Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2009-3706—25.1%
——8——CVE-2023-22119—25.1%
——8——CVE-2024-36674—25.1%
——8——CVE-2024-4485—25.1%
——8——CVE-2026-3659—25.1%
——8——CVE-2024-3667—25.1%
——8——CVE-2025-9914—25.1%
——8——CVE-2024-10504—25.1%
——8——CVE-2025-30726—25.1%
——8——CVE-2016-3764—25.1%
——8——CVE-2025-51411—25.1%
——8——CVE-2013-2188—25.1%
——8——CVE-2000-1162—25.1%
——8——CVE-2024-44930—25.1%
——8——CVE-2024-30481—25.1%
——8——CVE-2016-9356—25.1%
——8——CVE-2009-4193—25.1%
——8——CVE-2026-78446.3 MED25.1%
——8A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Compatible File Service. The manipulation results in missing authentication. The attacker must have access to the local network to execute the attack. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.53dCVE-2026-791364.3 MED25.1%
——8Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)15dCVE-2018-6599—25.0%
——8——CVE-2026-96894.2 MED25.0%
——8A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.26dCVE-2025-3382—25.0%
——8——CVE-2023-0723—25.0%
——8——CVE-2025-62362—25.0%
——8——CVE-2026-163917.5 HIG25.0%
——8Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.53dCVE-2025-8770—25.0%
——8——CVE-2026-453007.4 HIG25.0%
——8The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.54dCVE-2025-56405—25.0%
——8——CVE-2018-10497—25.0%
——8——CVE-2025-26994—25.0%
——8——CVE-2025-57320—25.0%
——8——CVE-2024-49548—25.0%
——8——CVE-2017-11171—25.0%
——8——CVE-2017-11672—25.0%
——8——CVE-2020-3416—25.0%
——8——CVE-2025-49969—25.0%
——8——CVE-2020-5983—25.0%
——8——CVE-2024-48877—25.0%
——8——CVE-2026-592226.5 MED25.0%
——8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returned full UserModelResponse objects for channel members, including settings.ui.toolServers[].key and webhook configuration, allowing a normal channel participant to retrieve other users’ sensitive settings. This issue is fixed in version 0.10.0.67dCVE-2025-30171—25.0%
——8——