Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,277
- High8,404
- Medium6,471
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-61778—23.4%
——7——CVE-2026-6160—23.4%
——7——CVE-2026-45808—23.4%
——7OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.2dCVE-2023-4756—23.4%
——7——CVE-2025-11590—23.4%
——7——CVE-2025-0809—23.4%
——7——CVE-2026-30760—23.4%
——7——CVE-2024-41270—23.4%
——7——CVE-2013-6306—23.4%
——7——CVE-2026-5650—23.4%
——7——CVE-2024-359147.5 HIG23.4%
——7In the Linux kernel, the following vulnerability has been resolved:
nfsd: Fix error cleanup path in nfsd_rename()
Commit a8b0026847b8 ("rename(): avoid a deadlock in the case of parents
having no common ancestor") added an error bail out path. However this
path does not drop the remount protection that has been acquired. Fix
the cleanup path to properly drop the remount protection.38dCVE-2025-24630—23.4%
——7——CVE-2026-822858.2 HIG23.4%
——7bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to enumerate internal network services and cloud metadata endpoints, then retrieve captured responses from object storage using caller-supplied object names.11dCVE-2025-11600—23.4%
——7——CVE-2023-21998—23.4%
——7——CVE-2026-447695.5 MED23.4%
——7SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.59dCVE-2026-729804.4 MED23.4%
——7Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.1dCVE-2025-64983—23.4%
——7——CVE-2026-199875.3 MED23.4%
——7A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely.22dCVE-2024-8562—23.4%
——7——CVE-2025-13567—23.4%
——7——CVE-2024-10667—23.4%
——7——CVE-2020-15375—23.4%
——7——CVE-2025-58458—23.4%
——7——CVE-2023-22001—23.4%
——7——CVE-2023-47583—23.4%
——7——CVE-2023-26330—23.4%
——7——CVE-2026-43378—23.4%
——7——CVE-2023-2335—23.4%
——7——CVE-2017-9079—23.4%
——7——CVE-2025-23755—23.4%
——7——CVE-2026-876368.8 HIG23.4%
——7Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-762125.3 MED23.4%
——7phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend while escapeLikeWildcards() escapes user input with the '|' prefix. As a result, wildcard escaping is a no-op and user-supplied % and _ characters remain active LIKE wildcards. An unauthenticated attacker can submit such characters in the public FAQ search form to force maximally broad pattern matches and expensive sequential scans, resulting in a denial of service. The PDO PostgreSQL backend is not affected, and quotes remain escaped so this does not enable quote-breaking SQL injection or data exfiltration.10dCVE-2026-852305.4 MED23.4%
——7A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an authenticated user able to modify dashboard widget settings could persist arbitrary URL values, including URLs using the javascript: scheme, through either of the dashboard settings persistence paths.
A malicious javascript: URL stored in a dashboard button could potentially result in client-side script execution in the MISP security context if the value reached a rendering or navigation path without the existing runtime validation. Such execution could allow an attacker to perform actions with the privileges of the affected user or access information available to their MISP session.
The practical exploitability of this issue is reduced by the fact that MISP already applied URL validation at render time, which neutralized known malicious values before they were presented to the user. The vulnerability therefore represents a persistence-layer validation gap and a defense-in-depth weakness rather than evidence of a direct bypass of the existing rendering protection.
The patch introduces a canonical url schema type and validates dashboard widget configuration before it is persisted through either settings save mechanism. ButtonWidget URLs must now be strings resolving to an absolute path on the current MISP instance or a full URL with the same origin. Values using javascript:, external origins, malformed URL forms, and non-string values are rejected at save time.20hCVE-2025-23920—23.4%
——7——CVE-2026-33159—23.4%
——7——CVE-2026-660645.3 MED23.4%
——7goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.43dCVE-2024-33927—23.4%
——7——CVE-2000-0409—23.4%
——7——CVE-2022-47662—23.4%
——7——