Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,666
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2003-0887—21.7%
——7——CVE-2014-3611—21.7%
——7——CVE-2026-7599—21.7%
——7——CVE-2025-63248—21.7%
——7——CVE-2026-766346.5 MED21.7%
——7WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags.19dCVE-2023-20854—21.7%
——7——CVE-2026-141006.5 MED21.7%
——7Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)69dCVE-2026-7618—21.7%
——7——CVE-2024-41705—21.7%
——7——CVE-2005-2311—21.7%
——7——CVE-2019-17435—21.7%
——7——CVE-2026-544577.7 HIG21.7%
——7TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gateway filesystem to be read, including credential files. Selecting the s3_compatible storage type causes outbound object-storage requests to attacker-chosen internal or cloud-metadata endpoints. Exploitation requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This issue is fixed in version 2026.6.0.14dCVE-2014-2384—21.7%
——7——CVE-2026-177944.3 MED21.7%
——7Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)36dCVE-2022-1419—21.7%
——7——CVE-2025-52775—21.7%
——7——CVE-2026-7445—21.7%
——7——CVE-2009-5117—21.7%
——7——CVE-2022-42819—21.7%
——7——CVE-2021-42809—21.7%
——7——CVE-2026-42037—21.7%
——7——CVE-2024-45193—21.7%
——7——CVE-2020-0564—21.7%
——7——CVE-2026-140986.5 MED21.7%
——7Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)69dCVE-2024-20856—21.7%
——7——CVE-2026-33042—21.7%
——7——CVE-2025-8092—21.7%
——7——CVE-2025-671597.5 HIG21.7%
——7Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.66dCVE-2026-140716.5 MED21.7%
——7Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)69dCVE-2025-1115—21.7%
——7——CVE-2026-24035—21.7%
——7——CVE-2021-22566—21.7%
——7——CVE-2024-41126—21.7%
——7——CVE-2026-7728—21.7%
——7——CVE-2026-6325—21.7%
——7——CVE-2026-41954—21.7%
——7——CVE-2025-22310—21.7%
——7——CVE-2026-738947.3 HIG21.7%
——7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).11dCVE-2025-150986.3 MED21.7%
——7A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/header/body can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.45dCVE-2026-134359.9 CRI21.7%
——7IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.35d