Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,231
- High8,254
- Medium6,235
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-4568—23.6%
——7——CVE-2026-18673—23.6%
——7When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication.
An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.11dCVE-2020-24502—23.6%
——7——CVE-2025-67823—23.6%
——7——CVE-2025-710016.5 MED23.6%
——7A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.69dCVE-2026-17524.3 MED23.6%
——7GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API.48dCVE-2026-143505.3 MED23.6%
——7IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.3dCVE-2025-27827—23.6%
——7——CVE-2025-61751—23.6%
——7——CVE-2026-110118.1 HIG23.6%
——7Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)51dCVE-2026-2555—23.6%
——7——CVE-2024-41565—23.6%
——7——CVE-2022-1671—23.6%
——7——CVE-2024-22938—23.6%
——7——CVE-2024-20129—23.6%
——7——CVE-2026-339517.5 HIG23.6%
——7Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers to modify navigation data source priorities. This endpoint, accessible via PUT /signalk/v1/api/sourcePriorities, does not enforce authentication or authorization checks and directly assigns user-controlled input to the server configuration. As a result, attackers can influence which GPS, AIS, or other sensor data sources are trusted by the system. The changes are immediately applied and persisted to disk, allowing the manipulation to survive server restarts. This issue has been patched in version 2.24.0-beta.1.49dCVE-2025-9177—23.6%
——7——CVE-2025-54319—23.6%
——7——CVE-2019-5673—23.6%
——7——CVE-2025-53814—23.6%
——7——CVE-2014-1317—23.6%
——7——CVE-2017-14569—23.6%
——7——CVE-2019-15436—23.6%
——7——CVE-2017-14302—23.6%
——7——CVE-2017-14562—23.6%
——7——CVE-2017-14308—23.6%
——7——CVE-2017-10774—23.6%
——7——CVE-2024-41965—23.6%
——7——CVE-2026-749358.8 HIG23.6%
——7Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.22dCVE-2026-106924.3 MED23.6%
——7A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.14.1 is able to address this issue. This patch is called 25bc02fac74051ddae15ce79e952f00211b1ea6b. Upgrading the affected component is recommended.51dCVE-2017-14543—23.6%
——7——CVE-2017-14565—23.6%
——7——CVE-2017-10757—23.6%
——7——CVE-2017-10780—23.6%
——7——CVE-2017-10778—23.6%
——7——CVE-2017-14310—23.6%
——7——CVE-2017-14283—23.6%
——7——CVE-2019-15437—23.6%
——7——CVE-2017-14309—23.6%
——7——CVE-2017-14544—23.6%
——7——