Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,948
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-69135—27.4%
——8——CVE-2024-12561—27.4%
——8——CVE-2024-32815—27.4%
——8——CVE-2025-57968—27.4%
——8——CVE-2026-467004.3 MED27.4%
——8Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated non-admin BASIC user in OpenID multi-user deployments can probe the secrets store and learn which admin-managed bank-sync integrations have been configured, including simplefin_accessKey, pluggyai_clientSecret, pluggyai_itemIds, and the gocardless secrets. This issue is fixed in version 26.6.0.70dCVE-2009-1883—27.4%
——8——CVE-2011-1016—27.4%
——8——CVE-1999-1439—27.4%
——8——CVE-2024-33630—27.4%
——8——CVE-2020-14019—27.4%
——8——CVE-2026-517395.9 MED27.4%
——8Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.15dCVE-2024-27949—27.4%
——8——CVE-2024-9217—27.4%
——8——CVE-2026-692507.5 HIG27.4%
——8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without authentication, triggered outbound POST requests to an attacker-controlled server, reflected the full remote response body to the caller through tokenInfo, and sent client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body. This issue is fixed in version 3.1.3.2dCVE-2024-8103—27.4%
——8——CVE-2025-6072—27.4%
——8——CVE-2022-1890—27.4%
——8——CVE-2025-34200—27.4%
——8——CVE-2024-49248—27.4%
——8——CVE-2026-759277.2 HIG27.4%
——8The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15 `manage_capabilities_*` capabilities — including `manage_capabilities`, `manage_capabilities_roles`, `manage_capabilities_settings`, and `manage_capabilities_backup` — via a hard-coded `$eligible_roles = ['administrator', 'editor']` assignment that runs automatically on the first `admin_init` after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with `cme_`, `capsman`, `pp_capabilities`, or `presspermit` via `update_option()`. The escalation stops short of full Administrator access, as WordPress's `map_meta_cap` layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on `manage_capabilities_*` capabilities remains fully accessible.5dCVE-2016-6719—27.4%
——8——CVE-2024-6391—27.4%
——8——CVE-2026-554624.3 MED27.4%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.64dCVE-2020-37065—27.4%
——8——CVE-2023-53918—27.4%
——8——CVE-2026-177674.3 MED27.4%
——8Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)43dCVE-2026-100599.1 CRI27.4%
——8A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.8dCVE-2014-8610—27.4%
——8——CVE-2024-51989—27.4%
——8——CVE-2025-5722—27.4%
——8——CVE-2024-6532—27.4%
——8——CVE-2024-4821—27.4%
——8——CVE-2026-40252—27.4%
——8——CVE-2024-30549—27.4%
——8——CVE-2022-0184—27.4%
——8——CVE-2023-4588—27.4%
——8——CVE-2025-6185—27.4%
——8——CVE-2025-66238—27.4%
——8——CVE-2020-11827—27.4%
——8——CVE-2026-56317—27.4%
——8——