Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-55891—25.7%
——8——CVE-2026-688716.5 MED25.7%
——8The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.29dCVE-2025-12426—25.7%
——8——CVE-2025-54320—25.7%
——8——CVE-2025-32299—25.7%
——8——CVE-2026-749838.1 HIG25.7%
——8Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.27dCVE-2026-41386—25.7%
——8——CVE-2018-2005—25.7%
——8——CVE-2005-0576—25.7%
——8——CVE-2026-688726.5 MED25.7%
——8The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.29dCVE-2025-565627.5 HIG25.7%
——8An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.72dCVE-2021-28704—25.7%
——8——CVE-2017-5701—25.7%
——8——CVE-2024-5076—25.7%
——8——CVE-2022-22371—25.7%
——8——CVE-2024-26350—25.7%
——8——CVE-2024-46078—25.7%
——8——CVE-2024-31198—25.7%
——8——CVE-2025-25208—25.7%
——8——CVE-2026-619679.8 CRI25.7%
——8Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.32dCVE-2021-4041—25.7%
——8——CVE-2024-6669—25.7%
——8——CVE-2024-31197—25.7%
——8——CVE-2023-6323—25.7%
——8——CVE-2025-634015.5 MED25.7%
——8Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives72dCVE-2026-3355—25.7%
——8——CVE-2026-27649—25.7%
——8——CVE-2025-634025.5 MED25.7%
——8An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests72dCVE-2026-364996.5 MED25.7%
——8A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion.55dCVE-2024-40547—25.7%
——8——CVE-2007-4270—25.7%
——8——CVE-2025-3257—25.7%
——8——CVE-2025-26976—25.7%
——8——CVE-2024-49321—25.7%
——8——CVE-2026-109806.5 MED25.7%
——8Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)55dCVE-2025-6848—25.7%
——8——CVE-2023-44332—25.7%
——8——CVE-2007-5555—25.7%
——8——CVE-2026-1352—25.7%
——8——CVE-2024-35224—25.7%
——8——