Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2007-2883—26.5%
——8——CVE-2013-4215—26.5%
——8——CVE-2024-47316—26.5%
——8——CVE-2019-3615—26.5%
——8——CVE-2024-8324—26.5%
——8——CVE-2023-39610—26.5%
——8——CVE-2025-24541—26.5%
——8——CVE-2025-62085—26.5%
——8——CVE-2014-8833—26.5%
——8——CVE-2022-37030—26.5%
——8——CVE-2024-47498—26.5%
——8——CVE-2022-44312—26.5%
——8——CVE-2008-0663—26.5%
——8——CVE-2025-45011—26.5%
——8——CVE-2024-56363—26.5%
——8——CVE-2026-39308—26.5%
——8——CVE-2026-759205.3 MED26.5%
——8phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.14dCVE-2025-40605—26.5%
——8——CVE-2024-4486—26.5%
——8——CVE-2025-1496—26.5%
——8——CVE-2024-47425—26.5%
——8——CVE-2025-61595—26.5%
——8——CVE-2026-736548.5 HIG26.5%
——8Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packages/core/src/v3/runMetadata/operations.ts without rejecting dangerous constructor and prototype path segments. A caller with a normal environment API key can pollute Object.prototype in the shared webapp process, corrupting Prisma queries and Prometheus labels, breaking other tenants' worker authentication, and causing a process-wide denial of service. This issue is fixed in version 4.5.6.32dCVE-2026-861835.3 MED26.5%
——8A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.4dCVE-2024-3230—26.5%
——8——CVE-2026-860796.5 MED26.5%
——8n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An identifier containing path separators or dot segments could select another index or a cluster administration endpoint under the stored Elasticsearch credential. The affected request construction includes packages/nodes-base/nodes/Elastic/Elasticsearch/GenericFunctions.ts and the missing toPathSegment encoding. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.4dCVE-2024-47503—26.5%
——8——CVE-2020-28941—26.5%
——8——CVE-2024-21285—26.5%
——8——CVE-2026-22037—26.5%
——8——CVE-2026-6318—26.5%
——8——CVE-2026-905175.3 MED26.5%
——8A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.1dCVE-2017-5967—26.5%
——8——CVE-2020-3835—26.5%
——8——CVE-2008-0038—26.5%
——8——CVE-1999-0965—26.5%
——8——CVE-2024-34047—26.5%
——8——CVE-2026-501388.1 HIG26.5%
——8goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches the issue.27dCVE-2015-0988—26.5%
——8——CVE-2012-4859—26.5%
——8——