Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-622356.3 MED20.9%
——6Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update, delete, and export objects from any directory lacking an explicit permissions configuration, bypassing intended authorization controls.52dCVE-2025-22578—20.9%
——6——CVE-2022-22187—20.9%
——6——CVE-2026-33893—20.9%
——6——CVE-2024-49646—20.9%
——6——CVE-2025-24340—20.9%
——6——CVE-2024-40913—20.9%
——6——CVE-2018-5718—20.9%
——6——CVE-2025-10682—20.9%
——6——CVE-2026-35628—20.9%
——6——CVE-2023-52973—20.9%
——6——CVE-2023-41942—20.9%
——6——CVE-2025-29719—20.9%
——6——CVE-2026-54209—20.9%
——6Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by
including the string "(editini)" in the file path, writing the new
password to the specified "Archive.ini" file. However, the application
does not verify that the provided path actually refers to an
"Archive.ini" file. If an attacker specifies a different file with
excessive size, a buffer overflow occurs. This vulnerability allows an
unauthenticated attacker to crash the server, resulting in denial of
service. This issue affects TeamDavid through Rollout 524.12dCVE-2026-535008.2 HIG20.9%
——6Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.38dCVE-2024-1816—20.9%
——6——CVE-2026-44330—20.9%
——6——CVE-2024-42000—20.9%
——6——CVE-2025-10029—20.9%
——6——CVE-2023-47093—20.9%
——6——CVE-2025-48395—20.9%
——6——CVE-2024-51698—20.9%
——6——CVE-2025-10028—20.9%
——6——CVE-2022-34740—20.9%
——6——CVE-2025-68979—20.9%
——6——CVE-2026-771896.5 MED20.9%
——6The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection via 'order' Shortcode Attribute in all versions up to, and including, 1.8.12.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The [charitable_donors] shortcode is accessible to Contributor-level users via draft or pending post previews, providing an authenticated but low-privileged entry point for exploitation.5dCVE-2024-51704—20.9%
——6——CVE-2025-8039—20.9%
——6——CVE-2024-8632—20.9%
——6——CVE-2025-5264—20.9%
——6——CVE-2025-45264.3 MED20.9%
——6A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue. It is suggested to upgrade the affected component. The action taken by the vendor is: "Review and correction of controls related to the exposure of user information in the product configuration interface." The vulnerabilities are limited to NGC Explorer and do not affect other Dígitro products, including UNA and Guardião.38dCVE-2022-43255—20.9%
——6——CVE-2024-51696—20.9%
——6——CVE-2025-3007—20.9%
——6——CVE-2024-2861—20.9%
——6——CVE-2025-10027—20.9%
——6——CVE-2024-38694—20.9%
——6——CVE-2026-729086.5 MED20.9%
——6ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an authenticated low-privilege user to inject SQL and extract sensitive information. This issue is fixed in versions 15.109.0 and 16.20.0.26dCVE-2016-2877—20.9%
——6——CVE-2026-107053.1 LOW20.9%
——6A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.47d