Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-39528—26.6%
——8——CVE-2010-0310—26.6%
——8——CVE-2026-421427.1 HIG26.6%
——8TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data (sheet names, IDs, column headers). Version 3.17.0 fixes the issue.6dCVE-2024-32584—26.6%
——8——CVE-2025-11612—26.6%
——8——CVE-2023-50829—26.6%
——8——CVE-2025-31896—26.6%
——8——CVE-2017-5625—26.6%
——8——CVE-2025-14150—26.6%
——8——CVE-2024-22200—26.6%
——8——CVE-2024-42699—26.6%
——8——CVE-2023-5194—26.6%
——8——CVE-2025-10409—26.6%
——8——CVE-2023-6958—26.6%
——8——CVE-2026-598088.8 HIG26.6%
——8AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the videos_id parameter, then use that hash in an unauthenticated request to gain administrative session access and modify system configuration.22dCVE-2026-8443—26.6%
——8——CVE-2025-6248—26.6%
——8——CVE-2026-83778.2 HIG26.6%
——8Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations.
This issue affects Access Control System (GKS): before Version 2.71dCVE-2024-1568—26.6%
——8——CVE-2025-11613—26.6%
——8——CVE-2020-12144—26.6%
——8——CVE-2026-906023.5 LOW26.6%
——8A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.1dCVE-2022-2346—26.6%
——8——CVE-2025-2406—26.6%
——8——CVE-2025-10400—26.6%
——8——CVE-2023-49292—26.6%
——8——CVE-2022-34696—26.6%
——8——CVE-2023-51524—26.6%
——8——CVE-2007-2360—26.6%
——8——CVE-2025-12314—26.6%
——8——CVE-2025-63588—26.6%
——8——CVE-2019-3584—26.6%
——8——CVE-2025-7590—26.6%
——8——CVE-2025-39493—26.6%
——8——CVE-2025-49914—26.6%
——8——CVE-2022-21768—26.6%
——8——CVE-2025-30317—26.6%
——8——CVE-2013-1726—26.6%
——8——CVE-2020-14754—26.6%
——8——CVE-2025-11611—26.6%
——8——