Vulnerabilities exploitable today
369,308in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,141
- High7,633
- Medium5,637
- Low545
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-57498—20.4%
——6——CVE-2026-712417.5 HIG20.4%
——6Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers, the entire student database can be enumerated without authentication.11dCVE-2026-733878.1 HIG20.4%
——6Unauthenticated Local File Inclusion in Resido <= 1.5 versions.17dCVE-2021-31637—20.4%
——6——CVE-2024-36366—20.4%
——6——CVE-2026-72759—20.4%
——6In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated conversion lookup returns None. The previous logic only denied access when the conversion object existed and the visibility check failed. As a result, deleted conversions bypassed the authorization check and their retained history input/output could be disclosed to a user able to request the corresponding history entry. The July 22, 2026 commit changes the logic to deny access whenever the conversion is missing or the requester lacks permission11dCVE-2025-67856—20.4%
——6——CVE-2024-13366—20.4%
——6——CVE-2026-144184.3 MED20.4%
——6Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)66dCVE-2026-2782—20.4%
——6——CVE-2023-7043—20.4%
——6——CVE-2022-32579—20.4%
——6——CVE-2024-54352—20.4%
——6——CVE-2026-465108.2 HIG20.4%
——6form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose name starts with __proto__[...] causes the library to mutate Object.prototype, which is a prototype pollution primitive of the entire Node.js process. This vulnerability is fixed in 1.0.1.47dCVE-2024-20138—20.4%
——6——CVE-2024-22475—20.4%
——6——CVE-2026-24603—20.4%
——6——CVE-2019-9013—20.4%
——6——CVE-2024-20486—20.4%
——6——CVE-2023-40520—20.4%
——6——CVE-2025-14635—20.4%
——6——CVE-2025-54108—20.4%
——6——CVE-2020-3948—20.4%
——6——CVE-2026-134607.5 HIG20.4%
——6IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.20dCVE-2025-58668—20.4%
——6——CVE-2024-35886—20.4%
——6——CVE-2025-46299—20.4%
——6——CVE-2025-8617—20.4%
——6——CVE-2025-13497—20.4%
——6——CVE-2026-178204.3 MED20.4%
——6Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)34dCVE-2022-49673—20.4%
——6——CVE-2026-148176.8 MED20.4%
——6The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.11dCVE-2024-27303—20.4%
——6——CVE-2024-42070—20.4%
——6——CVE-2020-5974—20.4%
——6——CVE-2026-480535.8 MED20.4%
——6Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report identified two endpoints on the `RemoteFacilityUser*` viewsets; remediation review found two further reflection points on the same pattern. The GET endpoint was unauthenticated. Version 0.19.4 fixes the vulnerability.20dCVE-2026-177754.3 MED20.4%
——6Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2026-178294.3 MED20.4%
——6Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)34dCVE-2026-47344—20.4%
——6When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.45dCVE-2025-4671—20.4%
——6——