Vulnerabilities exploitable today
369,575in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,111
- High7,598
- Medium5,690
- Low556
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-46440—21.1%
——6——CVE-2023-20573—21.1%
——6——CVE-2026-33081—21.1%
——6——CVE-2025-31197—21.1%
——6——CVE-2024-45045—21.1%
——6——CVE-2022-41634—21.1%
——6——CVE-2026-12205—21.1%
——6——CVE-2024-32572—21.1%
——6——CVE-2022-44740—21.1%
——6——CVE-2024-11897—21.1%
——6——CVE-2023-28144—21.1%
——6——CVE-2003-0857—21.1%
——6——CVE-2024-4026—21.1%
——6——CVE-2026-478417.4 HIG21.1%
——6An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
Spring Security 6.4.0 - 6.4.183dCVE-2026-55095—21.1%
——6OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_ project attribute. The dialog path resolves the project custom field by its raw identifier without enforcing the normal admin_only visibility scope and renders the stored custom-field comment in read-only mode. This discloses hidden comment text but does not disclose the custom-field value or permit writes or mutation. This issue is reported as fixed in version 17.6.0.17dCVE-2026-18371—21.1%
——6HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.7dCVE-2025-52899—21.1%
——6——CVE-2021-2353—21.1%
——6——CVE-2024-40995—21.1%
——6——CVE-2024-6300—21.1%
——6——CVE-2026-252129.9 CRI21.1%
——6An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.45dCVE-2024-36238—21.1%
——6——CVE-2024-10885—21.1%
——6——CVE-2022-35638—21.1%
——6——CVE-2024-39125—21.1%
——6——CVE-2024-10484—21.1%
——6——CVE-2022-27823—21.1%
——6——CVE-2022-34641—21.1%
——6——CVE-2024-37524—21.1%
——6——CVE-2025-8540—21.1%
——6——CVE-2024-22876—21.1%
——6——CVE-2025-69292—21.1%
——6——CVE-2026-49338—21.1%
——6——CVE-2020-10206—21.1%
——6——CVE-2026-788636.3 MED21.1%
——6A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be performed from remote. Upgrading to version 3.1.0 is recommended to address this issue. Upgrading the affected component is recommended.11dCVE-2024-4304—21.1%
——6——CVE-2026-536206.3 MED21.1%
——6GROWI contains a vulnerability with an authorization bypass through user-controlled key in the bookmark folder APIs. If this vulnerability is exploited, an authenticated attacker could retrieve, tamper with, and/or delete the other user's bookmark data.7dCVE-2025-22299—21.1%
——6——CVE-2025-24182—21.1%
——6——CVE-2021-30699—21.1%
——6——