Vulnerabilities exploitable today
369,346in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,106
- High7,541
- Medium5,585
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-31325—20.7%
——6——CVE-2025-43838—20.7%
——6——CVE-2026-631786.5 MED20.7%
——6Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py call update_user_group and add_users_to_user_group in ee/onyx/db/user_group.py without enforcing _validate_curator_can_modify_group, allowing a curator to add accounts to arbitrary groups and obtain document access through get_acl_for_user and the OpenSearch access_control_list filter. This issue is fixed in version 4.3.0.20dCVE-2025-65502—20.7%
——6——CVE-2024-12214—20.7%
——6——CVE-2026-445855.4 MED20.7%
——6Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request. An attacker could modify the service ID value in the client-side request and successfully create a ticket associated with another user's service.
The vulnerability requires authentication and does not provide direct access to service contents or customer data. However, referenced service information could become visible to support personnel handling the ticket. Successful exploitation could allow an authenticated user to: create support tickets referencing services belonging to other users, potentially cause support staff to interact with or review unrelated customer services. The vulnerability did not allow direct access to another user's service, modification of another user's service or retrieval of confidential service data through the vulnerable endpoint itself. This issue has been fixed in version 1.5.0.45dCVE-2025-10209—20.7%
——6——CVE-2026-436785.3 MED20.7%
——6An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.9dCVE-2025-47580—20.7%
——6——CVE-2024-11464—20.7%
——6——CVE-2026-44430—20.7%
——6——CVE-2025-59187—20.7%
——6——CVE-2026-168798.8 HIG20.7%
——6IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.17dCVE-2020-27797—20.7%
——6——CVE-2026-647969.8 CRI20.7%
——6Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.41dCVE-2025-56448—20.7%
——6——CVE-2025-12039—20.7%
——6——CVE-2011-0452—20.7%
——6——CVE-2025-63617—20.7%
——6——CVE-2023-30853—20.7%
——6——CVE-2026-32252—20.6%
——6——CVE-2026-73405—20.7%
——6An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint.
The token_required decorator used by the Pub/Sub interface authenticated requests solely by matching the X-API-KEY header against an existing user API key. Unlike the REST API authentication mechanism, it did not verify the account's is_active and is_confirmed state.
Because the self-registration process issues an API key before account confirmation is completed, an attacker could create an account and immediately use the resulting API key to access Pub/Sub topics that should only be available to active, confirmed users. This could expose stream events that would otherwise be inaccessible through the REST API, including newly submitted or not-yet-moderated data such as comments.
The vulnerability results from inconsistent authorization enforcement between the REST API and the SSE streaming interface.
The patch corrects the issue by requiring accounts to be both active and confirmed before permitting access to Pub/Sub streams, bringing the SSE authorization boundary in line with the REST API.11dCVE-2025-30112—20.7%
——6——CVE-2002-0889—20.7%
——6——CVE-2021-3440—20.7%
——6——CVE-2025-10915—20.7%
——6——CVE-2026-28136—20.7%
——6——CVE-2025-21127—20.7%
——6——CVE-2024-36792—20.7%
——6——CVE-2026-41245.4 MED20.7%
——6The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler only verifies a nonce (check_ajax_referer) but performs no capability checks via current_user_can(). Furthermore, the nonce ('ziggeo_ajax_nonce') is exposed to all logged-in users on every page via the wp_head and admin_head hooks . This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke multiple administrative operations including: saving arbitrary translation strings (translations_panel_save_strings via update_option('ziggeo_translations')), creating/updating/deleting event templates (event_editor_save_template/update_template/remove_template via update_option('ziggeo_events')), modifying SDK application settings (sdk_applications operations), and managing notifications (notification_handler via update_option('ziggeo_notifications')).44dCVE-2025-13378—20.7%
——6——CVE-2024-53763—20.7%
——6——CVE-2023-21450—20.7%
——6——CVE-2025-2341—20.7%
——6——CVE-2024-22562—20.7%
——6——CVE-2026-15318.1 HIG20.7%
——6A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information.54dCVE-2025-8976—20.7%
——6——CVE-2025-5702—20.7%
——6——CVE-2020-27798—20.7%
——6——CVE-2026-23469.8 CRI20.7%
——6Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.
This issue affects Mobile App: through 12.05.2026.11d