Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,221
- High8,143
- Medium6,169
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34270—22.8%
——7——CVE-2025-139148.7 HIG22.8%
——7A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM
attacker to impersonate managed devices.
Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials.
This issue affects all versions of Apstra before 6.1.1.65dCVE-2025-24316—22.8%
——7——CVE-2023-27623—22.8%
——7——CVE-2026-35671—22.8%
——7——CVE-2023-47818—22.8%
——7——CVE-2026-141186.5 MED22.8%
——7Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)70dCVE-2023-41847—22.8%
——7——CVE-2021-44194—22.8%
——7——CVE-2025-32089—22.8%
——7——CVE-2026-89637.5 HIG22.8%
——7Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.49dCVE-2024-2660—22.8%
——7——CVE-2026-706947.7 HIG22.8%
——7Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in Oracle Payments, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).16dCVE-2025-52717—22.8%
——7——CVE-2023-38010—22.8%
——7——CVE-2023-34002—22.8%
——7——CVE-2026-47682—22.8%
——7CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.36dCVE-2026-43872—22.8%
——7——CVE-2026-130836.9 MED22.8%
——7A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.65dCVE-2012-3122—22.8%
——7——CVE-2023-49822—22.8%
——7——CVE-2023-34169—22.8%
——7——CVE-2026-527718.3 HIG22.8%
——7YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled — the POST /api/pages/{tag} API accepts arbitrary URL-encoded values, including single quotes, and stores them. A low-privilege authenticated user can therefore create a page whose tag is a SQL fragment, make the page non-orphaned via the standard {{include page="…"}} link mechanism, and then invoke the delete endpoint to execute arbitrary SQL inside the wiki database - including time-based blind data exfiltration from any table. This issue has been patched in version 4.6.6.2dCVE-2023-30478—22.8%
——7——CVE-2025-54157—22.8%
——7——CVE-2025-13696—22.8%
——7——CVE-2025-53509—22.8%
——7——CVE-2026-42998—22.8%
——7——CVE-2021-44195—22.8%
——7——CVE-2023-26542—22.8%
——7——CVE-2026-348326.5 MED22.8%
——7Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The handler enforces authentication but does not enforce object ownership (or moderator/admin authorization) before deletion. In verification, a second non-privileged account successfully deleted a victim account's feedback item, and the item immediately disappeared from the feedback listing/detail views. This issue has been patched in version 1.66.1.48dCVE-2025-30741—22.8%
——7——CVE-2026-4778—22.8%
——7——CVE-2026-525399.1 CRI22.8%
——7Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.41dCVE-2023-32745—22.8%
——7——CVE-2026-81659—22.8%
——7Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.13dCVE-2026-54202—22.8%
——7Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the
archive creation functionality. Because the archive path is
user-controlled and insufficiently validated, an attacker can manipulate
the input to traverse directories. This allows the creation of folders
in arbitrary locations, including sensitive directories such as
C:\Windows or for different users. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.3dCVE-2026-758439.9 CRI22.8%
——7ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts.10dCVE-2025-8901—22.8%
——7——CVE-2023-27453—22.8%
——7——