Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,666
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64012—21.7%
——7——CVE-2026-654875.3 MED21.7%
——7Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.47dCVE-2025-53704—21.7%
——7——CVE-2019-14605—21.7%
——7——CVE-2019-0146—21.7%
——7——CVE-2025-7813—21.7%
——7——CVE-2023-0729—21.7%
——7——CVE-2024-5031—21.7%
——7——CVE-2025-31023—21.7%
——7——CVE-2024-9457—21.7%
——7——CVE-2026-183947.4 HIG21.7%
——7Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure.
To remediate this issue, users should upgrade to version 0.8.2.35dCVE-2026-566786.4 MED21.7%
——79Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region value, allowing an authenticated attacker to supply a crafted region such as kiro-canary.local:8443# and cause 9Router to send the Kiro validation request to an attacker-controlled host while forwarding the submitted Kiro API key as an Authorization header. This issue is fixed in version 0.5.6.54dCVE-2026-5001—21.7%
——7——CVE-2026-619835.3 MED21.7%
——7Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.57dCVE-2026-340777.5 HIG21.7%
——7React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.48dCVE-2026-24547—21.7%
——7——CVE-2026-6780—21.7%
——7——CVE-2026-577795.3 MED21.7%
——7Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.57dCVE-2023-41813—21.7%
——7——CVE-2026-654695.3 MED21.7%
——7Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.47dCVE-2026-654685.3 MED21.7%
——7Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.47dCVE-2021-47711—21.7%
——7——CVE-2026-452826.5 MED21.7%
——7Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker can access attachments of link shares when knowing the share token, circumventing password protection or download restrictions. It is applicable to any file that is shared directly, as the attacker only needs to know a documentId they own, apart of the mentioned share token. For shared folders the attacker has to know or guess a documentId of a file that is included inside the folder, making it much harder to exploit. The attacker can only extract an attachments, but not the file shared file or folder itself. It is recommended that the Nextcloud Server is upgraded to 33.0.3 or 32.0.9. It is recommended that the Nextcloud Enterprise Server is upgraded to 33.0.3, 32.0.9, 31.0.14.5, 30.0.17.9, 29.0.16.16, 28.0.14.17 or 27.1.11.548dCVE-2025-40732—21.6%
——7——CVE-2019-0147—21.7%
——7——CVE-2026-50233—21.7%
——7——CVE-2026-654765.3 MED21.7%
——7Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.47dCVE-2026-1722—21.6%
——7——CVE-2026-24140—21.7%
——7——CVE-2019-14601—21.7%
——7——CVE-2024-501138.8 HIG21.7%
——7In the Linux kernel, the following vulnerability has been resolved:
firewire: core: fix invalid port index for parent device
In a commit 24b7f8e5cd65 ("firewire: core: use helper functions for self
ID sequence"), the enumeration over self ID sequence was refactored with
some helper functions with KUnit tests. These helper functions are
guaranteed to work expectedly by the KUnit tests, however their application
includes a mistake to assign invalid value to the index of port connected
to parent device.
This bug affects the case that any extra node devices which has three or
more ports are connected to 1394 OHCI controller. In the case, the path
to update the tree cache could hits WARN_ON(), and gets general protection
fault due to the access to invalid address computed by the invalid value.
This commit fixes the bug to assign correct port index.35dCVE-2026-204328.0 HIG21.7%
——7In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461.46dCVE-2024-268097.8 HIG21.7%
——7In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo: release elements in clone only from destroy path
Clone already always provides a current view of the lookup table, use it
to destroy the set, otherwise it is possible to destroy elements twice.
This fix requires:
212ed75dc5fb ("netfilter: nf_tables: integrate pipapo into commit protocol")
which came after:
9827a0e6e23b ("netfilter: nft_set_pipapo: release elements in clone from abort path").35dCVE-2026-654725.3 MED21.7%
——7Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.47dCVE-2026-667108.1 HIG21.7%
——7Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.27dCVE-2026-577505.3 MED21.7%
——7Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.68dCVE-2026-577815.3 MED21.7%
——7Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through <= 1.25.10.57dCVE-2026-273995.3 MED21.7%
——7Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.47dCVE-2025-61589—21.7%
——7——CVE-2025-48027—21.7%
——7——