Vulnerabilities exploitable today
369,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,158
- High7,692
- Medium5,631
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-18768—19.8%
——6——CVE-2024-32787—19.8%
——6——CVE-2025-40742—19.8%
——6——CVE-2024-32783—19.8%
——6——CVE-2026-396895.3 MED19.8%
——6Missing Authorization vulnerability in eshipper eShipper Commerce eshipper-commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eShipper Commerce: from n/a through <= 2.16.12.43dCVE-2025-10289—19.8%
——6——CVE-2026-49156.5 MED19.8%
——6Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (server process termination) via a crafted webhook callback response containing a null attachment entry.. Mattermost Advisory ID: MMSA-2026-0064144dCVE-2018-5871—19.8%
——6——CVE-2026-487446.5 MED19.8%
——6Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate() mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType() and translation() queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.17dCVE-2022-50716—19.8%
——6——CVE-2024-33978—19.8%
——6——CVE-2022-50733—19.8%
——6——CVE-2026-805998.1 HIG19.8%
——6In the Linux kernel, the following vulnerability has been resolved:
batman-adv: dat: ensure accessible eth_hdr proto field
When batadv_get_vid() accesses the proto field of the ethernet header, it
is not checking if the data itself is accessible. The caller is responsible
for it. But in contrast to other call sites, batadv_dat_get_vid() and its
caller didn't make sure this is true. This could have caused an
out-of-bounds access.8dCVE-2023-54044—19.8%
——6——CVE-2022-21513—19.8%
——6——CVE-2024-37946—19.8%
——6——CVE-2024-11097—19.8%
——6——CVE-2020-12981—19.8%
——6——CVE-2021-31231—19.8%
——6——CVE-2024-20533—19.8%
——6——CVE-2025-63446—19.8%
——6——CVE-2026-25336—19.8%
——6——CVE-2024-52905—19.8%
——6——CVE-2026-25348—19.8%
——6——CVE-2024-46083—19.8%
——6——CVE-2026-440735.0 MED19.8%
——6Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.44dCVE-2026-324718.5 HIG19.8%
——6Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.12dCVE-2026-729157.5 HIG19.8%
——6Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collection policy namespace. The exposed data included the other user's current email address and last-used IP address. This issue is fixed in versions 4.6.4 and 4.7.0-beta.1.25dCVE-2024-10891—19.8%
——6——CVE-2024-20534—19.8%
——6——CVE-2023-52649—19.8%
——6——CVE-2025-11725—19.8%
——6——CVE-2025-63447—19.8%
——6——CVE-2025-63448—19.8%
——6——CVE-2024-3543—19.8%
——6——CVE-2024-32784—19.8%
——6——CVE-2026-306894.3 MED19.8%
——6In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not offer an API service.65dCVE-2024-20514—19.8%
——6——CVE-2026-45666—19.8%
——6——CVE-2018-6975—19.8%
——6——