Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-30453—23.0%
——7——CVE-2021-2167—23.0%
——7——CVE-2025-39578—23.0%
——7——CVE-2024-51016—23.0%
——7——CVE-2024-51000—23.0%
——7——CVE-2023-49259—23.0%
——7——CVE-2024-50995—23.0%
——7——CVE-2021-4022—23.0%
——7——CVE-2024-52013—23.0%
——7——CVE-2024-51013—23.0%
——7——CVE-2018-3682—23.0%
——7——CVE-2025-39576—23.0%
——7——CVE-2024-1344—23.0%
——7——CVE-2024-51012—23.0%
——7——CVE-2022-46845—23.0%
——7——CVE-2026-3702—23.0%
——7——CVE-2024-50998—23.0%
——7——CVE-2010-2072—23.0%
——7——CVE-2026-33584—23.0%
——7——CVE-2026-93667.3 HIG23.0%
——7A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.50dCVE-2017-18830—23.0%
——7——CVE-2026-38616.5 MED23.0%
——7LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.65dCVE-2025-8121—22.9%
——7——CVE-2020-4887—22.9%
——7——CVE-2025-7956—22.9%
——7——CVE-2025-68069—22.9%
——7——CVE-2024-25673—22.9%
——7——CVE-2024-55995—22.9%
——7——CVE-2026-480742.7 LOW22.9%
——7OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table by email. The `email` clause has no `tenantId` predicate. Any pending invite in any tenant that shares the deleted staff's email is removed. A TENANT_ADMIN of tenant A who deletes a staff record with email `victim[@]example[.]com` also deletes the pending invite for `victim[@]example[.]com` in tenant B, even though they have no relationship to tenant B. The user-side delete is correctly scoped (`eq(user.id, staffId), eq(user.tenantId, tenantId)`), and the pending-invite-only delete path (when `staffId` is itself an invite ID) is also tenant-scoped. The bug is specifically in the invite cleanup that runs as a side effect of deleting an existing staff user. Version 1.0.6 patches the issue.2dCVE-2025-68975—22.9%
——7——CVE-2026-35584—22.9%
——7——CVE-2026-22193—22.9%
——7——CVE-2026-646626.5 MED22.9%
——7Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.2dCVE-2026-1294—22.9%
——7——CVE-2026-384446.1 MED22.9%
——7osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.10dCVE-2024-6979—22.9%
——7——CVE-2026-5242—22.9%
——7——CVE-2026-400376.5 MED22.9%
——7OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.48dCVE-2022-21704—22.9%
——7——CVE-2021-25263—22.9%
——7——