Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,204
- High7,819
- Medium6,373
- Low706
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1691—28.2%
——8——CVE-2024-37800—28.2%
——8——CVE-2025-13538—28.2%
——8——CVE-2024-24562—28.2%
——8——CVE-2026-484157.6 HIG28.2%
——8Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.20dCVE-2025-6721—28.2%
——8——CVE-2025-44958—28.2%
——8——CVE-2024-43397—28.2%
——8——CVE-2024-4190—28.2%
——8——CVE-2019-11101—28.2%
——8——CVE-2023-23853—28.2%
——8——CVE-2026-34241—28.2%
——8——CVE-2023-318685.4 MED28.2%
——8Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. The major one requires the user to be authenticated with a common account, he can then target an Administrator. All others endpoints need the malicious user to be authenticated as an Administrator. Therefore, the impact is diminished.70dCVE-2025-8911—28.2%
——8——CVE-2025-8910—28.2%
——8——CVE-2026-28039—28.2%
——8——CVE-2024-43926—28.2%
——8——CVE-2022-21823—28.2%
——8——CVE-2026-582144.3 MED28.2%
——8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.65dCVE-2026-3914—28.2%
——8——CVE-2024-37625—28.2%
——8——CVE-2026-480836.5 MED28.2%
——8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout log, interprets newline characters as real line breaks, and enforces no size or rate limits. Three independent abuse modes follow: log injection (forge log lines that look like legitimate system events), log volume DoS (saturate the logging pipeline at sustained 100+ requests per second of small messages), and oversized-payload submission (100 KB payloads accepted; larger sizes not tested). The most operationally damaging mode is log injection. An attacker can inject lines that an operator scanning logs would mistake for real system errors, mask their own activity behind fake noise, or pollute SIEM alerting rules with crafted false positives. A line such as `[error]: injected admin error` injected from an unauthenticated source is indistinguishable from the application's own error output once written to disk. Version 1.0.2 fixes the issue.8dCVE-2019-3715—28.2%
——8——CVE-2023-22037—28.2%
——8——CVE-2016-8227—28.2%
——8——CVE-2024-5968—28.2%
——8——CVE-2023-23457—28.2%
——8——CVE-2023-6391—28.2%
——8——CVE-2025-50167—28.2%
——8——CVE-2023-3576—28.2%
——8——CVE-2025-1813—28.2%
——8——CVE-2020-24158—28.2%
——8——CVE-2014-5260—28.2%
——8——CVE-2024-12409—28.2%
——8——CVE-2025-7342—28.2%
——8——CVE-2023-30529—28.2%
——8——CVE-2025-2414—28.2%
——8——CVE-2025-46964—28.2%
——8——CVE-2026-3916—28.2%
——8——CVE-2025-13764—28.2%
——8——