Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-6505—26.3%
——8——CVE-2026-54299—26.3%
——8——CVE-2024-32701—26.3%
——8——CVE-2026-47190—26.3%
——8——CVE-2020-0379—26.3%
——8——CVE-2023-32604—26.3%
——8——CVE-2021-40647—26.3%
——8——CVE-2024-27986—26.3%
——8——CVE-2023-32537—26.3%
——8——CVE-2021-44189—26.3%
——8——CVE-2025-71281—26.3%
——8——CVE-2024-11144—26.3%
——8——CVE-2026-89677.5 HIG26.3%
——8Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.54dCVE-2025-32119—26.3%
——8——CVE-2025-41450—26.3%
——8——CVE-2025-13175—26.3%
——8——CVE-2023-32391—26.3%
——8——CVE-2026-851849.1 CRI26.3%
——8@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as authentication or authorization, is skipped. An unauthenticated network attacker can use this to bypass path-based access controls in a Fastify application that relies on middie for those controls. Users should upgrade to @fastify/middie 9.3.4 or later.7dCVE-2023-27754—26.3%
——8——CVE-2025-68431—26.3%
——8——CVE-2006-1844—26.3%
——8——CVE-2021-40424—26.3%
——8——CVE-2025-3425—26.3%
——8——CVE-2024-20103—26.3%
——8——CVE-2024-34140—26.3%
——8——CVE-2024-4756—26.3%
——8——CVE-2024-7052—26.3%
——8——CVE-2022-33315—26.3%
——8——CVE-2006-3669—26.3%
——8——CVE-2026-583713.1 LOW26.3%
——8SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application/javascript in the shared writeJson helper (weed/server/common.go), with no callback-name validation, no X-Content-Type-Options: nosniff header, and no CORS allow-list. Every JSON endpoint that uses writeJson - including the unauthenticated master endpoints /dir/status, /dir/lookup and /cluster/status, the volume server /status, and the filer directory listing, all reachable in the default configuration (no -whiteList, no security.toml, bound to 0.0.0.0) - can therefore be loaded cross-origin via a script tag with a chosen callback, letting a third-party web page read cluster topology, volume server URLs and gRPC ports, file identifiers, and directory listings. Because the callback string is reflected at the start of the body and no nosniff header is sent, MIME-sniffing clients may also interpret the reflected content as HTML.63dCVE-2026-54494—26.3%
——8Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE, which treats NAT64 64:ff9b::/96 and 6to4 2002::/16 wrappers of private, loopback, or link-local IPv4 addresses as public. An authenticated user can place such an address in a podcast RSS <enclosure url> and reach app/Values/Podcast/EpisodePlayable.php through EpisodePlayable::createForEpisode(), where isSafeUrl() accepts the target and Http::sink($file)->get($url) fetches it. On a host with NAT64 or 6to4 routing, Koel can request internal services or cloud metadata and return the response body to the user. This issue is fixed in version 9.7.16dCVE-2026-21722—26.3%
——8——CVE-2024-37624—26.3%
——8——CVE-2026-555125.3 MED26.3%
——8nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map for 10m. Expired states are swept lazily, but there is no rate limit or maximum live-state cap on the allocation path. An unauthenticated remote client can therefore grow OIDC.states for the full state TTL, bounded by request throughput rather than by configured auth rate limits. This issue has been patched in version 0.5.0.6dCVE-2026-437358.1 HIG26.3%
——8The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.29dCVE-2024-11019—26.3%
——8——CVE-2025-61819—26.3%
——8——CVE-2024-3494—26.3%
——8——CVE-2024-2250—26.3%
——8——CVE-2024-3005—26.3%
——8——