Vulnerabilities exploitable today
371,523in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,605
- Medium6,350
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-9095—22.1%
——7——CVE-2024-47131—22.1%
——7——CVE-2024-5090—22.1%
——7——CVE-2026-728809.9 CRI22.1%
——7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/certificate.ts accepts a client-supplied certificatePath, and packages/server/src/services/certificate.ts joins that value to the certificate root without confinement. An authenticated user with certificate create or delete permission can use certificatePath to write attacker-controlled certificate content outside the intended directory or delete an out-of-root directory. This vulnerability is fixed in 0.29.13.13hCVE-2025-15025—22.1%
——7——CVE-2017-6270—22.1%
——7——CVE-2024-23782—22.1%
——7——CVE-2020-10939—22.1%
——7——CVE-2022-49698—22.1%
——7——CVE-2023-7192—22.1%
——7——CVE-2026-78477—22.1%
——7Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.8dCVE-2025-49419—22.1%
——7——CVE-2025-66494—22.1%
——7——CVE-2024-22229—22.1%
——7——CVE-2022-1626—22.1%
——7——CVE-2026-4735—22.1%
——7——CVE-2017-16512—22.1%
——7——CVE-2025-25379—22.1%
——7——CVE-2026-419215.4 MED22.1%
——7Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers can supply crafted HTML or script content in fields such as title, author, isbn, publishercode, place, collectiontitle, itemtype, and note, which are stored without sanitization and later rendered in the suggestion list template, causing injected scripts to execute in the browser of any staff user who views the suggestions.9dCVE-2025-23783—22.1%
——7——CVE-2023-49117—22.1%
——7——CVE-2023-47559—22.1%
——7——CVE-2026-18363—22.1%
——7A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able to obtain a valid password reset token could reuse it to perform an unauthorised password reset and compromise the affected account.41dCVE-2023-50339—22.1%
——7——CVE-2023-32088—22.1%
——7——CVE-2023-42436—22.1%
——7——CVE-2023-26085—22.1%
——7——CVE-2026-492277.6 HIG22.1%
——7Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment operations allow a low-privileged Author to manage comments under another Author's posts. The admin/controller/content/comment.php and admin/controller/content/comments.php controllers and the admin/sql/sqlite/comment.sql queries accept a caller-controlled comment_id without verifying comment.post_id against post.admin_id for the current admin_id. An attacker can read pending comment content and commenter email addresses, change moderation status, edit comment content, or delete comments, breaking author and moderation boundaries. This issue is fixed in version 1.0.8.4.13hCVE-2023-32089—22.1%
——7——CVE-2010-5169—22.1%
——7——CVE-2026-210357.5 HIG22.1%
——7Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.71dCVE-2026-168785.4 MED22.1%
——7IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.23dCVE-2010-5159—22.1%
——7——CVE-2023-45740—22.1%
——7——CVE-2025-12994—22.1%
——7——CVE-2017-2327—22.1%
——7——CVE-2020-24504—22.1%
——7——CVE-2024-44058—22.1%
——7——CVE-2020-5387—22.1%
——7——CVE-2024-39354—22.1%
——7——