Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,948
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-177604.3 MED27.4%
——8Side-channel information leakage in NoStatePrefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)47dCVE-2026-177694.3 MED27.4%
——8Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)43dCVE-2020-0520—27.4%
——8——CVE-2026-32594—27.4%
——8——CVE-2025-55051—27.4%
——8——CVE-2026-177724.3 MED27.4%
——8Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)43dCVE-2019-14414—27.4%
——8——CVE-2025-39477—27.4%
——8——CVE-2021-39373—27.4%
——8——CVE-2024-9165—27.4%
——8——CVE-2025-696186.5 MED27.4%
——8An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical internal files, potentially leading to arbitrary code execution or exposure of sensitive information.73dCVE-2026-49232—27.4%
——8Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR server.
This only affects users that make their HTTP or RTR server available to untrusted networks.55dCVE-2024-6610—27.4%
——8——CVE-2026-63652—27.4%
——8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.7dCVE-2026-3747—27.4%
——8——CVE-2024-8919—27.4%
——8——CVE-2013-6927—27.4%
——8——CVE-2025-53992—27.4%
——8——CVE-2019-25703—27.4%
——8——CVE-2025-5723—27.4%
——8——CVE-2022-1389—27.4%
——8——CVE-2025-55050—27.4%
——8——CVE-2013-5160—27.4%
——8——CVE-2002-0087—27.4%
——8——CVE-2024-6263—27.4%
——8——CVE-2026-480615.9 MED27.4%
——8Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.6dCVE-2026-177304.3 MED27.4%
——8Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)47dCVE-2024-45368—27.4%
——8——CVE-2026-76164—27.4%
——8AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host.
The crawler can therefore be instructed to make direct HTTP(S) requests to addresses that should not be reachable by application users, including loopback addresses, RFC1918 private networks, link-local addresses, and cloud metadata services such as 169.254.169.254.
Manual crawler tasks bypass the existing domain blacklist because they are assigned a non-zero priority, and ordinary IP literals are classified as web targets and fetched directly rather than through Tor or another proxy. Consequently, an attacker can use the AIL server as a network pivot to access services available from the server's network context.
Responses generated by these requests, including captured HTML, screenshots, and HAR data, can subsequently be accessed through the crawler interface. This makes the SSRF non-blind and may allow an attacker to disclose sensitive internal application data, service information, or cloud instance metadata and credentials.
The patch introduces validation that resolves crawler destinations and rejects URLs resolving to non-global IP addresses, addressing localhost, private-network, and link-local targets.28dCVE-2025-53505—27.4%
——8——CVE-2026-584177.5 HIG27.4%
——8REST API exposes organization membership of private organizations to public21dCVE-2010-20010—27.4%
——8——CVE-2025-53988—27.4%
——8——CVE-2022-509536.2 MED27.4%
——8WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing directory traversal sequences and null bytes to bypass file restrictions and read sensitive files like system configuration.55dCVE-2024-43303—27.4%
——8——CVE-2022-1534—27.4%
——8——CVE-2016-7653—27.4%
——8——CVE-2025-14027—27.4%
——8——CVE-2024-3639—27.4%
——8——CVE-2025-61074—27.4%
——8——