Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,951
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-46672—26.9%
——8——CVE-2019-256888.2 HIG26.9%
——8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents.53dCVE-2026-25889—26.9%
——8——CVE-2026-49346—26.9%
——8——CVE-2025-68003—26.9%
——8——CVE-2019-25575—26.9%
——8——CVE-2026-664508.1 HIG26.9%
——8Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.32dCVE-2025-49327—26.9%
——8——CVE-2026-39590—26.9%
——8——CVE-2025-11618—26.9%
——8——CVE-2022-2275—26.9%
——8——CVE-2026-558776.1 MED26.9%
——8Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested script elements, on* event handlers, or dangerous URL schemes to execute cross-site scripting. This issue is fixed in versions 2.36.1 and 3.2.0.27dCVE-2025-51735—26.9%
——8——CVE-2020-35504—26.9%
——8——CVE-2017-13271—26.9%
——8——CVE-2026-666578.1 HIG26.9%
——8Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.32dCVE-2025-12266—26.9%
——8——CVE-2017-4900—26.9%
——8——CVE-2026-487606.1 MED26.9%
——8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13.63dCVE-2026-34895—26.9%
——8——CVE-2026-138317.5 HIG26.9%
——8Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)76dCVE-2025-49421—26.9%
——8——CVE-2022-45133—26.9%
——8——CVE-2022-4332—26.9%
——8——CVE-2026-450666.1 MED26.9%
——8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers follow WHATWG URL parsing, and because <area href> is checked against the media policy rather than the link policy. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.62dCVE-2025-61488—26.9%
——8——CVE-2026-33544—26.9%
——8——CVE-2025-67111—26.9%
——8——CVE-2008-0996—26.9%
——8——CVE-2026-597106.1 MED26.9%
——8showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.71dCVE-2026-874949.6 CRI26.9%
——8Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)7dCVE-2017-14890—26.9%
——8——CVE-2025-30678—26.9%
——8——CVE-2013-1030—26.9%
——8——CVE-2021-45095—26.9%
——8——CVE-2026-15310—26.9%
——8When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possibly resulting in memory exhaustion.5dCVE-2025-43833—26.9%
——8——CVE-2026-704828.1 HIG26.9%
——8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issued to. Anyone holding an access token minted for any client registered with the same provider could exchange it for an Open WebUI session as that token user, including applications the operator does not control and has never authorized. This issue is fixed in 0.11.0.7dCVE-2026-501438.1 HIG26.9%
——8The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the attacker-controlled webServerMcpPath from an Actor definition without verifying the resulting origin, allowing a malicious Actor publisher to use a userinfo-style authority value to redirect connectMCPClient to a third-party host. The call-actor, fetch-actor-details, and actor-mcp tool-loading paths pass this URL to transports in src/mcp/client.ts that attach the victim Authorization bearer token, exposing the Apify API token and enabling access to Actors, stored data, and billable compute. A victim must invoke or inspect the attacker-controlled Actor. This issue is fixed in version 0.10.11.28dCVE-2019-25576—26.9%
——8——