Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-11109—26.2%
——8——CVE-2026-574256.5 MED26.2%
——8Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.54dCVE-2024-50684—26.2%
——8——CVE-2026-3911—26.2%
——8——CVE-2011-4316—26.2%
——8——CVE-2025-13724—26.2%
——8——CVE-2026-40492—26.2%
——8——CVE-2026-50785.3 MED26.2%
——8Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged log lines, breaking the one-request-per-line structure of access logs and enabling log forgery against downstream log consumers. The built-in combined, common, default, and short formats are affected, as well as any custom format that references :remote-user. Affected versions: morgan 1.2.0 through 1.10.1. Patches: upgrade to morgan 1.11.0, which neutralizes control characters in the :remote-user token output. Workarounds: use a custom format string that does not include :remote-user.55dCVE-2026-141019.6 CRI26.2%
——8Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)75dCVE-2016-8461—26.2%
——8——CVE-2024-7204—26.2%
——8——CVE-2026-23754—26.2%
——8——CVE-2026-516737.5 HIG26.2%
——8Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.14dCVE-2020-8714—26.2%
——8——CVE-2024-28431—26.2%
——8——CVE-2026-23848—26.2%
——8——CVE-2024-34954—26.2%
——8——CVE-2025-9689—26.2%
——8——CVE-2026-57340—26.2%
——8——CVE-2024-6498—26.2%
——8——CVE-2026-179678.8 HIG26.2%
——8Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)43dCVE-2026-578126.5 MED26.2%
——8Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.64dCVE-2026-108988.3 HIG26.2%
——8Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)55dCVE-2001-0993—26.2%
——8——CVE-2018-253917.5 HIG26.2%
——8HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and admin/modul/mod_update/aksi_update.php (module=update&act=hapus) endpoints process deletions without verifying the requester's privileges, enabling removal of pengurus (administrator) and update records.56dCVE-2021-28688—26.2%
——8——CVE-2002-0040—26.2%
——8——CVE-2001-0062—26.2%
——8——CVE-2000-0729—26.2%
——8——CVE-2024-13332—26.2%
——8——CVE-2025-70042—26.2%
——8——CVE-2002-0831—26.2%
——8——CVE-2020-4832—26.2%
——8——CVE-2026-41324—26.2%
——8——CVE-2022-44033—26.2%
——8——CVE-2024-31282—26.2%
——8——CVE-2026-56013—26.2%
——8——CVE-2026-40359—26.2%
——8——CVE-2026-35604—26.2%
——8——CVE-2023-6401—26.2%
——8——