Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,223
- High7,904
- Medium6,420
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-27951—27.8%
——8——CVE-2026-197177.5 HIG27.8%
——8The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site.21dCVE-2026-789706.5 MED27.8%
——8JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of all users, including real names, phone numbers, email addresses, employee numbers, and role definitions, due to missing fine-grained permission checks and incomplete data desensitization.8dCVE-2026-40890—27.8%
——8——CVE-2025-10395—27.8%
——8——CVE-2024-8846—27.8%
——8——CVE-2022-36484—27.8%
——8——CVE-2004-0015—27.8%
——8——CVE-1999-1536—27.8%
——8——CVE-2002-0356—27.8%
——8——CVE-2022-36488—27.8%
——8——CVE-2016-15028—27.8%
——8——CVE-2023-5001—27.8%
——8——CVE-2026-535288.8 HIG27.8%
——8LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset directory. This could allow sensitive local files, such as the application database, to become downloadable as page assets. Users should update to version 0.10.1 or greater. As an additional mitigation, operators should ensure that the LeafWiki process runs with the least privileges necessary and does not have filesystem access to sensitive files outside the application’s required directories. Until a patch is applied, operators may reduce risk by restricting editor access to trusted users only and by limiting the filesystem permissions of the LeafWiki process.7dCVE-2026-35417—27.8%
——8——CVE-2023-45777—27.8%
——8——CVE-2026-738966.5 MED27.8%
——8Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).19dCVE-2026-875248.3 HIG27.8%
——8Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)6dCVE-2026-1197—27.8%
——8——CVE-2023-26398—27.8%
——8——CVE-2023-46605—27.8%
——8——CVE-2026-139388.8 HIG27.8%
——8Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)76dCVE-2023-26371—27.8%
——8——CVE-2026-660065.3 MED27.8%
——8lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.48dCVE-2025-1365—27.8%
——8——CVE-2022-34251—27.8%
——8——CVE-2026-201247.7 HIG27.8%
——8A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.41dCVE-2023-29280—27.8%
——8——CVE-2026-140439.6 CRI27.8%
——8Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)76dCVE-2025-54852—27.8%
——8——CVE-2024-8892—27.8%
——8——CVE-2026-141209.6 CRI27.8%
——8Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)76dCVE-2017-12351—27.8%
——8——CVE-2026-739955.4 MED27.8%
——8Subscriber Broken Authentication in User Registration <= 5.2.6 versions.27dCVE-2024-52367—27.8%
——8——CVE-2025-49012—27.8%
——8——CVE-2025-47527—27.8%
——8——CVE-2026-140559.6 CRI27.8%
——8Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)77dCVE-2024-46881—27.8%
——8——CVE-2026-140379.6 CRI27.8%
——8Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)77d