Vulnerabilities exploitable today
372,926in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,229
- High8,251
- Medium6,231
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-0260—23.9%
——7——CVE-2026-693287.8 HIG23.9%
——7Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.3dCVE-2026-843776.5 MED23.9%
——7LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2.9dCVE-2023-44341—23.9%
——7——CVE-2025-4323—23.9%
——7——CVE-2025-8345—23.9%
——7——CVE-2020-15709—23.9%
——7——CVE-2024-4271—23.9%
——7——CVE-2023-38074—23.9%
——7——CVE-2026-27366—23.9%
——7——CVE-2026-125175.3 MED23.9%
——7The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and private-network URLs and read back the parsed page metadata. This is a Server-Side Request Forgery.65dCVE-2026-5290—23.9%
——7——CVE-2026-5842—23.9%
——7——CVE-2024-39772—23.9%
——7——CVE-2024-21148—23.9%
——7——CVE-2025-42949—23.9%
——7——CVE-2026-42595—23.9%
——7——CVE-2022-43651—23.9%
——7——CVE-2022-33744—23.9%
——7——CVE-2026-29206—23.9%
——7——CVE-2026-4751—23.9%
——7——CVE-2024-55451—23.9%
——7——CVE-2023-29575—23.9%
——7——CVE-2024-41733—23.9%
——7——CVE-2024-5126—23.9%
——7——CVE-2024-535976.3 MED23.9%
——7masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.69dCVE-2024-52487—23.9%
——7——CVE-2012-2120—23.9%
——7——CVE-2026-802088.2 HIG23.9%
——7APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the backend server, so both endpoints are reachable by any unauthenticated client that can reach the gateway. An attacker can POST to /api/v1/internal/getUserHistories to enumerate the accounts sitting in the 30-day cooling-off period that follows a deletion request, then POST to /api/v1/internal/users/{userId}/close for each one. The closure path clears the account's email address, phone number and nickname, cancels its space subscriptions, removes its space memberships and deletes its OAuth bindings, so the cooling-off window that exists to let a user reverse a deletion request is bypassed and the account cannot be recovered.14dCVE-2026-659595.3 MED23.9%
——7Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() without acl.CheckAccessHTTP(r, acl.DEBUGGING), unlike comparable debug endpoints. A remote caller who can reach the vttablet debug HTTP port can bypass the configured security policy and stream VrLogStats data produced from NewVrLogStats().Send(), including literal SQL statements and bound application values from MoveTables, Reshard, Materialize, and vitess-strategy Online DDL workflows24dCVE-2026-791225.9 MED23.9%
——7Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)16dCVE-2023-6801—23.9%
——7——CVE-2018-4348—23.9%
——7——CVE-2014-3077—23.9%
——7——CVE-2025-11726—23.9%
——7——CVE-2024-13554—23.9%
——7——CVE-2024-3236—23.9%
——7——CVE-2026-655295.3 MED23.9%
——7Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.51dCVE-2025-4292—23.9%
——7——CVE-2024-42493—23.9%
——7——