Vulnerabilities exploitable today
371,523in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,605
- Medium6,351
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11602—22.1%
——7——CVE-2024-33051—22.1%
——7——CVE-2022-49059—22.1%
——7——CVE-2025-2204—22.1%
——7——CVE-2024-11616—22.1%
——7——CVE-2011-20002—22.1%
——7——CVE-2025-11445—22.1%
——7——CVE-2025-62618—22.1%
——7——CVE-2017-1362—22.1%
——7——CVE-2025-30960—22.1%
——7——CVE-2024-0841—22.1%
——7——CVE-2013-2816—22.1%
——7——CVE-2026-72217.3 HIG22.1%
——7A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.17.1 is able to address this issue. The patch is identified as 3f678a1e7bd400cd76469d61024097d4920dc6b5. It is recommended to upgrade the affected component.47dCVE-2022-37326—22.1%
——7——CVE-2023-23941—22.1%
——7——CVE-2025-12620—22.1%
——7——CVE-2025-36071—22.1%
——7——CVE-2024-52001—22.1%
——7——CVE-2025-0448—22.1%
——7——CVE-2022-22983—22.1%
——7——CVE-2024-37141—22.1%
——7——CVE-2025-9441—22.1%
——7——CVE-2023-32433—22.1%
——7——CVE-2026-335784.3 MED22.1%
——7OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots despite configured allowlist restrictions.46dCVE-2026-34062—22.1%
——7——CVE-2026-346938.0 HIG22.1%
——7Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.12dCVE-2026-32573—22.1%
——7——CVE-2020-3891—22.1%
——7——CVE-2009-3100—22.1%
——7——CVE-2025-32782—22.1%
——7——CVE-2024-52268—22.1%
——7——CVE-2011-4922—22.1%
——7——CVE-2024-33050—22.1%
——7——CVE-2020-35531—22.1%
——7——CVE-2026-28677—22.1%
——7——CVE-2026-445055.3 MED22.1%
——7Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer returns a FoundRecord, the code verifies the record via dht_verifier.verify(&record.record). On verifier error, handle_dht_get logs and returns early without completing the oneshot used by Network::dht_get, and without cleaning up per-query bookkeeping. Later query progress can hit the "DHT inconsistent state" path and also return without cleanup. Because Network::dht_get awaits the oneshot without a timeout, the caller future can hang indefinitely. This issue has been patched in version 1.4.0.48dCVE-2020-35533—22.1%
——7——CVE-2023-4828—22.1%
——7——CVE-2025-30454—22.1%
——7——CVE-2026-189737.3 HIG22.1%
——7A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.27d