Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,951
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-736128.1 HIG26.9%
——8File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.7dCVE-2021-33448—26.9%
——8——CVE-2025-53470—26.9%
——8——CVE-2025-7582—26.9%
——8——CVE-2012-1796—26.9%
——8——CVE-2025-7479—26.9%
——8——CVE-2026-35305—26.9%
——8——CVE-2026-33237—26.9%
——8——CVE-2026-506808.2 HIG26.9%
——8Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.56dCVE-2026-770719.8 CRI26.9%
——8n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intended single-row operation into full-table disclosure, deletion, or modification.14dCVE-2026-751038.8 HIG26.9%
——8Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.29dCVE-2025-7581—26.9%
——8——CVE-2024-1847—26.9%
——8——CVE-2024-31082—26.9%
——8——CVE-2025-52041—26.9%
——8——CVE-2026-53453—26.9%
——8Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected surfaces included the backend API, upload API, stream routes, terminal WebSocket, Blueprint Studio WebSocket subscriptions, call_service, render_template, global_replace, file and stream access paths, upload handling, and terminal helpers. A non-admin user could invoke arbitrary Home Assistant services, expose Home Assistant state through templates, modify configuration files, access streamed or downloaded configuration content, upload files, or reach terminal-related helpers. These actions could compromise the confidentiality, integrity, and availability of the Home Assistant installation. This issue is fixed in version 2.5.2.7dCVE-2024-36523—26.9%
——8——CVE-2025-6914—26.9%
——8——CVE-2025-7163—26.9%
——8——CVE-2025-6910—26.9%
——8——CVE-2024-12736—26.9%
——8——CVE-2026-7980—26.9%
——8——CVE-2024-8455—26.9%
——8——CVE-2025-48752—26.9%
——8——CVE-2024-7161—26.9%
——8——CVE-2025-7561—26.9%
——8——CVE-2025-7161—26.9%
——8——CVE-2026-40978—26.9%
——8——CVE-2026-7987—26.9%
——8——CVE-2025-7556—26.9%
——8——CVE-2025-7212—26.9%
——8——CVE-2025-7560—26.9%
——8——CVE-2025-48755—26.9%
——8——CVE-2023-50803—26.9%
——8——CVE-2025-7557—26.9%
——8——CVE-2018-20908—26.9%
——8——CVE-2026-39559—26.9%
——8——CVE-2026-450666.1 MED26.9%
——8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers follow WHATWG URL parsing, and because <area href> is checked against the media policy rather than the link policy. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.62dCVE-2019-256888.2 HIG26.9%
——8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents.53dCVE-2019-25575—26.9%
——8——