Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low586
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-825215.3 MED21.9%
——7parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal sequences, the filename sanitization function produces an empty string, and a fallback to the raw unsanitized subject causes the resulting file to be written outside the intended samples directory. An attacker who can cause a forensic failure report with a crafted Subject to be processed can write a dot-prefixed file with attacker-controlled content to an ancestor directory of the configured samples output path. Exploitation requires that file output for forensic report samples is enabled.5dCVE-2026-76244.3 MED21.9%
——7The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to invoke privileged state-changing Squirrly cloud API operations, such as revoking the site's Google Search Console and Google Analytics integrations via `api/gsc/revoke` and `api/ga/revoke`, that are otherwise restricted to administrator-level users holding the `sq_manage_settings` capability.48dCVE-2022-36614—21.9%
——7——CVE-2026-30836—21.9%
——7——CVE-2026-49230—21.9%
——7——CVE-2022-35104—21.9%
——7——CVE-2026-30874—21.9%
——7——CVE-2026-726476.5 MED21.9%
——7Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request whose deeply nested structure is processed without a depth limit, exhausting the thread stack and terminating the affected node.7dCVE-2024-10325—21.9%
——7——CVE-2023-26592—21.9%
——7——CVE-2023-45222—21.9%
——7——CVE-2026-726536.5 MED21.9%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.6dCVE-2025-3583—21.9%
——7——CVE-2025-0708—21.9%
——7——CVE-2025-3275—21.9%
——7——CVE-2025-55210—21.9%
——7——CVE-2025-49854—21.9%
——7——CVE-2022-43652—21.9%
——7——CVE-2022-39997—21.9%
——7——CVE-2022-36615—21.9%
——7——CVE-2025-58053—21.9%
——7——CVE-2026-771513.7 LOW21.9%
——7A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing a manipulation results in risky cryptographic algorithm. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 5.4.2 can resolve this issue. The patch is named 9ce19a3b0d0765086a655f45d3a706ec1810404f. It is recommended to upgrade the affected component.15dCVE-2026-726596.5 MED21.9%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before use. Processing the request causes unbounded memory growth in the Kibana process, which is terminated by the host once available memory is exhausted. Kibana then becomes unavailable to all users until the service is restarted.6dCVE-2022-35107—21.9%
——7——CVE-2023-37332—21.9%
——7——CVE-2022-36612—21.9%
——7——CVE-2026-730867.4 HIG21.9%
——7nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.27dCVE-2016-5918—21.9%
——7——CVE-2022-35105—21.9%
——7——CVE-2025-151156.5 MED21.9%
——7Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification.50dCVE-2025-25469—21.9%
——7——CVE-2025-48244—21.9%
——7——CVE-2024-12815—21.9%
——7——CVE-2025-25634—21.9%
——7——CVE-2023-30775—21.9%
——7——CVE-2025-21621—21.9%
——7——CVE-2024-11130—21.9%
——7——CVE-2025-57903—21.9%
——7——CVE-2024-41826—21.9%
——7——CVE-2024-40833—21.9%
——7——