Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-0517—25.0%
——8——CVE-2010-1671—25.0%
——8——CVE-2026-28922—25.0%
——8——CVE-2026-84149—25.0%
——8This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.14dCVE-2002-1268—25.0%
——8——CVE-2025-11460—25.0%
——8——CVE-2026-3231—25.0%
——8——CVE-2024-5567—25.0%
——8——CVE-2019-19891—25.0%
——8——CVE-2002-1266—25.0%
——8——CVE-2026-55732—25.0%
——8Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.50dCVE-2022-22631—25.0%
——8——CVE-2022-44313—25.0%
——8——CVE-2026-811016.5 MED25.0%
——8The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint option into the user profile without passing it through createSafeUrl in src/config.ts, the helper that already restricted the environment-variable form of the same setting to the vendor's own hosts over HTTPS. Because the connect path in src/mcp.ts attaches the stored token as a bearer credential on every request to the configured endpoint, a user who was persuaded to run configure with an endpoint of the attacker's choosing sent their personal access token to that destination on each subsequent invocation. Version 0.2.5 applies the same helper to the option.19dCVE-2022-44319—25.0%
——8——CVE-2025-9400—25.0%
——8——CVE-2026-262377.5 HIG25.0%
——8A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.
We have already fixed the vulnerability in the following version:
QuMagie 2.9.0 and later54dCVE-2024-4288—25.0%
——8——CVE-2024-3370—25.0%
——8——CVE-2024-36407—25.0%
——8——CVE-2026-5277—25.0%
——8——CVE-2026-695438.5 HIG25.0%
——8Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.24dCVE-2026-54845.3 MED25.0%
——8A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 26.03.1 is able to address this issue. This patch is called 8a59895ba063040cc8dafd82e94024c406df3d04. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.57dCVE-2020-14545—25.0%
——8——CVE-2025-14924—25.0%
——8——CVE-2024-42358—25.0%
——7——CVE-2025-7718—25.0%
——7——CVE-2026-27051—25.0%
——7——CVE-2024-22819—24.9%
——7——CVE-2023-50825—25.0%
——7——CVE-2026-809898.8 HIG25.0%
——7In the Linux kernel, the following vulnerability has been resolved:
net: thunderbolt: Mark the connection down when bringing it up fails
Every failure path in tbnet_connected_work() undoes its own work and
returns without clearing login_sent, so the connection still looks
established. The next tbnet_tear_down() therefore takes its main branch
and repeats a teardown that already happened: it stops rings that are
already stopped, which is a dev_WARN() and fatal under panic_on_warn,
and it releases net->remote_transmit_path even on the HopID mismatch
path, where this connection never owned that id, silently freeing one
that someone else is still using.
Clear login_sent on those paths. That is enough for tbnet_tear_down() to
leave the unwound state alone, and login_received has to stay set: it
records that the peer has logged in and carries the transmit path it gave
us, which nothing on this side can make the peer send again. Two things
change beyond keeping the teardown out of the way: the logout request in
that block is no longer sent, and the peer's next login request now
re-queues our login work rather than connected_work, giving the
connection a fresh login instead of a retry on stale state.21hCVE-2024-22818—24.9%
——7——CVE-2024-11108—25.0%
——7——CVE-2025-2481—25.0%
——7——CVE-2024-13083—25.0%
——7——CVE-2025-48175—25.0%
——7——CVE-2025-49175—25.0%
——7——CVE-2026-8669—25.0%
——7——CVE-2025-41084—25.0%
——7——CVE-2026-591197.3 HIG25.0%
——7Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.29d