Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-70475—21.9%
——7Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Any authenticated user, regardless of assigned permissions, can modify execution state, data, and metadata of any execution in their workspace, enabling privilege escalation and manipulation of workflow execution results. This issue is fixed in 3.1.3.35dCVE-2025-33225—21.9%
——7——CVE-2025-11332—21.9%
——7——CVE-2025-2222—21.9%
——7——CVE-2026-726846.5 MED21.9%
——7A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation occurs outside the scope of the existing memory accounting controls that were intended to constrain it. The resulting out-of-memory condition is fatal and terminates the affected node process, causing a denial of service.7dCVE-2017-12146—21.9%
——7——CVE-2026-341246.5 MED21.9%
——7A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.46dCVE-2022-49548—21.9%
——7——CVE-2005-2196—21.9%
——7——CVE-2024-23851—21.9%
——7——CVE-2026-152109.1 CRI21.9%
——7The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.13dCVE-2025-59955—21.9%
——7——CVE-2025-67921—21.9%
——7——CVE-2009-4191—21.9%
——7——CVE-2026-29097—21.9%
——7——CVE-2023-2352—21.9%
——7——CVE-2025-43533—21.9%
——7——CVE-2023-4690—21.9%
——7——CVE-2026-153158.8 HIG21.9%
——7Tapo C120 v1 and C200 v5
contain an improper authentication vulnerability within the login
authentication verification module. An attacker on the local network can
exploit weaknesses in challenge parameter validation to bypass normal
authentication controls and obtain administrative session tokens.
Successful
exploitation may allow an attacker to subsequently execute privileged
management actions, enable unauthorized administrative access and temporary
disruption of device services, resulting in a denial-of-service (DoS)
condition.4dCVE-2023-40464—21.9%
——7——CVE-2026-732478.6 HIG21.9%
——7Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that accesses internal services or cloud metadata.26dCVE-2026-781155.4 MED21.9%
——7A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.13dCVE-2023-30775—21.9%
——7——CVE-2025-57903—21.9%
——7——CVE-2025-15510—21.9%
——7——CVE-2026-239295.4 MED21.9%
——7Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.10hCVE-2023-53688—21.9%
——7——CVE-2025-2314—21.9%
——7——CVE-2024-37943—21.9%
——7——CVE-2016-2985—21.9%
——7——CVE-2025-21621—21.9%
——7——CVE-2023-52117—21.9%
——7——CVE-2022-42854—21.9%
——7——CVE-2025-510558.6 HIG21.9%
——7Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database information.66dCVE-2011-0461—21.9%
——7——CVE-2023-47869—21.9%
——7——CVE-2023-20047—21.9%
——7——CVE-2025-59017—21.9%
——7——CVE-2024-27008—21.9%
——7——CVE-2021-21429—21.9%
——7——