Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11880—25.6%
——8——CVE-2026-596547.5 HIG25.6%
——8Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server.
This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.20dCVE-2025-7714—25.6%
——8——CVE-2024-20907—25.6%
——8——CVE-2023-5006—25.6%
——8——CVE-2020-8334—25.6%
——8——CVE-2024-37459—25.6%
——8——CVE-2025-23206—25.6%
——8——CVE-2020-24222—25.6%
——8——CVE-2025-61943—25.6%
——8——CVE-2010-3580—25.6%
——8——CVE-2026-140118.1 HIG25.6%
——8Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)76dCVE-2026-32808—25.6%
——8——CVE-2020-6785—25.6%
——8——CVE-2026-49493—25.6%
——8——CVE-2024-28793—25.6%
——8——CVE-2024-45678—25.6%
——8——CVE-2025-5082—25.6%
——8——CVE-2026-54665—25.6%
——8——CVE-2026-1181—25.6%
——8——CVE-2024-47378—25.6%
——8——CVE-2025-508616.5 MED25.6%
——8The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.72dCVE-2025-57275—25.6%
——8——CVE-2017-202828.2 HIG25.6%
——8Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/product parameters and malicious product_id values to extract sensitive database information.27dCVE-2026-26732—25.6%
——8——CVE-2026-581778.1 HIG25.6%
——8The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.46dCVE-2024-20950—25.6%
——8——CVE-2026-35036—25.6%
——8——CVE-2022-3650—25.6%
——8——CVE-2026-42233—25.6%
——8——CVE-2026-162638.8 HIG25.6%
——8The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.20dCVE-2011-3982—25.6%
——8——CVE-2023-22076—25.6%
——8——CVE-2024-35687—25.6%
——8——CVE-2025-40659—25.6%
——8——CVE-2024-37920—25.6%
——8——CVE-2026-47680—25.6%
——8The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause source-controller to write fetched object data to paths outside the per-reconciliation working directory. The corruption surface is bounded by source-controller's own and downstream Flux controllers' digest verification: source-controller verifies stored artifact digests during reconciliation and rebuilds on divergence; consumers (kustomize-controller, helm-controller) verify the digest of fetched artifacts and reject mismatches. These checks prevent a manipulated artifact from reaching the cluster, but an attacker can still write files anywhere the source-controller pod has permission to write. Separately, a user with permission to create or update `GitRepository` resources can cause source-controller to test for the existence of paths outside the cloned repository. Because the result is exposed via the resource's status, this allows limited enumeration of file paths on the controller pod. This surface exists only on source-controller v1.6.0 and later, where the sparse-checkout feature was introduced. This vulnerability was fixed in source-controller v1.8.5. There is no in-product workaround. Users should upgrade to a patched version. As a defense-in-depth measure for the GitRepository sparse-checkout surface, a `ValidatingAdmissionPolicy` (or a third-party policy engine such as Kyverno or OPA Gatekeeper) can be deployed to reject `GitRepository` resources whose `.spec.sparseCheckout` entries contain `..` or absolute path segments.6dCVE-2026-137526.0 MED25.6%
——8Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulnerable command paths, causing Snowflake CLI to execute unintended SQL in the context of the user’s Snowflake session. Successful exploitation required crafted values to reach vulnerable parameters, including through socially engineered input, malicious repository configuration, or compromised automation feeding external values into the CLI, and impact is limited by the privileges assigned to the active session. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.77dCVE-2023-29759—25.6%
——8——CVE-2026-32277—25.6%
——8——