Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,226
- High8,209
- Medium6,217
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-8903—24.2%
——7——CVE-2025-20159—24.2%
——7——CVE-2025-4333—24.2%
——7——CVE-2026-281907.1 HIG24.2%
——7Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.19dCVE-2025-15117—24.2%
——7——CVE-2025-15358—24.2%
——7——CVE-2026-325618.8 HIG24.2%
——7Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.18dCVE-2015-1009—24.2%
——7——CVE-2026-673267.0 HIG24.2%
——7GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.3dCVE-2016-7714—24.2%
——7——CVE-2018-18984—24.2%
——7——CVE-2024-20512—24.2%
——7——CVE-2025-4768—24.2%
——7——CVE-2024-37249—24.2%
——7——CVE-2024-41858—24.2%
——7——CVE-2024-25513—24.2%
——7——CVE-2019-25536—24.2%
——7——CVE-2025-49011—24.2%
——7——CVE-2026-545987.5 HIG24.2%
——7Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has been patched in version 4.9.4.4dCVE-2025-38637—24.2%
——7——CVE-2025-37128—24.2%
——7——CVE-2024-35768—24.2%
——7——CVE-2024-21213—24.2%
——7——CVE-2026-21224—24.2%
——7——CVE-2025-4305—24.2%
——7——CVE-2025-13950—24.2%
——7——CVE-2014-4867—24.2%
——7——CVE-2017-18789—24.2%
——7——CVE-2026-25482—24.2%
——7——CVE-2024-1743—24.2%
——7——CVE-2006-6674—24.2%
——7——CVE-2026-32002—24.2%
——7——CVE-2007-4415—24.2%
——7——CVE-2023-295406.1 MED24.2%
——7Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.24dCVE-2021-42810—24.2%
——7——CVE-2021-44321—24.2%
——7——CVE-2026-7597—24.2%
——7——CVE-2026-823066.5 MED24.2%
——7StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials.12dCVE-2026-33685—24.2%
——7——CVE-2026-733014.3 MED24.2%
——7Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and default-group flags. The disclosure exposes the tenant access-control structure to users who are not builders or administrators. This issue is fixed in version 3.39.25.4d