Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-10723—26.8%
——8——CVE-2024-12515—26.8%
——8——CVE-2024-29115—26.8%
——8——CVE-2024-11777—26.8%
——8——CVE-2025-3004—26.8%
——8——CVE-2026-28128—26.8%
——8——CVE-2026-44601—26.8%
——8——CVE-2026-159435.5 MED26.8%
——8A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.38dCVE-2024-51484—26.8%
——8——CVE-2026-29856—26.8%
——8——CVE-2026-6035—26.8%
——8——CVE-2023-52175—26.8%
——8——CVE-2018-0275—26.8%
——8——CVE-2025-3005—26.8%
——8——CVE-2026-28559—26.8%
——8——CVE-2024-11896—26.8%
——8——CVE-2012-0420—26.8%
——8——CVE-2020-15100—26.8%
——8——CVE-2023-2179—26.8%
——8——CVE-2019-14715—26.8%
——8——CVE-2026-56697—26.8%
——8——CVE-2026-18526—26.8%
——8HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.19dCVE-2009-1297—26.8%
——8——CVE-2007-2837—26.8%
——8——CVE-2026-32792—26.8%
——8——CVE-2014-8013—26.8%
——8——CVE-2023-45271—26.8%
——8——CVE-2024-27189—26.8%
——8——CVE-2024-0656—26.8%
——8——CVE-2025-12609—26.8%
——8——CVE-2024-51487—26.8%
——8——CVE-2024-51485—26.8%
——8——CVE-2006-0858—26.8%
——8——CVE-2023-41311—26.8%
——8——CVE-2008-3791—26.8%
——8——CVE-2026-94726.3 MED26.8%
——8A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.55dCVE-2026-94736.3 MED26.8%
——8A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.55dCVE-2025-27001—26.8%
——8——CVE-2005-2939—26.8%
——8——CVE-2024-30530—26.8%
——8——