Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-422013.3 LOW23.7%
——7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the API layer, with zero shell-safety checks. These values are then interpolated directly into Docker Compose YAML command: strings without any escaping. This issue is fixed in version 4.0.0-beta.474.66dCVE-2026-27855—23.7%
——7——CVE-2026-25366—23.7%
——7——CVE-2017-12136—23.7%
——7——CVE-2017-12550—23.7%
——7——CVE-2009-4184—23.7%
——7——CVE-2026-114607.3 HIG23.7%
——7A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed indefinitely citing time concerns. No patch is currently available and the disclosure deadline has expired.51dCVE-2002-2382—23.7%
——7——CVE-2025-61754—23.7%
——7——CVE-2025-32296—23.7%
——7——CVE-2024-11486—23.7%
——7——CVE-2016-2456—23.7%
——7——CVE-2009-3412—23.7%
——7——CVE-2026-703387.8 HIG23.6%
——7Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.28dCVE-2026-99738.8 HIG23.7%
——7Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)52dCVE-2024-25691—23.7%
——7——CVE-2025-66552—23.7%
——7——CVE-2023-5578—23.7%
——7——CVE-2025-710016.5 MED23.6%
——7A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.69dCVE-2026-17524.3 MED23.6%
——7GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API.48dCVE-2020-24502—23.6%
——7——CVE-2026-4542—23.6%
——7——CVE-2023-5975—23.6%
——7——CVE-2019-5642—23.6%
——7——CVE-2026-41690—23.6%
——7——CVE-2024-12102—23.6%
——7——CVE-2022-45885—23.6%
——7——CVE-2024-37502—23.6%
——7——CVE-2026-596447.5 HIG23.6%
——7In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.11dCVE-2026-790404.3 MED23.6%
——7Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)15dCVE-2010-3507—23.6%
——7——CVE-2021-40790—23.6%
——7——CVE-2020-36917—23.6%
——7——CVE-2020-28219—23.6%
——7——CVE-2011-2041—23.6%
——7——CVE-2025-53035—23.6%
——7——CVE-2026-143505.3 MED23.6%
——7IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.3dCVE-2026-54287—23.6%
——7——CVE-2026-135067.5 HIG23.6%
——7In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).14dCVE-2025-67823—23.6%
——7——