Vulnerabilities exploitable today
369,346in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,106
- High7,542
- Medium5,585
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2002-0889—20.7%
——6——CVE-2025-30112—20.7%
——6——CVE-2025-10915—20.7%
——6——CVE-2026-73405—20.7%
——6An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint.
The token_required decorator used by the Pub/Sub interface authenticated requests solely by matching the X-API-KEY header against an existing user API key. Unlike the REST API authentication mechanism, it did not verify the account's is_active and is_confirmed state.
Because the self-registration process issues an API key before account confirmation is completed, an attacker could create an account and immediately use the resulting API key to access Pub/Sub topics that should only be available to active, confirmed users. This could expose stream events that would otherwise be inaccessible through the REST API, including newly submitted or not-yet-moderated data such as comments.
The vulnerability results from inconsistent authorization enforcement between the REST API and the SSE streaming interface.
The patch corrects the issue by requiring accounts to be both active and confirmed before permitting access to Pub/Sub streams, bringing the SSE authorization boundary in line with the REST API.11dCVE-2025-59187—20.7%
——6——CVE-2020-27797—20.7%
——6——CVE-2026-168798.8 HIG20.7%
——6IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.17dCVE-2024-11464—20.7%
——6——CVE-2026-44430—20.7%
——6——CVE-2025-56448—20.7%
——6——CVE-2026-647969.8 CRI20.7%
——6Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.41dCVE-2026-171837.1 HIG20.7%
——6An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.6dCVE-2026-28799—20.7%
——6——CVE-2022-43655—20.7%
——6——CVE-2026-6358—20.7%
——6——CVE-2021-3701—20.7%
——6——CVE-2022-3061—20.7%
——6——CVE-2024-11807—20.7%
——6——CVE-2026-764005.9 MED20.7%
——6In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches until event delivery stops. The vulnerability is possible because HTTP Event Collector delivery retry handling uses an unbounded default for failed batches instead of a finite retry limit. For more information see Install Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/install/install-splunk-connect-for-kafka), Data ingestion parameters for Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/overview/data-ingestion-parameters-for-splunk-connect-for-kafka), and Set up and use HTTP Event Collector with configuration files (https://help.splunk.com/en/splunk-enterprise/get-data-in/get-started-with-getting-data-in/9.4/get-data-with-http-event-collector/set-up-and-use-http-event-collector-with-configuration-files) in the Splunk documentation.13dCVE-2025-15279—20.7%
——6——CVE-2025-3452—20.6%
——6——CVE-2024-6578—20.7%
——6——CVE-2026-6768—20.7%
——6——CVE-2023-31761—20.7%
——6——CVE-2024-10588—20.7%
——6——CVE-2024-4330—20.7%
——6——CVE-2022-35166—20.7%
——6——CVE-2022-488167.8 HIG20.7%
——6In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: lock against ->sock changing during sysfs read
->sock can be set to NULL asynchronously unless ->recv_mutex is held.
So it is important to hold that mutex. Otherwise a sysfs read can
trigger an oops.
Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before
handling sysfs reads") appears to attempt to fix this problem, but it
only narrows the race window.34dCVE-2025-63617—20.7%
——6——CVE-2024-3262—20.7%
——6——CVE-2025-3959—20.6%
——6——CVE-2026-109697.5 HIG20.7%
——6Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)46dCVE-2026-32204—20.7%
——6——CVE-2023-30853—20.7%
——6——CVE-2025-12039—20.7%
——6——CVE-2026-39315—20.7%
——6——CVE-2020-27798—20.7%
——6——CVE-2025-8365—20.7%
——6——CVE-2025-5702—20.7%
——6——CVE-2026-23469.8 CRI20.7%
——6Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.
This issue affects Mobile App: through 12.05.2026.11d