Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,627
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-37097—21.1%
——6——CVE-2023-46048—21.1%
——6——CVE-2026-111168.8 HIG21.1%
——6Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)46dCVE-2025-14056—21.1%
——6——CVE-2024-56087—21.1%
——6——CVE-2024-35737—21.1%
——6——CVE-2024-42422—21.0%
——6——CVE-2026-78864.3 MED21.0%
——6Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation controllers accept user-supplied file attachment IDs and load files directly via `$em->find(File::class, $attachmentID)` without checking per-file permissions (`canViewFile()`). A user who can post in any conversation can reference any file in the CMS file manager by its sequential ID, effectively bypassing the file permission system. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with a vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Mandani for reporting. if a site truly has private files, the owner should set up a private storage location https://documentation.concretecms.org/user-guide/editors-reference/dashboard/system-and-maintenance/files/file-storage-locations outside of the webroot so that permissions can be checked on view as well. That way, even if a authorized user attaches a file, or otherwise links to it, unauthorized users won't be able to view the file.46dCVE-2025-32114—21.0%
——6——CVE-2026-9177—21.0%
——6A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This
flaw
allows an attacker with admin privileges to inject arbitrary Java code expressions, which are
executed server-side when the template is rendered (i.e., during email
sending). Successful exploitation of this flaw allows an attacker to
execute
arbitrary code on the server that results in full host compromise.
This issue affects all Axway SecureTransport versions prior 5.5-20260528 update.39dCVE-2020-4372—21.0%
——6——CVE-2005-3106—21.0%
——6——CVE-2023-45734—21.0%
——6——CVE-2026-164097.5 HIG21.0%
——6Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.45dCVE-2026-38808—21.0%
——6——CVE-2026-4082—21.0%
——6——CVE-2025-7638—21.0%
——6——CVE-2025-68569—21.0%
——6——CVE-2024-32547—21.0%
——6——CVE-2025-0820—21.0%
——6——CVE-2024-47506—21.0%
——6——CVE-2025-32116—21.0%
——6——CVE-2025-59575—21.0%
——6——CVE-2024-24840—21.0%
——6——CVE-2026-39546—21.0%
——6——CVE-2026-349329.3 CRI21.0%
——6hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.45dCVE-2025-655948.1 HIG21.0%
——6OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.65dCVE-2025-22035—21.0%
——6——CVE-2026-72904—21.0%
——6Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied JSON schemas in apps/api/src/lib/extract/helpers/dereference-schema.ts. The affected code invokes the json-schema-ref-parser dependency with default resolver settings, allowing external and local file references to be resolved during schema processing. An authenticated attacker can supply a malicious schema containing a $ref within default, const, or enum fields that are not traversed by AJV validation. By triggering a dereference error, file contents from the extract worker filesystem may be included in persisted error messages returned through the extraction API, enabling arbitrary file reads and SSRF against internal or external HTTP endpoints. This issue is fixed in version 2.11.32.27dCVE-2026-826772.4 LOW21.0%
——6A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.7dCVE-2026-2801—21.0%
——6——CVE-2026-207668.8 HIG21.0%
——6An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.49dCVE-2024-10477—21.0%
——6——CVE-2026-39977—21.0%
——6——CVE-2026-712438.8 HIG21.0%
——6The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = "mkdir -p " + path.join(info.destination, info.name) + "; " - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an argument array.12dCVE-2025-67976—21.0%
——6——CVE-2024-10014—21.0%
——6——CVE-2021-42254—21.0%
——6——CVE-2024-50548—21.0%
——6——CVE-2025-21571—21.0%
——6——