Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-21070—25.6%
——8——CVE-2026-6605—25.6%
——8——CVE-2023-35907—25.6%
——8——CVE-2026-828559.8 CRI25.6%
——8@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.15dCVE-2020-8671—25.6%
——8——CVE-2026-54217—25.6%
——8Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An
attacker can send an email containing malicious JavaScript code. When a
user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.8dCVE-2022-45792—25.6%
——8——CVE-2022-3882—25.6%
——8——CVE-2020-3541—25.6%
——8——CVE-2026-150865.9 MED25.6%
——8vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.64dCVE-2024-5451—25.6%
——8——CVE-2023-25526—25.6%
——8——CVE-2024-9853—25.6%
——8——CVE-2025-5266—25.6%
——8——CVE-2024-36469—25.6%
——8——CVE-2023-24914—25.6%
——8——CVE-2025-68150—25.6%
——8——CVE-2024-5611—25.6%
——8——CVE-2023-3286—25.6%
——8——CVE-2021-25171—25.6%
——8——CVE-2026-567775.0 MED25.6%
——8n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task executor module namespace. The issue only affects self-hosted instances where the Python Task Runner is enabled; where N8N_BLOCK_RUNNER_ENV_ACCESS is configured to allow it, this can disclose environment variables accessible to the task runner process.75dCVE-2026-792248.3 HIG25.6%
——8Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)15dCVE-2024-579978.8 HIG25.6%
——8In the Linux kernel, the following vulnerability has been resolved:
wifi: wcn36xx: fix channel survey memory allocation size
KASAN reported a memory allocation issue in wcn->chan_survey
due to incorrect size calculation.
This commit uses kcalloc to allocate memory for wcn->chan_survey,
ensuring proper initialization and preventing the use of uninitialized
values when there are no frames on the channel.42dCVE-2026-82089—25.6%
——8The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.6dCVE-2017-15351—25.6%
——8——CVE-2026-40490—25.6%
——8——CVE-2026-694677.8 HIG25.6%
——8Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.5dCVE-2022-47443—25.6%
——8——CVE-2019-25330—25.6%
——8——CVE-2019-25328—25.6%
——8——CVE-2022-3883—25.6%
——8——CVE-2021-26572—25.6%
——8——CVE-2018-25209—25.6%
——8——CVE-2024-8430—25.6%
——8——CVE-2026-637484.3 MED25.6%
——8SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.55dCVE-2024-10232—25.6%
——8——CVE-2020-4345—25.6%
——8——CVE-2024-28164—25.6%
——8——CVE-2025-13115—25.6%
——8——CVE-2011-2569—25.6%
——8——