Vulnerabilities exploitable today
371,523in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,605
- Medium6,351
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-485817.8 HIG22.1%
——7Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.47dCVE-2026-503917.8 HIG22.1%
——7Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.49dCVE-2026-503437.8 HIG22.1%
——7Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.49dCVE-2021-20870—22.1%
——7——CVE-2023-41097—22.1%
——7——CVE-2019-19105—22.1%
——7——CVE-2026-34333—22.1%
——7——CVE-2026-759337.3 HIG22.1%
——7Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain.19dCVE-2026-571077.8 HIG22.1%
——7Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.50dCVE-2021-0586—22.1%
——7——CVE-2024-5440—22.1%
——7——CVE-2026-705925.5 MED22.1%
——7Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the caller-supplied filename. This issue is fixed in version 6.54.1.12hCVE-2026-503467.8 HIG22.1%
——7Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.49dCVE-2024-52592—22.1%
——7——CVE-2026-503447.8 HIG22.1%
——7Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.48dCVE-2025-2950—22.1%
——7——CVE-2024-8851—22.1%
——7——CVE-2025-66588—22.1%
——7——CVE-2025-3815—22.1%
——7——CVE-2026-41331—22.1%
——7——CVE-2025-26367—22.1%
——7——CVE-2024-11616—22.1%
——7——CVE-2024-11586—22.1%
——7——CVE-2024-55100—22.1%
——7——CVE-2025-62643—22.1%
——7——CVE-2024-57868—22.1%
——7——CVE-2025-2191—22.1%
——7——CVE-2026-44666—22.1%
——7——CVE-2013-2822—22.1%
——7——CVE-2013-0979—22.1%
——7——CVE-2025-13385—22.1%
——7——CVE-2025-48262—22.1%
——7——CVE-2026-32004—22.1%
——7——CVE-2026-73081—22.1%
——7Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that path to a shell-invoked build command. A step name containing shell metacharacters can break out of the intended build invocation and execute arbitrary commands during compilation before any code sandbox is created. An authenticated user with permission to create or edit a flow can execute commands as the worker process user, read and write the worker filesystem, exfiltrate environment secrets, and reach internal services available to the worker. This issue is fixed in version 0.80.0.28dCVE-2026-44655—22.1%
——7Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator access level) to inject HTML in Move Attachments admin page. This vulnerability is fixed in 2.28.2.50dCVE-2017-1362—22.1%
——7——CVE-2020-35531—22.1%
——7——CVE-2024-0841—22.1%
——7——CVE-2025-11445—22.1%
——7——CVE-2024-52268—22.1%
——7——