Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,627
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-38122—21.1%
——6——CVE-2026-17251—21.1%
——6A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of
TL-MR6400 v7. An unauthenticated remote attacker can
trigger the vulnerability by sending a specially crafted HTTP request
containing a malformed session cookie header.
Successful
exploitation may cause the HTTP service process to crash, resulting in a
denial-of-service condition and temporary loss of management or CGI
functionality until service recovery.10dCVE-2024-49656—21.1%
——6——CVE-2024-37509—21.1%
——6——CVE-2024-56085—21.1%
——6——CVE-2024-40966—21.1%
——6——CVE-2024-37199—21.1%
——6——CVE-2026-33162—21.1%
——6——CVE-2026-138648.1 HIG21.1%
——6Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)67dCVE-2025-3035—21.1%
——6——CVE-2025-9364—21.1%
——6——CVE-2026-24539—21.1%
——6——CVE-2025-32228—21.1%
——6——CVE-2024-49660—21.1%
——6——CVE-2024-35697—21.1%
——6——CVE-2026-124118.4 HIG21.1%
——6Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.67dCVE-2026-557658.5 HIG21.1%
——6CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was preloaded with track_utility enabled and an untrusted tenant held pg_monitor or pg_read_all_stats, the tenant could recover platform-managed superuser or application-owner passwords, reconnect through enabled superuser TCP access, and execute operating system commands in the database pod with `COPY ... FROM PROGRAM`. Clusters using SCRAM-SHA-256 verifiers in managed-role Secrets were not affected. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.13dCVE-2025-4839—21.1%
——6——CVE-2026-139886.5 MED21.1%
——6Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)68dCVE-2026-93909.1 CRI21.1%
——6XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.
verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName grammar that XML requires of an ID, so a URI containing a single quote closes the string literal in the generated expression and appends arbitrary XPath operators.
A crafted URI can make the lookup match elements the reference does not name, or every element in the document, so which node is selected for digest verification is decided by the injected expression rather than by the reference.33dCVE-2025-64336—21.1%
——6——CVE-2025-10039—21.1%
——6——CVE-2024-49670—21.1%
——6——CVE-2026-43914—21.1%
——6——CVE-2026-7738—21.1%
——6——CVE-2026-447637.6 HIG21.1%
——6SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.12dCVE-2026-420079.1 CRI21.1%
——6An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.4dCVE-2026-2804—21.1%
——6——CVE-2025-24164—21.1%
——6——CVE-2025-24526—21.1%
——6——CVE-2026-197566.3 MED21.1%
——6A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.21dCVE-2026-199695.4 MED21.1%
——6A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Model Output Mesh Generator. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.18dCVE-2024-49663—21.1%
——6——CVE-2026-11847—21.1%
——6——CVE-2024-40975—21.1%
——6——CVE-2026-712358.8 HIG21.1%
——6Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).12dCVE-2026-28255—21.1%
——6——CVE-2020-9848—21.1%
——6——CVE-2022-38657—21.1%
——6——CVE-2026-140146.5 MED21.1%
——6Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)68d