Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13734—20.9%
——6——CVE-2022-45448—20.9%
——6——CVE-2025-34519—20.9%
——6——CVE-2025-10366—20.9%
——6——CVE-2026-50887—20.9%
——6——CVE-2024-35280—20.9%
——6——CVE-2026-41394—20.9%
——6——CVE-2024-44179—20.9%
——6——CVE-2026-32498—20.9%
——6——CVE-2025-41013—20.9%
——6——CVE-2026-6356—20.9%
——6——CVE-2025-0254—20.9%
——6——CVE-2026-81931—20.9%
——6Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Seller role) to execute arbitrary JavaScript in the application origin. The photo validation rule classifies the file only by its content (magic bytes) and rejects only a fixed list of PHP extensions, while ProductSaveController::save() names the stored file using the client-supplied extension and copies it into the public web root. A file that begins with an image header and carries an HTML extension passes validation, is stored under public/asset/upload/product/, and is served with a text/html content type, turning the upload into first-party stored script execution.6dCVE-2026-32495—20.9%
——6——CVE-2025-5757—20.9%
——6——CVE-2026-519779.1 CRI20.9%
——6An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component7dCVE-2026-17595—20.9%
——6Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.6dCVE-2026-841957.7 HIG20.9%
——6Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or attacker-controlled endpoints, gaining full control over Kyverno policies and cluster resources.6dCVE-2026-28076—20.9%
——6——CVE-2026-20985—20.9%
——6——CVE-2026-25309—20.9%
——6——CVE-2024-7244—20.9%
——6——CVE-2021-21526—20.9%
——6——CVE-2011-1822—20.9%
——6——CVE-2025-1533—20.9%
——6——CVE-2026-24565—20.9%
——6——CVE-2023-34326—20.9%
——6——CVE-2025-5764—20.9%
——6——CVE-2008-7207—20.9%
——6——CVE-2026-664256.5 MED20.9%
——6Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.26dCVE-2024-26900—20.9%
——6——CVE-2026-740207.5 HIG20.9%
——6Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.18dCVE-2012-0450—20.9%
——6——CVE-2026-632594.3 MED20.8%
——6Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.35dCVE-2026-50885—20.9%
——6——CVE-2003-1476—20.9%
——6——CVE-2025-14778—20.9%
——6——CVE-2023-32377—20.9%
——6——CVE-2011-5066—20.9%
——6——CVE-2024-6284—20.9%
——6——