Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,210
- High7,840
- Medium6,386
- Low706
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-28805—28.1%
——8——CVE-2026-437926.5 MED28.1%
——8An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.49dCVE-2020-8730—28.1%
——8——CVE-2015-5748—28.1%
——8——CVE-2025-69253—28.1%
——8——CVE-2025-8590—28.1%
——8——CVE-2010-5203—28.1%
——8——CVE-2026-200028.1 HIG28.1%
——8A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability is due to inadequate validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted requests to an affected device. A successful exploit could allow the attacker to obtain full access to the database and read certain files on the underlying operating system. To exploit this vulnerability, the attacker would need valid user credentials.37dCVE-2025-60563—28.1%
——8——CVE-2025-60551—28.1%
——8——CVE-2023-4228—28.1%
——8——CVE-2017-9684—28.1%
——8——CVE-2026-423606.5 MED28.1%
——8A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the rendered field exceeded `[core] max_templated_field_length`: Airflow stringified the structure before redaction, losing the nested key context, and persisted the plaintext value into `rendered_fields`. An authenticated UI/API user with permission to read rendered template fields could harvest secret values intended to be masked. Affects deployments where Dag authors pass structured JSON to operators with nested sensitive keys. This is a variant of `CWE-200` previously addressed for the user-registered `mask_secret()` patterns in CVE-2025-68438; that fix did not cover the nested sensitive-keyword allowlist. Users who already upgraded for CVE-2025-68438 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the nested-key path.57dCVE-2025-58096—28.1%
——8——CVE-2025-9725—28.1%
——8——CVE-2026-53430—28.1%
——8——CVE-2025-61960—28.1%
——8——CVE-2024-6415—28.1%
——8——CVE-2022-4707—28.1%
——8——CVE-2026-140656.5 MED28.1%
——8Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)77dCVE-2026-139266.5 MED28.1%
——8Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2026-139196.5 MED28.1%
——8Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2026-737058.8 HIG28.1%
——8An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary commands on the underlying operating system, leading to complete compromise of the affected system.14dCVE-2026-72018.8 HIG28.1%
——8CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users.56dCVE-2024-34462—28.1%
——8——CVE-2021-28707—28.1%
——8——CVE-2024-20829—28.1%
——8——CVE-2019-25422—28.1%
——8——CVE-2026-3962—28.1%
——8——CVE-2025-61938—28.1%
——8——CVE-2018-253718.2 HIG28.1%
——8mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.55dCVE-2025-4124—28.1%
——8——CVE-2024-22250—28.1%
——8——CVE-2026-614298.5 HIG28.1%
——8PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.65dCVE-2024-27087—28.1%
——8——CVE-2020-8731—28.1%
——8——CVE-2025-60564—28.1%
——8——CVE-2025-15103—28.1%
——8——CVE-2025-59781—28.1%
——8——CVE-2024-25573—28.1%
——8——