Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,211
- High7,860
- Medium6,394
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-6223—28.0%
——8——CVE-2026-97427.5 HIG28.0%
——8When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.55dCVE-2024-52958—28.0%
——8——CVE-2026-824775.8 MED28.0%
——8In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.15dCVE-2024-9259—28.0%
——8——CVE-2020-6790—28.0%
——8——CVE-2024-10646—28.0%
——8——CVE-2024-36790—28.0%
——8——CVE-2026-64639—28.0%
——8Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.13dCVE-2025-23641—28.0%
——8——CVE-2026-892538.7 HIG28.0%
——8WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings such as http://evil.example/"onmouseover=alert(document.domain)//, while getDonationLink() applies only strip_tags() and does not encode double quotes. plugin/CustomizeUser/actionButton.php echoes the value unencoded into an <a href="..."> attribute, and that button is included from view/modeYoutubeBottom.php on the watch page when the CustomizeUser option allowDonationLink is enabled. An authenticated user who updates their own profile via objects/userUpdate.json.php can therefore break out of the href attribute and inject an event handler that executes JavaScript in the browser of any visitor—including an administrator—who views the attacker's videos and interacts with (for example, hovers over) the donation button. The issue was unfixed at the time of reporting.5dCVE-2024-24446—28.0%
——8——CVE-2024-9654—28.0%
——8——CVE-2024-8284—28.0%
——8——CVE-2026-171978.1 HIG28.0%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.30dCVE-2024-11575—28.0%
——8——CVE-2018-12148—28.0%
——8——CVE-2026-143996.5 MED28.0%
——8Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)76dCVE-2026-48046—28.0%
——8Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.7dCVE-2026-3371210.0 CRI28.0%
——8Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch function exposed inside the isolated-vm sandbox calls Node.js native fetch without the SSRF validation (validateHttpReqUrl) that protects the HTTP Request block. This bypasses all SSRF mitigations added after GHSA-8gq9-rw7v-3jpr. Exploitation of this unauthenticated SSRF vulnerability can lead to cloud credential theft, internal network access and data exfiltration for any self-hosted Typebot deployments and hosted services. This issue has been fixed in version 3.16.0.55dCVE-2025-11192—28.0%
——8——CVE-2024-33073—28.0%
——8——CVE-2025-9656—28.0%
——8——CVE-2026-591025.4 MED28.0%
——8Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by setting a full name containing an HTML payload and triggering an Actions run. When the DEFAULT_SHOW_FULL_NAME option is enabled, the run description is assembled server-side with the user's display name interpolated into an HTML string via a translation function that does not escape its arguments, and the frontend renders the result using a Vue v-html binding, causing script execution for any user who views the affected Actions run page.72dCVE-2026-144026.5 MED28.0%
——8Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)76dCVE-2023-32360—28.0%
——8——CVE-2026-8444—28.0%
——8——CVE-2024-5478—28.0%
——8——CVE-2026-24297—28.0%
——8——CVE-2024-9260—28.0%
——8——CVE-2025-30093—28.0%
——8——CVE-2025-69808—28.0%
——8——CVE-2026-30934—28.0%
——8——CVE-2019-6633—28.0%
——8——CVE-2025-3937—28.0%
——8——CVE-2015-1064—28.0%
——8——CVE-2026-892558.7 HIG28.0%
——8AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab.5dCVE-2024-57348—28.0%
——8——CVE-2022-40489—28.0%
——8——CVE-2017-1125—28.0%
——8——