Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,948
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-158768.8 HIG27.4%
——8An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php, alertlog.inc.php, arp-search.inc.php, as-selection.inc.php, bills.inc.php, device_mibs.inc.php, device_oids.inc.php, edit-ports.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, mibs.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, tnmsneinfo.inc.php, and toner.inc.php (in includes/html/table).13dCVE-2021-2286—27.4%
——8——CVE-2024-10176—27.4%
——8——CVE-2026-458117.5 HIG27.4%
——8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.51dCVE-2026-53540—27.4%
——8——CVE-2026-694035.5 MED27.4%
——8Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.8dCVE-2012-0539—27.4%
——8——CVE-2024-10705—27.4%
——8——CVE-2004-0770—27.4%
——8——CVE-2013-5145—27.4%
——8——CVE-2026-341018.8 HIG27.4%
——8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23dCVE-2018-18466—27.4%
——8——CVE-2022-24401—27.4%
——8——CVE-2024-8989—27.4%
——8——CVE-2026-517565.9 MED27.4%
——8Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.15dCVE-2026-341028.8 HIG27.4%
——8Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23dCVE-2024-8915—27.4%
——8——CVE-2024-9642—27.4%
——8——CVE-2020-8578—27.4%
——8——CVE-2024-12835—27.4%
——8——CVE-2022-20865—27.4%
——8——CVE-2026-736569.9 CRI27.4%
——8Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId predicate. A caller with a valid API key for one project can submit another project's deployment identifier, link an attacker-owned background worker to the victim deployment, and move the victim deployment from BUILDING to DEPLOYING. This issue is fixed in version 4.5.6.33dCVE-2024-10268—27.4%
——8——CVE-2025-49893—27.4%
——8——CVE-2026-341048.8 HIG27.4%
——8Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform error-based SQL injection to extract database contents.23dCVE-2026-51290—27.4%
——8Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.47dCVE-2020-6015—27.4%
——8——CVE-2022-38059—27.4%
——8——CVE-2026-325528.5 HIG27.4%
——8Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.27dCVE-2020-8590—27.4%
——8——CVE-2025-11159—27.4%
——8——CVE-2024-4095—27.4%
——8——CVE-2024-45050—27.4%
——8——CVE-2024-13839—27.4%
——8——CVE-2026-582094.3 MED27.4%
——8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.65dCVE-2026-341675.0 MED27.4%
——8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property without Livewire's #[Locked] attribute. It loads activities via Activity::find($this->activityId) with no authorization or team scoping. Activity IDs are auto-incrementing integers. Any authenticated user can enumerate activity records across all teams and read the full command output from remote SSH processes, which may include secrets, configuration files, and infrastructure details. This issue is fixed in version 4.0.0-beta.471.70dCVE-2024-4342—27.4%
——8——CVE-2023-38211—27.4%
——8——CVE-2025-12419—27.4%
——8——CVE-2024-55885—27.4%
——8——