Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,269
- High8,357
- Medium6,443
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-185045.4 MED23.5%
——7fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such as an integer, Ajv can coerce a JSON string into the expected type during validation, but Fastify does not replace the root request body with the coerced value, so the route handler receives the original unvalidated string. As a result, a request that should have failed validation can reach application logic with a value that does not satisfy the schema, which can undermine integrity and access-control checks that rely on the validated type. Users should upgrade to fastify 5.12.1, which fixes the mismatch. No known workarounds are available.9dCVE-2025-60239—23.5%
——7——CVE-2024-21150—23.5%
——7——CVE-2023-31982—23.5%
——7——CVE-2026-48972—23.5%
——7——CVE-2026-441077.5 HIG23.5%
——7A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.43dCVE-2023-22424—23.5%
——7——CVE-2026-150875.9 MED23.5%
——7vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.60dCVE-2023-33207—23.5%
——7——CVE-2018-4434—23.5%
——7——CVE-2023-45765—23.5%
——7——CVE-2024-42337—23.5%
——7——CVE-2024-39598—23.5%
——7——CVE-2026-30915—23.5%
——7——CVE-2026-40198—23.5%
——7——CVE-2025-8054—23.5%
——7——CVE-2026-226744.8 MED23.5%
——7Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the unsanitized innerHTML assignment in the branding service to execute arbitrary JavaScript in the browser of every authenticated user on every page load.59dCVE-2026-170756.5 MED23.5%
——7IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.23dCVE-2022-46740—23.5%
——7——CVE-2024-2179—23.5%
——7——CVE-2025-53902—23.5%
——7——CVE-2026-2890—23.5%
——7——CVE-2025-7958—23.5%
——7——CVE-2023-31346—23.5%
——7——CVE-2023-28495—23.5%
——7——CVE-2025-4257—23.5%
——7——CVE-2011-0790—23.5%
——7——CVE-2023-6040—23.5%
——7——CVE-2025-62765—23.5%
——7——CVE-2022-38086—23.5%
——7——CVE-2025-5132—23.5%
——7——CVE-2026-393428.8 HIG23.5%
——7ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0.49dCVE-2003-0956—23.5%
——7——CVE-2026-6771—23.5%
——7——CVE-2009-0925—23.5%
——7——CVE-2009-3572—23.5%
——7——CVE-2023-26543—23.5%
——7——CVE-2026-56383—23.5%
——7——CVE-2026-33132—23.5%
——7——CVE-2007-1191—23.5%
——7——