Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,951
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-450646.1 MED26.9%
——8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.56dCVE-2026-22326—26.9%
——8——CVE-2026-457536.1 MED26.9%
——8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes can leave javascript: URIs unsanitized and enable XSS when the resulting HTML is rendered or a victim submits a form or clicks a button. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.63dCVE-2026-666538.1 HIG26.9%
——8Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.32dCVE-2026-86298.1 HIG26.9%
——8Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.63dCVE-2025-5827—26.9%
——8——CVE-2026-39523—26.9%
——8——CVE-2026-875009.6 CRI26.9%
——8Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)6dCVE-2026-39559—26.9%
——8——CVE-2026-13283—26.9%
——8——CVE-2023-53880—26.9%
——8——CVE-2017-14894—26.9%
——8——CVE-2025-49326—26.9%
——8——CVE-2023-28390—26.9%
——8——CVE-2023-3591—26.9%
——8——CVE-2022-4016—26.9%
——8——CVE-2025-30679—26.9%
——8——CVE-2026-725999.8 CRI26.9%
——8An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.13dCVE-2025-52566—26.9%
——8——CVE-2026-498545.3 MED26.9%
——8Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.62dCVE-2026-49295—26.9%
——8——CVE-2025-67419—26.9%
——8——CVE-2017-7794—26.9%
——8——CVE-2025-5830—26.9%
——8——CVE-2025-3385—26.9%
——8——CVE-2015-3860—26.9%
——8——CVE-2024-28798—26.9%
——8——CVE-2010-0561—26.9%
——8——CVE-2000-0090—26.9%
——8——CVE-2018-5821—26.9%
——8——CVE-2023-35791—26.9%
——8——CVE-2025-47671—26.9%
——8——CVE-2026-41484—26.9%
——8——CVE-2026-159213.1 LOW26.9%
——8Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) parse the node.js mirror's `index.tab` and use each release's LTS codename field as an alias filename without validating it. A malicious, compromised, or man-in-the-middled mirror can return an LTS codename containing path-traversal sequences such as `../../../.bashrc`, causing nvm to write the associated version string to a path outside `$NVM_DIR/alias`. With the default layout (`$NVM_DIR` is `~/.nvm`), this can create or overwrite files in the user's home directory, including shell startup files, which can lead to code execution in a later shell session. Exploitation requires the victim to use a hostile mirror -- via a compromised mirror or CDN, a network man-in-the-middle, or a maliciously configured `NVM_NODEJS_ORG_MIRROR`/`NVM_IOJS_ORG_MIRROR` -- and to run an affected command. Version 0.40.6 validates remote LTS codenames as safe alias filenames and rejects `..` path components when writing alias files.62dCVE-2017-6679—26.9%
——8——CVE-2014-2489—26.9%
——8——CVE-2026-547146.1 MED26.9%
——8Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML RelayState, SAMLResponse, and actionUrl into a Logto-origin auto-submit HTML form in packages/core/src/saml-application/SamlApplication/utils.ts without HTML-attribute escaping. A SAML application flow with a crafted RelayState from GET or POST /api/saml/:id/authn could inject script that runs on the Logto tenant origin after the user completes login. This issue is fixed in version 1.41.0.64dCVE-2024-13626—26.9%
——8——CVE-2026-35602—26.9%
——8——CVE-2022-36561—26.9%
——8——