Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,208
- High7,829
- Medium6,383
- Low706
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-22128—28.1%
——8——CVE-2025-54066—28.1%
——8——CVE-2026-822868.6 HIG28.1%
——8gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from attacker-controlled URLs.16dCVE-2025-52430—28.1%
——8——CVE-2025-14885—28.1%
——8——CVE-2024-2740—28.1%
——8——CVE-2005-1915—28.1%
——8——CVE-2020-3455—28.1%
——8——CVE-2024-29796—28.1%
——8——CVE-2026-467376.7 MED28.1%
——8Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.49dCVE-2025-9264—28.1%
——8——CVE-2026-599236.1 MED28.1%
——8Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.3.0.69dCVE-2026-791328.3 HIG28.1%
——8Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)20dCVE-2023-48011—28.1%
——8——CVE-2023-28655—28.1%
——8——CVE-2026-90882.7 LOW28.1%
——8A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.55dCVE-2025-69170—28.1%
——8——CVE-2025-49885—28.1%
——8——CVE-2026-281508.1 HIG28.1%
——8Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.27dCVE-2026-135043.5 LOW28.1%
——8A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.78dCVE-2025-156277.5 HIG28.1%
——8A cryptographic
weakness exists in the Omada adoption protocol.
The protocol relies on hard-coded cryptographic keys to establish trust and
protect authentication exchanges between controllers and managed devices during
device adoption.
An attacker may
be able to impersonate trusted controllers or managed devices and gain access
to sensitive adoption-related communications.40dCVE-2026-13558—28.1%
——8——CVE-2024-8799—28.1%
——8——CVE-2024-8942—28.1%
——8——CVE-2014-4284—28.1%
——8——CVE-2024-37758—28.1%
——8——CVE-2026-466054.3 MED28.1%
——8Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.56dCVE-2025-12626—28.1%
——8——CVE-2018-4313—28.1%
——8——CVE-2006-1656—28.1%
——8——CVE-2025-69164—28.1%
——8——CVE-2026-147913.5 LOW28.1%
——8A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.72dCVE-2004-0256—28.1%
——8——CVE-2026-791098.3 HIG28.1%
——8Improper input validation in Printing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2011-1749—28.1%
——8——CVE-2026-156783.5 LOW28.1%
——8A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.63dCVE-2026-152966.4 MED28.1%
——8The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is a bypass to CVE-2024-10227.65dCVE-2022-23830—28.1%
——8——CVE-2025-61197—28.1%
——8——CVE-2025-69125—28.1%
——8——