Vulnerabilities exploitable today
369,308in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,127
- High7,592
- Medium5,602
- Low538
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41339—20.5%
——6——CVE-2026-824537.5 HIG20.5%
——6rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.8dCVE-2025-24136—20.5%
——6——CVE-2026-39519—20.5%
——6——CVE-2026-202688.6 HIG20.5%
——6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.23dCVE-2023-390613.5 LOW20.5%
——6Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.60dCVE-2025-69337—20.5%
——6——CVE-2024-3109—20.5%
——6——CVE-2023-449157.1 HIG20.5%
——6A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login_error parameter.64dCVE-2026-281429.3 CRI20.5%
——6Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.23dCVE-2026-48886—20.5%
——6——CVE-2025-41443—20.5%
——6——CVE-2025-52358—20.5%
——6——CVE-2026-25340—20.5%
——6——CVE-2026-166474.1 MED20.5%
——6Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.2dCVE-2024-33980—20.5%
——6——CVE-2026-54812—20.5%
——6——CVE-2026-655089.3 CRI20.5%
——6Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.25dCVE-2025-69306—20.5%
——6——CVE-2023-43656—20.5%
——6——CVE-2025-47528—20.5%
——6——CVE-2026-1844—20.5%
——6——CVE-2024-5520—20.5%
——6——CVE-2025-45737—20.5%
——6——CVE-2024-41584—20.5%
——6——CVE-2025-4411—20.5%
——6——CVE-2025-31063—20.5%
——6——CVE-2024-6358—20.5%
——6——CVE-2026-760334.2 MED20.5%
——6Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)17dCVE-2025-62288—20.5%
——6——CVE-2024-38654—20.5%
——6——CVE-2024-38870—20.5%
——6——CVE-2026-26328—20.5%
——6——CVE-2025-49312—20.5%
——6——CVE-2026-143915.3 MED20.5%
——6Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)66dCVE-2024-13043—20.5%
——6——CVE-2026-44498—20.5%
——6——CVE-2026-32005—20.5%
——6——CVE-2026-7050—20.5%
——6——CVE-2026-632999.9 CRI20.5%
——6An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.9d