Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,277
- High8,404
- Medium6,471
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-36951—23.4%
——7——CVE-2026-822858.2 HIG23.4%
——7bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to enumerate internal network services and cloud metadata endpoints, then retrieve captured responses from object storage using caller-supplied object names.11dCVE-2013-6306—23.4%
——7——CVE-2024-359147.5 HIG23.4%
——7In the Linux kernel, the following vulnerability has been resolved:
nfsd: Fix error cleanup path in nfsd_rename()
Commit a8b0026847b8 ("rename(): avoid a deadlock in the case of parents
having no common ancestor") added an error bail out path. However this
path does not drop the remount protection that has been acquired. Fix
the cleanup path to properly drop the remount protection.38dCVE-2025-0809—23.4%
——7——CVE-2025-24630—23.4%
——7——CVE-2024-41270—23.4%
——7——CVE-2026-447695.5 MED23.4%
——7SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.59dCVE-2026-30760—23.4%
——7——CVE-2026-1304—23.4%
——7——CVE-2025-13569—23.4%
——7——CVE-2026-5293—23.4%
——7——CVE-2025-13570—23.4%
——7——CVE-2026-762547.5 HIG23.4%
——7In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that user, which can allow for access to all relevant data and system integrity available to that user and affect system availability. The vulnerability is possible because Dataset Explorer does not validate or escape dataset names before building SPL searches and does not apply SPL safeguards for risky commands to those searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Explore a dataset (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.4/manage-and-explore-datasets/explore-a-dataset) and SPL safeguards for risky commands (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/best-practices-for-splunk-platform-security/spl-safeguards-for-risky-commands) in the Splunk documentation.15dCVE-2025-13571—23.4%
——7——CVE-2023-22000—23.4%
——7——CVE-2020-3917—23.4%
——7——CVE-2025-13030—23.4%
——7——CVE-2026-855408.8 HIG23.4%
——7DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.3dCVE-2024-37860—23.4%
——7——CVE-2022-24106—23.4%
——7——CVE-2025-11593—23.4%
——7——CVE-2024-2003—23.4%
——7——CVE-2021-27702—23.4%
——7——CVE-2025-3525—23.4%
——7——CVE-2013-2598—23.4%
——7——CVE-2025-13286—23.4%
——7——CVE-2024-10770—23.4%
——7——CVE-2026-876368.8 HIG23.4%
——7Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)1dCVE-2026-762125.3 MED23.4%
——7phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend while escapeLikeWildcards() escapes user input with the '|' prefix. As a result, wildcard escaping is a no-op and user-supplied % and _ characters remain active LIKE wildcards. An unauthenticated attacker can submit such characters in the public FAQ search form to force maximally broad pattern matches and expensive sequential scans, resulting in a denial of service. The PDO PostgreSQL backend is not affected, and quotes remain escaped so this does not enable quote-breaking SQL injection or data exfiltration.10dCVE-2026-852305.4 MED23.4%
——7A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an authenticated user able to modify dashboard widget settings could persist arbitrary URL values, including URLs using the javascript: scheme, through either of the dashboard settings persistence paths.
A malicious javascript: URL stored in a dashboard button could potentially result in client-side script execution in the MISP security context if the value reached a rendering or navigation path without the existing runtime validation. Such execution could allow an attacker to perform actions with the privileges of the affected user or access information available to their MISP session.
The practical exploitability of this issue is reduced by the fact that MISP already applied URL validation at render time, which neutralized known malicious values before they were presented to the user. The vulnerability therefore represents a persistence-layer validation gap and a defense-in-depth weakness rather than evidence of a direct bypass of the existing rendering protection.
The patch introduces a canonical url schema type and validates dashboard widget configuration before it is persisted through either settings save mechanism. ButtonWidget URLs must now be strings resolving to an absolute path on the current MISP instance or a full URL with the same origin. Values using javascript:, external origins, malformed URL forms, and non-string values are rejected at save time.20hCVE-2026-5650—23.4%
——7——CVE-2025-55084—23.4%
——7——CVE-2019-25320—23.4%
——7——CVE-2025-13273—23.4%
——7——CVE-2025-23755—23.4%
——7——CVE-2023-2335—23.4%
——7——CVE-2025-30926—23.4%
——7——CVE-2025-13325—23.4%
——7——CVE-2024-9542—23.4%
——7——