Vulnerabilities exploitable today
373,020in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,129
- Medium6,192
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-578255.7 MED23.9%
——7In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.4dCVE-2016-5848—23.9%
——7——CVE-2026-350328.1 HIG23.9%
——7Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP URLs. This is exploitable by any authenticated user because the EnableLiveTvManagement permission defaults to true for all new users. An attacker can chain these vulnerabilities by adding an M3U tuner pointing to an attacker-controlled server, serving a crafted M3U with a channel pointing to the Jellyfin database, exfiltrating the database to extract admin session tokens, and escalating to admin privileges. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can disable Live TV Management privileges for all users.50dCVE-2024-55076—23.9%
——7——CVE-2024-37317—23.9%
——7——CVE-2024-51473—23.9%
——7——CVE-2026-802088.2 HIG23.9%
——7APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the backend server, so both endpoints are reachable by any unauthenticated client that can reach the gateway. An attacker can POST to /api/v1/internal/getUserHistories to enumerate the accounts sitting in the 30-day cooling-off period that follows a deletion request, then POST to /api/v1/internal/users/{userId}/close for each one. The closure path clears the account's email address, phone number and nickname, cancels its space subscriptions, removes its space memberships and deletes its OAuth bindings, so the cooling-off window that exists to let a user reverse a deletion request is bypassed and the account cannot be recovered.15dCVE-2024-21148—23.9%
——7——CVE-2024-38308—23.9%
——7——CVE-2026-5842—23.9%
——7——CVE-2025-42949—23.9%
——7——CVE-2024-39772—23.9%
——7——CVE-2024-10897—23.9%
——7——CVE-2026-5290—23.9%
——7——CVE-2018-4348—23.9%
——7——CVE-2026-57323—23.9%
——7——CVE-2026-42595—23.9%
——7——CVE-2023-6801—23.9%
——7——CVE-2014-3077—23.9%
——7——CVE-2026-27366—23.9%
——7——CVE-2026-57665—23.9%
——7——CVE-2026-791225.9 MED23.9%
——7Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)17dCVE-2020-15709—23.9%
——7——CVE-2025-8345—23.9%
——7——CVE-2024-4271—23.9%
——7——CVE-2026-843776.5 MED23.9%
——7LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2.10dCVE-2026-57630—23.9%
——7——CVE-2026-693287.8 HIG23.9%
——7Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.4dCVE-2026-811655.3 MED23.9%
——7Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.10dCVE-2023-44341—23.9%
——7——CVE-2024-13554—23.9%
——7——CVE-2025-66123—23.9%
——7——CVE-2025-57350—23.9%
——7——CVE-2026-196255.3 MED23.9%
——7When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.3dCVE-2024-30442—23.9%
——7——CVE-2026-5288—23.9%
——7——CVE-2026-52779—23.9%
——7——CVE-2026-409754.8 MED23.9%
——7Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.50dCVE-2023-7298—23.9%
——7——CVE-2024-53731—23.9%
——7——