Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-28848—26.3%
——8——CVE-2024-42794—26.3%
——8——CVE-2026-627887.0 HIG26.3%
——8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.33dCVE-2020-5908—26.3%
——8——CVE-2024-4035—26.3%
——8——CVE-2021-32556—26.3%
——8——CVE-2023-7030—26.3%
——8——CVE-2026-26722—26.3%
——8——CVE-2026-89667.5 HIG26.3%
——8Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.54dCVE-2024-11092—26.3%
——8——CVE-2026-64655—26.3%
——8GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow flag values without escaping regex metacharacters, so a user-supplied repository or workflow name is treated as a regular expression rather than a literal string. Because GitHub permits characters such as `.` in organization, repository, and workflow path names and `.` is a regex wildcard, an attacker can register a lookalike name (for example github/artifact.attestations-workflows) that satisfies a matcher intended for a different trusted signer (github/artifact-attestations-workflows), bypassing the intended Sigstore attestation verification. Exploitation requires the attacker to create a plausible lookalike repository and produce valid attestations from it, which could undermine supply chain verification for CI/CD pipelines or policy gates that pin trust to a specific signing workflow. This issue is fixed in version 2.97.0.5dCVE-2026-713667.7 HIG26.3%
——8A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.18dCVE-2024-4014—26.3%
——8——CVE-2025-11044—26.3%
——8——CVE-2023-32605—26.3%
——8——CVE-2022-41211—26.3%
——8——CVE-2026-30831—26.3%
——8——CVE-2020-29069—26.3%
——8——CVE-2023-1221—26.3%
——8——CVE-2020-8703—26.3%
——8——CVE-2025-48141—26.3%
——8——CVE-2026-73598.8 HIG26.3%
——8Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)54dCVE-2026-731977.5 HIG26.3%
——8A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.21dCVE-2024-13544—26.3%
——8——CVE-2025-22129—26.3%
——8——CVE-2024-47646—26.3%
——8——CVE-2025-53891—26.3%
——8——CVE-2026-704928.7 HIG26.3%
——8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} rather than as text, so script in the message runs in the browser of whoever views it, including shared chats and channels. The viewer's session token in localStorage can be stolen, and an administrator viewer can have their account taken over. This issue is fixed in 0.11.0.7dCVE-2026-46808—26.3%
——8——CVE-2025-67965—26.3%
——8——CVE-2025-10293—26.3%
——8——CVE-2026-848874.3 MED26.3%
——8A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.12dCVE-2024-6766—26.3%
——8——CVE-2026-41685—26.3%
——8——CVE-2025-8859—26.3%
——8——CVE-2025-26489—26.3%
——8——CVE-2026-731987.5 HIG26.3%
——8A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.22dCVE-2025-53592—26.3%
——8——CVE-2026-30098.1 HIG26.3%
——8A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.1dCVE-2026-73548.8 HIG26.3%
——8Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)54d