Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,224
- High7,944
- Medium6,436
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-666009.1 CRI27.4%
——8Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.27dCVE-2024-3249—27.4%
——8——CVE-2026-18756—27.4%
——8HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into submitting the legitimate membership request form, and cause the server to return JavaScript containing attacker-controlled code.19dCVE-2026-24845—27.4%
——8——CVE-2024-9895—27.4%
——8——CVE-2026-19716—27.4%
——8Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.15dCVE-2025-64423—27.4%
——8——CVE-2025-58595—27.4%
——8——CVE-2024-7231—27.4%
——8——CVE-2007-5664—27.4%
——8——CVE-2019-256637.1 HIG27.4%
——8SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.54dCVE-2024-4641—27.4%
——8——CVE-2020-27212—27.4%
——8——CVE-2025-12773—27.4%
——8——CVE-2022-4001—27.4%
——8——CVE-2026-328247.3 HIG27.4%
——8dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply `forwardToUrl` and `redirectUrl` values when triggering password reset or confirmation flows. Those values are then embedded into the outgoing email workflow without host allowlisting. This creates two related abuse paths:
- password reset or confirmation links can be sent to a victim with the token already attached to an attacker-controlled `forwardToUrl`
- after a legitimate password reset completes, the browser is redirected to attacker-controlled `redirectUrl`
In practice, this can be used for phishing, token capture, confirmation hijacking, or steering a victim from a trusted email
into an attacker domain. This is patched in version 26.06.08.57dCVE-2024-44052—27.4%
——8——CVE-2025-22729—27.4%
——8——CVE-2026-637684.3 MED27.4%
——8cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirect visitors from the trusted domain to attacker-controlled URLs for phishing attacks.55dCVE-2026-648308.8 HIG27.4%
——8FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.50dCVE-2020-3702—27.4%
——8——CVE-2026-50742—27.4%
——8——CVE-2025-22619—27.4%
——8——CVE-2024-21864—27.4%
——8——CVE-2023-5873—27.4%
——8——CVE-2016-6910—27.4%
——8——CVE-2006-5706—27.4%
——8——CVE-2024-4160—27.4%
——8——CVE-2023-4839—27.4%
——8——CVE-2001-1378—27.4%
——8——CVE-2026-41143—27.4%
——8——CVE-2024-4445—27.4%
——8——CVE-2021-26100—27.4%
——8——CVE-2024-5576—27.4%
——8——CVE-2023-45372—27.4%
——8——CVE-2015-4874—27.4%
——8——CVE-2025-9025—27.4%
——8——CVE-2018-6433—27.4%
——8——CVE-2025-24003—27.4%
——8——CVE-2020-12933—27.4%
——8——