Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-28492—25.0%
——8——CVE-2025-3149—25.0%
——8——CVE-2015-5045—25.0%
——8——CVE-2025-27162—25.0%
——8——CVE-2025-10988—25.0%
——8——CVE-2024-20929—25.0%
——8——CVE-2025-10278—25.0%
——8——CVE-2026-67402—25.0%
——8An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.6dCVE-2026-1487—25.0%
——8——CVE-2022-44320—25.0%
——8——CVE-2024-28279—25.0%
——8——CVE-2026-215758.0 HIG25.0%
——8This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.
Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:
* Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13
See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives).
This vulnerability was reported via our Bug Bounty program.36dCVE-2024-3926—25.0%
——8——CVE-2022-44315—25.0%
——8——CVE-2026-19539—25.0%
——8Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission.14dCVE-2026-55527—25.0%
——8——CVE-2026-19316—25.0%
——8A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.12dCVE-2025-10275—25.0%
——8——CVE-2025-10277—25.0%
——8——CVE-2024-4379—25.0%
——8——CVE-2025-39590—25.0%
——8——CVE-2001-1383—25.0%
——8——CVE-2026-19314—25.0%
——8An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.12dCVE-2001-0905—25.0%
——8——CVE-2026-749987.2 HIG25.0%
——8In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.7dCVE-2024-2092—25.0%
——8——CVE-2024-30111—25.0%
——8——CVE-2018-20579—25.0%
——8——CVE-2024-6480—25.0%
——8——CVE-2023-52147—25.0%
——8——CVE-2025-10240—25.0%
——8——CVE-2026-862845.3 MED25.0%
——8A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. To fix this issue, it is recommended to deploy a patch.7dCVE-2026-813568.2 HIG25.0%
——8Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.4dCVE-2016-3946—25.0%
——8——CVE-2023-52192—25.0%
——8——CVE-2024-4896—25.0%
——8——CVE-2024-4391—25.0%
——8——CVE-2025-46183—25.0%
——8——CVE-2022-44317—25.0%
——8——CVE-2024-4404—25.0%
——8——