Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,274
- High8,391
- Medium6,468
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2013-6840—23.4%
——7——CVE-2026-502227.5 HIG23.4%
——7Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs.
Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine, exhibit missing or insufficient access control validation, potentially allowing cross-tenant/cross-account access to userdata resources that belong to other tenants.
This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
The deleteCniConfiguration API, introduced in 4.21.0.0, also exhibits similar behaviour and lacks access validation.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.16dCVE-2025-58938—23.4%
——7——CVE-2026-33159—23.4%
——7——CVE-2000-0409—23.4%
——7——CVE-2025-23920—23.4%
——7——CVE-2026-660645.3 MED23.4%
——7goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.43dCVE-2024-33927—23.4%
——7——CVE-2025-11591—23.4%
——7——CVE-2022-22230—23.4%
——7——CVE-2025-23599—23.4%
——7——CVE-2022-3703—23.4%
——7——CVE-2025-12262—23.4%
——7——CVE-2026-674305.3 MED23.4%
——7MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by default, so repeated initialize requests retain unbounded ServerSession objects and can exhaust process memory. This issue is fixed in version 0.23.0.43dCVE-2025-13581—23.4%
——7——CVE-2025-13568—23.4%
——7——CVE-2024-10543—23.4%
——7——CVE-2026-562107.1 HIG23.4%
——7A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).10dCVE-2010-3684—23.4%
——7——CVE-2026-50746.5 MED23.4%
——7The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient sanitization of the user-supplied parameter which is concatenated directly into the ORDER BY clause of an SQL query without a whitelist check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability can only be exploited if the "User Private Content" addon is enabled, which is disabled by default..52dCVE-2026-592167.7 HIG23.4%
——7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learned another socket ID through ydoc:document:join to run code interpreter Python or tools in that user session. This issue is fixed in version 0.10.0.60dCVE-2025-13290—23.4%
——7——CVE-2026-455016.5 MED23.4%
——7Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.45dCVE-2025-23593—23.4%
——7——CVE-2016-10741—23.4%
——7——CVE-2023-26330—23.4%
——7——CVE-2026-43378—23.4%
——7——CVE-2023-22001—23.4%
——7——CVE-2002-1550—23.4%
——7——CVE-2022-47662—23.4%
——7——CVE-2025-14230—23.4%
——7——CVE-2016-2949—23.4%
——7——CVE-2011-0897—23.4%
——7——CVE-1999-0352—23.4%
——7——CVE-2025-12926—23.4%
——7——CVE-2024-3171—23.4%
——7——CVE-2022-48804—23.4%
——7——CVE-2025-58458—23.4%
——7——CVE-2024-8562—23.4%
——7——CVE-2026-199875.3 MED23.4%
——7A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely.22d