Vulnerabilities exploitable today
369,575in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,111
- High7,598
- Medium5,690
- Low556
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-43259—21.1%
——6——CVE-2022-1184—21.1%
——6——CVE-2002-2407—21.1%
——6——CVE-2026-792283.1 LOW21.1%
——6Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation into a privileged page via a crafted HTML page. (Chromium security severity: Medium)10dCVE-2022-3388—21.1%
——6——CVE-2026-758077.5 HIG21.1%
——6The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before the signature-validation verdict is enforced, because mo_saml_find_certificate() returns false on a fingerprint mismatch rather than halting execution. This makes it possible for unauthenticated attackers to overwrite the plugin's stored IdP signing certificate with an attacker-controlled value, and subsequently forge SAML assertions for any WordPress account — including administrators — to obtain a fully privileged session. Note: The exploit requires the administrator to perform a repair after receiving the test_config_error_wpsamlerr004 error message during the test configuration.9dCVE-2025-52459—21.1%
——6——CVE-2024-27077—21.1%
——6——CVE-2019-4731—21.1%
——6——CVE-2026-485017.4 HIG21.1%
——6GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that automatically attaches tokens to outgoing requests. This layer lacks accurate host detection and can incorrectly attribute the target host, providing it with a token it should never receive. Specifically, the host normalization logic collapses any *.github.com subdomain to github.com, so a request to tuf-repo.github.com (a GitHub Pages site, not a GitHub API endpoint) is treated as a request to github.com and receives the user's github.com token. For hosts that don't match github.com or a known GHES instance at all, the resolver falls back to GH_ENTERPRISE_TOKEN if set. The gh attestation, gh release verify and gh release verify-asset commands fetch data from several external hosts as part of their normal operation (TUF metadata from tuf-repo.github.com and tuf-repo-cdn.sigstore.dev, artifact bundles from Azure Blob Storage). Because these requests go through the same authenticated HTTP client, the token is sent to all of them. This vulnerability is fixed in 2.93.0.48dCVE-2024-23289—21.1%
——6——CVE-2024-13576—21.1%
——6——CVE-2020-8018—21.1%
——6——CVE-2022-38095—21.1%
——6——CVE-2024-13757—21.1%
——6——CVE-2024-44039—21.1%
——6——CVE-2026-739325.3 MED21.1%
——6Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).10dCVE-2026-666599.3 CRI21.1%
——6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.
This issue affects Tablesome Table: from n/a through 1.2.9.26dCVE-2022-0444—21.1%
——6——CVE-2022-34520—21.1%
——6——CVE-2026-579525.3 MED21.1%
——6Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.55dCVE-2022-34502—21.1%
——6——CVE-2023-51694—21.1%
——6——CVE-2026-39976—21.1%
——6——CVE-2022-26369—21.1%
——6——CVE-2025-2255—21.1%
——6——CVE-2026-3105—21.1%
——6——CVE-2024-12452—21.1%
——6——CVE-2026-535168.3 HIG21.1%
——6Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to bind the victim's OAuth identity to the attacker's account. The same primitive affects one-tap, and emailAndPassword.requireEmailVerification: true does not mitigate the link-time verification change. This issue is fixed in version 1.6.11.48dCVE-2021-3741—21.1%
——6——CVE-2022-36358—21.1%
——6——CVE-2026-4066—21.1%
——6——CVE-2005-3289—21.1%
——6——CVE-2026-49776—21.1%
——6——CVE-2022-27672—21.1%
——6——CVE-2025-55340—21.1%
——6——CVE-2024-45878—21.1%
——6——CVE-2025-504917.1 HIG21.1%
——6Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.64dCVE-2025-1410—21.1%
——6——CVE-2020-4900—21.1%
——6——