Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,231
- High8,251
- Medium6,234
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-4090—24.0%
——7——CVE-2024-36233—24.0%
——7——CVE-2024-36413—24.0%
——7——CVE-2023-51377—24.0%
——7——CVE-2023-21599—24.0%
——7——CVE-2026-563207.1 HIG24.0%
——7Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validating it matches the target app's owner organization. Authenticated attackers can create device records for an application using a foreign organization identifier, bypassing the intended org/app authorization boundary.73dCVE-2026-32999—24.0%
——7——CVE-2024-36215—24.0%
——7——CVE-2017-9552—24.0%
——7——CVE-2022-3633—24.0%
——7——CVE-2022-27537—23.9%
——7——CVE-2026-781827.3 HIG24.0%
——7A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.19dCVE-2026-186407.1 HIG24.0%
——7The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.14dCVE-2025-7926—24.0%
——7——CVE-2025-9148—24.0%
——7——CVE-2026-843539.6 CRI24.0%
——7Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)4dCVE-2024-8747—24.0%
——7——CVE-2021-45656—24.0%
——7——CVE-2026-727496.5 MED24.0%
——7n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global is used on the request-authentication path, the instance then fails every authenticated request, causing an instance-wide denial of service for all users until the process is restarted.10dCVE-2021-31829—24.0%
——7——CVE-2024-56006—24.0%
——7——CVE-2024-36225—24.0%
——7——CVE-2024-7938—24.0%
——7——CVE-2024-36217—24.0%
——7——CVE-2023-52186—24.0%
——7——CVE-2026-604718.3 HIG23.9%
——7Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the WebCenter Content: Imaging executes to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).46dCVE-2026-712708.6 HIG23.9%
——7Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf).17dCVE-2020-2025—23.9%
——7——CVE-2018-5826—23.9%
——7——CVE-2025-8040—23.9%
——7——CVE-2022-50941—23.9%
——7——CVE-2025-10965—23.9%
——7——CVE-2024-32368—23.9%
——7——CVE-2025-24723—23.9%
——7——CVE-2022-29213—23.9%
——7——CVE-2024-36819—23.9%
——7——CVE-2019-25062—23.9%
——7——CVE-2026-20999—23.9%
——7——CVE-2024-10554—23.9%
——7——CVE-2026-57630—23.9%
——7——