Vulnerabilities exploitable today
369,332in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,107
- High7,541
- Medium5,581
- Low536
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-41017—20.6%
——6——CVE-2026-810335.3 MED20.6%
——6Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address with no account raises an error that the global handler renders as a not-found status, while a registered address proceeds to send the reset message and returns no-content. The route is mounted without authentication. Submitting candidate addresses and comparing the two status codes therefore establishes which addresses hold accounts, with no credential and no rate limiting in the path.9dCVE-2025-14434—20.6%
——6——CVE-2024-140367.5 HIG20.6%
——6Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC packets to exhaust CPU resources in the affected process, causing further SDC messages to no longer be processed.46dCVE-2022-44513—20.6%
——6——CVE-2022-44512—20.6%
——6——CVE-2026-20114—20.6%
——6——CVE-2025-22386—20.6%
——6——CVE-2021-37436—20.6%
——6——CVE-2025-69234—20.6%
——6——CVE-2026-21944—20.6%
——6——CVE-2026-816987.5 HIG20.6%
——6openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.5dCVE-2021-479447.5 HIG20.6%
——6memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.44dCVE-2024-8487—20.6%
——6——CVE-2024-56240—20.6%
——6——CVE-2021-29038—20.6%
——6——CVE-2026-828569.8 CRI20.6%
——6@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails.4dCVE-2026-664158.5 HIG20.6%
——6Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC API endpoint to access cloud metadata services or read arbitrary files from the server filesystem.38dCVE-2026-668388.2 HIG20.6%
——6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connection's role. Ecto exposes the same option through Ecto.Repo.stream/2.
Postgrex appends the comment by concatenating it into the statement text sent in the Parse message, without escaping or rejecting */. The option is validated by comment_not_present!/1 at every other execution point; stream/4 never calls it. Because Parse accepts a single command, the injection is confined to the streamed statement and further statements cannot be chained.
This issue affects postgrex: from 0.19.3 before 0.22.4.20dCVE-2023-30300—20.6%
——6——CVE-2021-47971—20.6%
——6——CVE-2026-828579.8 CRI20.6%
——6hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.5dCVE-2025-22363—20.6%
——6——CVE-2025-12884—20.6%
——6——CVE-2026-84043.1 LOW20.6%
——6An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmed Badawe for reporting this issue.47dCVE-2024-46040—20.6%
——6——CVE-2024-56239—20.6%
——6——CVE-2025-12518—20.6%
——6——CVE-2026-1561—20.6%
——6——CVE-2024-11118—20.6%
——6——CVE-2024-355858.6 HIG20.6%
——6Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.4dCVE-2025-15062—20.6%
——6——CVE-2019-11867—20.6%
——6——CVE-2025-10354—20.6%
——6——CVE-2026-71191—20.6%
——6In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.31dCVE-2018-25380—20.6%
——6——CVE-2026-7768—20.6%
——6——CVE-2003-1460—20.6%
——6——CVE-2022-49611—20.6%
——6——CVE-2022-49297—20.6%
——6——