions(). An attacker who can reach the HMR port can therefore chain updateOptions('behavior', { openInEditor: '<command>' }) then openInEditor('<any-existing-file>') to execute an arbitrary program on the developer's machine. This issue is fixed in 3.3.1.9dCVE-2019-20480—29.2%
——9——CVE-2018-0359—29.2%
——9——CVE-2025-12845—29.2%
——9——CVE-2026-38949—29.2%
——9——CVE-2019-0061—29.2%
——9——CVE-2026-791758.3 HIG29.2%
——9Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)21dCVE-2026-40289—29.2%
——9——CVE-2025-70093—29.2%
——9——CVE-2023-37527—29.2%
——9——CVE-2023-47771—29.2%
——9——CVE-2024-50965—29.2%
——9——CVE-2025-7938—29.2%
——9——CVE-2008-0967—29.2%
——9——CVE-2014-8834—29.2%
——9——CVE-2026-766937.0 HIG29.2%
——9A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.1dCVE-2017-12314—29.2%
——9——CVE-2006-7204—29.2%
——9——CVE-2012-0871—29.2%
——9——CVE-2021-32463—29.2%
——9——CVE-2017-15837—29.2%
——9——CVE-2005-1916—29.2%
——9——CVE-2021-27758—29.2%
——9——CVE-2024-26271—29.2%
——9——CVE-2026-664446.5 MED29.2%
——9Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.34dCVE-2026-335766.5 MED29.1%
——9OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subsequently rejected.55dCVE-2025-2103—29.2%
——9——CVE-2025-9410—29.2%
——9——CVE-2026-7046—29.2%
——9——CVE-2008-1597—29.2%
——9——CVE-2024-3299—29.2%
——9——CVE-2026-45843—29.2%
——9——CVE-2024-1028—29.2%
——9——