Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,210
- High7,846
- Medium6,388
- Low707
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-8731—28.1%
——8——CVE-2025-60564—28.1%
——8——CVE-2022-4707—28.1%
——8——CVE-2026-140236.5 MED28.1%
——8Insufficient validation of untrusted input in SanitizerAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2026-626459.8 CRI28.1%
——8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.8dCVE-2017-9684—28.1%
——8——CVE-2026-53430—28.1%
——8——CVE-2026-423606.5 MED28.1%
——8A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the rendered field exceeded `[core] max_templated_field_length`: Airflow stringified the structure before redaction, losing the nested key context, and persisted the plaintext value into `rendered_fields`. An authenticated UI/API user with permission to read rendered template fields could harvest secret values intended to be masked. Affects deployments where Dag authors pass structured JSON to operators with nested sensitive keys. This is a variant of `CWE-200` previously addressed for the user-registered `mask_secret()` patterns in CVE-2025-68438; that fix did not cover the nested sensitive-keyword allowlist. Users who already upgraded for CVE-2025-68438 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the nested-key path.57dCVE-2025-9725—28.1%
——8——CVE-2026-139246.5 MED28.1%
——8Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)77dCVE-2026-178479.6 CRI28.1%
——8Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)44dCVE-2021-26930—28.1%
——8——CVE-2025-60552—28.1%
——8——CVE-2025-58096—28.1%
——8——CVE-2025-60562—28.1%
——8——CVE-2018-253718.2 HIG28.1%
——8mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.55dCVE-2025-61938—28.1%
——8——CVE-2025-4124—28.1%
——8——CVE-2024-22250—28.1%
——8——CVE-2026-614298.5 HIG28.1%
——8PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.65dCVE-2023-24048—28.1%
——8——CVE-2020-10684—28.1%
——8——CVE-2025-30958—28.1%
——8——CVE-2012-10012—28.1%
——8——CVE-2025-29485—28.1%
——8——CVE-2024-53472—28.1%
——8——CVE-2012-5820—28.1%
——8——CVE-2026-100258.2 HIG28.1%
——8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.37dCVE-2026-767938.1 HIG28.1%
——8The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.24dCVE-2024-8414—28.1%
——8——CVE-2026-694597.8 HIG28.1%
——8Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.7dCVE-2024-41663—28.1%
——8——CVE-2026-48517—28.1%
——8——CVE-2024-52312—28.1%
——8——CVE-2026-42434—28.1%
——8——CVE-2025-21704—28.1%
——8——CVE-2016-0405—28.1%
——8——CVE-2021-36158—28.1%
——8——CVE-2020-7312—28.1%
——8——CVE-2026-35599—28.1%
——8——