Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-18837—23.0%
——7——CVE-2024-51004—23.0%
——7——CVE-2026-725396.5 MED23.0%
——7An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the drafts endpoint. Sensitive credentials stored in these drafts are exposed across ACL boundaries.7dCVE-2013-1424—23.0%
——7——CVE-2025-39579—23.0%
——7——CVE-2023-40625—23.0%
——7——CVE-2024-45235—23.0%
——7——CVE-2026-40313—23.0%
——7——CVE-2024-30453—23.0%
——7——CVE-2024-51016—23.0%
——7——CVE-2025-39578—23.0%
——7——CVE-2024-51003—23.0%
——7——CVE-2010-3264—23.0%
——7——CVE-2024-52014—23.0%
——7——CVE-2024-41146—23.0%
——7——CVE-2025-27704—23.0%
——7——CVE-2026-149767.1 HIG23.0%
——7IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.36dCVE-2022-49217—23.0%
——7——CVE-2025-24722—23.0%
——7——CVE-2026-70474—23.0%
——7Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/<VICTIM_CREDENTIAL_UUID>, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&state=<VICTIM_CREDENTIAL_UUID>, and /api/v1/oauth2-credential/refresh/<VICTIM_CREDENTIAL_UUID>. This issue is fixed in version 3.1.3.2dCVE-2021-1824—23.0%
——7——CVE-2026-22700—23.0%
——7——CVE-2024-55511—23.0%
——7——CVE-2023-4722—23.0%
——7——CVE-2018-3682—23.0%
——7——CVE-2025-39576—23.0%
——7——CVE-2021-2167—23.0%
——7——CVE-2010-2072—23.0%
——7——CVE-2017-18830—23.0%
——7——CVE-2026-54133.7 LOW23.0%
——7A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails leads to information disclosure. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.48dCVE-2026-93667.3 HIG23.0%
——7A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.50dCVE-2026-38616.5 MED23.0%
——7LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.65dCVE-2026-3702—23.0%
——7——CVE-2024-5265—23.0%
——7——CVE-2024-1344—23.0%
——7——CVE-2026-562404.3 MED23.0%
——7Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion.59dCVE-2020-5892—23.0%
——7——CVE-2026-32300—23.0%
——7——CVE-2025-31251—23.0%
——7——CVE-2024-51001—23.0%
——7——