Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-3797—29.0%
——9——CVE-2014-0018—29.0%
——9——CVE-2013-6436—29.0%
——9——CVE-2005-4133—29.0%
——9——CVE-2014-2277—29.0%
——9——CVE-2024-21002—29.0%
——9——CVE-2024-22226—29.0%
——9——CVE-2024-11928—29.0%
——9——CVE-2023-46822—29.0%
——9——CVE-2026-621476.5 MED29.0%
——9The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.66dCVE-2024-29142—29.0%
——9——CVE-2023-46309—29.0%
——9——CVE-2024-11434—29.0%
——9——CVE-2022-33258—29.0%
——9——CVE-2026-630996.5 MED29.0%
——9TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the missing organization-scoped authorization check in AttachmentSrv.visible, which is implemented as a pass-through traversal, to download arbitrary attachments.62dCVE-2022-25731—29.0%
——9——CVE-2026-42984.3 MED29.0%
——9The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all customized privacy policy content including cookie notices, Google Analytics policies, Facebook policies, and YouTube policies to their default values.70dCVE-2023-45746—29.0%
——9——CVE-2026-9184—29.0%
——9——CVE-2026-736227.5 HIG29.0%
——9GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.14dCVE-2024-52463—29.0%
——9——CVE-2022-25726—29.0%
——9——CVE-2024-11363—29.0%
——9——CVE-2024-39033—29.0%
——9——CVE-2023-5615—29.0%
——9——CVE-2026-45675—29.0%
——9——CVE-2023-0593—29.0%
——9——CVE-2024-58293—29.0%
——9——CVE-2007-5907—29.0%
——9——CVE-2023-27149—29.0%
——9——CVE-2013-2976—29.0%
——9——CVE-2024-52454—29.0%
——9——CVE-2022-25747—29.0%
——9——CVE-2022-33291—29.0%
——9——CVE-2024-52460—29.0%
——9——CVE-2023-35024—29.0%
——9——CVE-2024-11709—29.0%
——9——CVE-2024-11686—29.0%
——9——CVE-2024-29091—29.0%
——9——CVE-2024-52462—29.0%
——9——