Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-728568.1 HIG25.7%
——8Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is a no-op and the route is protected only by a general authentication check, so any authenticated user — including a lowest-privilege BASIC app user — can reassign the tenant account-holder (top-privilege admin) email to an attacker-controlled address. The attacker can then use the public password-reset flow to take over the admin account, leading to full administrative access.15dCVE-2024-35174—25.7%
——8——CVE-2023-44434—25.7%
——8——CVE-2026-2633—25.7%
——8——CVE-2026-42036—25.7%
——8——CVE-2022-48508—25.7%
——8——CVE-2026-73065.6 MED25.7%
——8A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token leads to use of hard-coded cryptographic key
. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed publicly and may be used.53dCVE-2026-892128.6 HIG25.7%
——8A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.4dCVE-2026-727866.5 MED25.7%
——8Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword field in the User element save flow.15dCVE-2025-57959—25.7%
——8——CVE-2025-466387.5 HIG25.7%
——8Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).55dCVE-2025-1969—25.7%
——8——CVE-2022-46761—25.7%
——8——CVE-2025-57951—25.7%
——8——CVE-2025-68718—25.7%
——8——CVE-2025-35057—25.7%
——8——CVE-2025-11078—25.7%
——8——CVE-2025-6437—25.7%
——8——CVE-2026-27488—25.7%
——8——CVE-2025-4381—25.7%
——8——CVE-2024-10453—25.7%
——8——CVE-2022-46312—25.7%
——8——CVE-2024-12278—25.7%
——8——CVE-2026-30140—25.7%
——8——CVE-2020-25680—25.7%
——8——CVE-2023-31907—25.7%
——8——CVE-2026-5784—25.7%
——8——CVE-2026-32732—25.7%
——8——CVE-2026-626487.5 HIG25.7%
——8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.7dCVE-2025-7442—25.7%
——8——CVE-2025-52344—25.7%
——8——CVE-2022-48295—25.7%
——8——CVE-2020-7527—25.7%
——8——CVE-2025-15070—25.7%
——8——CVE-2019-14716—25.7%
——8——CVE-2019-12612—25.7%
——8——CVE-2024-56259—25.7%
——8——CVE-2026-25138—25.7%
——8——CVE-2019-20030—25.7%
——8——CVE-2023-25997—25.7%
——8——