Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-56244—25.8%
——8——CVE-2024-49755—25.8%
——8——CVE-2021-31224—25.8%
——8——CVE-2022-45673—25.8%
——8——CVE-2026-102545.3 MED25.8%
——8A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.55dCVE-2016-0234—25.8%
——8——CVE-2026-22046—25.8%
——8——CVE-2020-27790—25.8%
——8——CVE-2026-336845.3 MED25.8%
——8WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStream, and canCreateMeet parameters from user-supplied input and applies them to newly created accounts without verifying that the request was authenticated with a valid APISecret. By self-granting account attributes, attackers can mark their own accounts as email-verified without owning the address (bypassing email-gated functionality) and award themselves upload, streaming, and meeting-creation permissions, circumventing administrator access controls that intentionally restrict these capabilities for new users. This issue has been fixed in version 29.061dCVE-2021-39764—25.8%
——8——CVE-2023-51371—25.8%
——8——CVE-2026-66398—25.8%
——8phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a malicious ZIP file as an attachment, point the updater configuration to its stored path, and extract it into the application root to achieve code execution as the web server user.49dCVE-2025-363598.1 HIG25.8%
——8IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.71dCVE-2023-51374—25.8%
——8——CVE-2026-770899.8 CRI25.8%
——8Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.4dCVE-2026-850439.1 CRI25.8%
——8Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)7dCVE-2021-1390—25.8%
——8——CVE-2023-52195—25.8%
——8——CVE-2020-26599—25.8%
——8——CVE-2023-51693—25.8%
——8——CVE-2023-35711—25.8%
——8——CVE-2023-51492—25.8%
——8——CVE-2019-0145—25.8%
——8——CVE-2006-4413—25.8%
——8——CVE-2000-0031—25.8%
——8——CVE-2024-30107—25.8%
——8——CVE-2026-33378—25.8%
——8——CVE-2022-45668—25.8%
——8——CVE-2026-3409—25.8%
——8——CVE-2025-55797—25.8%
——8——CVE-2023-51689—25.8%
——8——CVE-2024-3801—25.8%
——8——CVE-2026-841318.8 HIG25.8%
——8Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.12dCVE-2026-749468.8 HIG25.8%
——8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.26dCVE-2023-51684—25.8%
——8——CVE-2026-41413—25.8%
——8——CVE-2026-51296—25.8%
——8Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.46dCVE-2024-4222—25.8%
——8——CVE-2026-705597.5 HIG25.8%
——8Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check. Any remote unauthenticated caller who can reach the Dinky HTTP port (8888 by default) receives the full live system configuration (54 entries on a stock v1.2.5 install) with one parameterless GET. Only one credential field (sys.maven.settings.repositoryPassword) has a desensitization handler wired; the other credential-bearing fields (sys.env.settings.dinkyToken, sys.ldap.settings.userPassword, sys.resource.settings.oss.accessKey and secretKey, and sys.dolphinscheduler.settings.token) return in cleartext. A bare install leaks the shipped defaults, including the hardcoded dinkyToken efda1551-7958-4e0f-80a8-dfd107df3e38 and minioadmin/minioadmin OSS keys; once an operator configures LDAP, object storage, or DolphinScheduler through the Settings Center, those live third-party credentials leak from the same endpoint. Because dinkyToken is the sole gate on the sibling POST /download/uploadFromRsByLocal arbitrary file write, this disclosure defeats token rotation as a mitigation for that vulnerability. Affects Dinky v1.2.5 (the current release, 2025-11-05) and the development branch (dev HEAD 63b5a5a), where the affected code is byte-identical.39dCVE-2026-30855—25.8%
——8——