Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,384
- High8,714
- Medium6,699
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-874786.5 MED28.3%
——8Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2025-24759—28.3%
——8——CVE-2025-22319—28.3%
——8——CVE-2026-54842—28.3%
——8——CVE-2025-5688—28.3%
——8——CVE-2026-162052.4 LOW28.3%
——8A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.58dCVE-2026-674377.5 HIG28.3%
——8OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.48dCVE-2025-327507.5 HIG28.3%
——8Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.55dCVE-2016-8225—28.3%
——8——CVE-2025-1372—28.3%
——8——CVE-2005-1368—28.3%
——8——CVE-2023-45045—28.3%
——8——CVE-2018-1000532—28.3%
——8——CVE-2025-14511—28.3%
——8——CVE-2023-52199—28.3%
——8——CVE-2025-14651—28.3%
——8——CVE-2025-54719—28.3%
——8——CVE-2024-1965—28.3%
——8——CVE-2023-28863—28.3%
——8——CVE-2026-31858—28.3%
——8——CVE-2026-31939—28.3%
——8——CVE-2025-54288—28.3%
——8——CVE-2026-585455.5 MED28.3%
——8Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.56dCVE-2020-9226—28.3%
——8——CVE-2008-3928—28.3%
——8——CVE-2023-52344—28.3%
——8——CVE-2026-32116—28.3%
——8——CVE-2024-12467—28.3%
——8——CVE-2023-52105—28.3%
——8——CVE-2019-25050—28.3%
——8——CVE-2007-3777—28.3%
——8——CVE-2025-9438—28.3%
——8——CVE-2026-10731—28.3%
——8SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be accessed without prior authentication, allowing unauthenticated attackers to execute arbitrary SQL queries on the backend database. A successful exploit could lead to database enumeration, the unauthorised creation of privileged users, the modification or deletion of critical information, and denial-of-service conditions.56dCVE-2025-5949—28.3%
——8——CVE-2026-283819.6 CRI28.3%
——8The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.78dCVE-2025-15314—28.3%
——8——CVE-2012-0875—28.3%
——8——CVE-2025-9017—28.3%
——8——CVE-2013-2162—28.3%
——8——CVE-2023-41301—28.3%
——8——