Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,182
- High7,845
- Medium5,731
- Low553
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-31854—19.7%
——6——CVE-2025-10683—19.7%
——6——CVE-2026-40699—19.7%
——6——CVE-2026-547658.5 HIG19.7%
——6Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.59dCVE-2026-826184.3 MED19.7%
——6A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String Array Range Writing. This manipulation causes out-of-bounds read. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.5dCVE-2024-13427—19.7%
——6——CVE-2021-47294—19.7%
——6——CVE-2025-68940—19.7%
——6——CVE-2026-46416—19.7%
——6——CVE-2026-132426.5 MED19.7%
——6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.30dCVE-2022-47440—19.7%
——6——CVE-2023-48651—19.7%
——6——CVE-2026-481085.3 MED19.7%
——6Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, the server-side identification reader used the same permissive path as the client, allowing pre-banner lines from clients, and the reader did not enforce a bounded number of pre-banner lines. For a library server built on russh, this could allow a remote peer to hold connection setup resources in the cleartext pre-authentication phase with malformed identification input that should have been rejected early. This issue has been patched in version 0.61.0.44dCVE-2024-37176—19.7%
——6——CVE-2026-7708—19.7%
——6——CVE-2009-2135—19.7%
——6——CVE-2026-25418—19.7%
——6——CVE-2025-57971—19.7%
——6——CVE-2022-47155—19.7%
——6——CVE-2024-28781—19.7%
——6——CVE-2025-9947—19.7%
——6——CVE-2025-66116—19.7%
——6——CVE-2026-46668—19.7%
——6SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.44dCVE-2026-175296.3 MED19.7%
——6A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue.40dCVE-2015-10146—19.7%
——6——CVE-2022-49395—19.7%
——6——CVE-2020-28209—19.7%
——6——CVE-2026-801955.4 MED19.7%
——6Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can submit a malformed members payload; although Kimai returns a validation error, the existing membership rows have already been deleted. This bypasses the dedicated member-removal endpoint's protection against removing teamleaders and can leave a team with no members or teamleaders, disrupting team-based access control.2dCVE-2023-29569—19.7%
——6——CVE-2026-3621—19.7%
——6——CVE-2024-27593—19.7%
——6——CVE-2025-20116—19.7%
——6——CVE-2024-9174—19.7%
——6——CVE-2025-47291—19.7%
——6——CVE-2023-47807—19.7%
——6——CVE-2024-45289—19.7%
——6——CVE-2022-39948—19.7%
——6——CVE-2026-102776.3 MED19.7%
——6A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 89c091ecf8b9f9c7291d1af0b1966e271f86551c. It is suggested to install a patch to address this issue.45dCVE-2020-6158—19.7%
——6——CVE-2023-2790—19.7%
——6——