Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47025—21.8%
——7——CVE-2024-447946.1 MED21.8%
——7A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.66dCVE-2025-712177.8 HIG21.8%
——7An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).47dCVE-2022-50358—21.8%
——7——CVE-2025-15404—21.8%
——7——CVE-2026-517375.3 MED21.8%
——7Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.7dCVE-2026-517615.3 MED21.8%
——7Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.7dCVE-2025-25129—21.8%
——7——CVE-2002-1667—21.8%
——7——CVE-2026-4780—21.8%
——7——CVE-2026-790144.3 MED21.8%
——7Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)11dCVE-2018-7515—21.8%
——7——CVE-2024-42624—21.8%
——7——CVE-2026-347697.7 HIG21.8%
——7Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls. Apps are only affected if they construct webPreferences from external or untrusted input without an allowlist. Apps that use a fixed, hardcoded webPreferences object are not affected. This issue has been patched in versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8.46dCVE-2025-5842—21.8%
——7——CVE-2025-1492—21.8%
——7——CVE-2020-6417—21.8%
——7——CVE-2025-22677—21.8%
——7——CVE-2009-5081—21.8%
——7——CVE-2005-4660—21.8%
——7——CVE-2002-0141—21.8%
——7——CVE-2026-8662—21.8%
——7——CVE-2026-75114—21.8%
——7Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.19dCVE-2016-11052—21.8%
——7——CVE-2026-76599—21.8%
——7Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.15dCVE-2024-49839—21.8%
——7——CVE-2024-42630—21.8%
——7——CVE-2025-67707—21.8%
——7——CVE-2020-12754—21.8%
——7——CVE-2026-73665—21.8%
——7FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path patched by node/lib/asterisk-manager-patch.js, allowing arbitrary commands to execute as the asterisk service user. This issue is fixed in version 17.0.9.22dCVE-2024-41347—21.8%
——7——CVE-2024-42608—21.8%
——7——CVE-2026-4570—21.8%
——7——CVE-2024-39063—21.8%
——7——CVE-2026-76601—21.8%
——7Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.15dCVE-2026-4781—21.8%
——7——CVE-2023-4843—21.8%
——7——CVE-2024-42628—21.8%
——7——CVE-2024-50419—21.8%
——7——CVE-2026-251979.1 CRI21.8%
——7A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.46d