Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-39394—21.8%
——7——CVE-2016-8032—21.8%
——7——CVE-2024-13564—21.8%
——7——CVE-2024-3288—21.8%
——7——CVE-2024-4200—21.8%
——7——CVE-2025-32526—21.8%
——7——CVE-2026-72774—21.8%
——7n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pre-execution permission check compares the unresolved expression instead of the resolved credential type, the ownership check is skipped and the credential is loaded at execution time, allowing the member to use or exfiltrate a credential they were not granted. Exploitation requires knowing the target credential's identifier.28dCVE-2003-0524—21.8%
——7——CVE-2024-5251—21.8%
——7——CVE-2026-167516.5 MED21.8%
——7Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted `approve-recovery` API request.40dCVE-2025-68072—21.8%
——7——CVE-2024-44005—21.8%
——7——CVE-2026-676075.9 MED21.8%
——7LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached thread id reuse, resulting in daemon destabilization or crash which can lead to a denial of service. The 2.3.1 patch only narrowed the timing window (an extra re-check and reordered cleanup), it never added the missing lock, so the underlying race remains.36dCVE-2026-206446.5 MED21.8%
——7The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.56dCVE-2026-4494—21.8%
——7——CVE-2024-35779—21.8%
——7——CVE-2024-35716—21.8%
——7——CVE-2024-5255—21.8%
——7——CVE-2017-8156—21.8%
——7——CVE-2017-18667—21.8%
——7——CVE-2024-5253—21.8%
——7——CVE-2024-34772—21.8%
——7——CVE-2025-46786—21.8%
——7——CVE-2026-39511—21.8%
——7——CVE-2025-10099—21.8%
——7——CVE-2024-13565—21.8%
——7——CVE-2024-13672—21.8%
——7——CVE-2026-31836—21.8%
——7——CVE-2025-28011—21.8%
——7——CVE-2025-55267—21.8%
——7——CVE-2026-554645.4 MED21.8%
——7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2.57dCVE-2025-34247—21.8%
——7——CVE-2024-44042—21.8%
——7——CVE-2025-0805—21.8%
——7——CVE-2026-133896.5 MED21.8%
——7The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.13dCVE-2025-23561—21.8%
——7——CVE-2023-45721—21.8%
——7——CVE-2025-0078—21.8%
——7——CVE-2026-98567.1 HIG21.8%
——7A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.5dCVE-2025-64751—21.8%
——7——