Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,182
- High7,848
- Medium5,731
- Low553
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13362—19.7%
——6——CVE-2025-49189—19.7%
——6——CVE-2025-65089—19.7%
——6——CVE-2025-36625—19.7%
——6——CVE-2025-538318.2 HIG19.7%
——6DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receive a patch.61dCVE-2021-33436—19.7%
——6——CVE-2025-66553—19.7%
——6——CVE-2026-102696.3 MED19.7%
——6A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 0.4.1 is capable of addressing this issue. The identifier of the patch is 428e2c045cb9c0eb8080e8b580471a9c2eaa95ca. Upgrading the affected component is recommended.45dCVE-2009-2135—19.7%
——6——CVE-2026-226818.5 HIG19.7%
——6OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.15dCVE-2025-26991—19.7%
——6——CVE-2026-89896.8 MED19.7%
——6Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.23dCVE-2023-52490—19.7%
——6——CVE-2026-9053—19.7%
——6Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.44dCVE-2026-26697—19.7%
——6——CVE-2019-8533—19.7%
——6——CVE-2026-62382—19.7%
——6PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the deletable_by_viewer restriction is never enforced. An attacker who knows only the secret URL can permanently delete an anonymous push even when the creator disabled viewer deletion and even without the passphrase. Only deployments that allow anonymous pushes (the default) are affected. The issue is fixed in v2.9.6.5dCVE-2026-30881—19.7%
——6——CVE-2026-783768.8 HIG19.7%
——6A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.8dCVE-2026-680009.8 CRI19.7%
——6The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet keywords like CREATE/TABLE/SET/PREPARE/EXECUTE are not included in the list, allowing for bypassing. Attackers can execute stacked SQL statements without logging in.4dCVE-2026-4734—19.7%
——6——CVE-2018-254138.2 HIG19.7%
——6AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.45dCVE-2025-12427—19.7%
——6——CVE-2020-37242—19.7%
——6——CVE-2025-23473—19.7%
——6——CVE-2026-853888.1 HIG19.7%
——6Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947.2dCVE-2025-23648—19.7%
——6——CVE-2011-1056—19.7%
——6——CVE-2021-22636—19.7%
——6——CVE-2025-23481—19.7%
——6——CVE-2026-26698—19.7%
——6——CVE-2025-23494—19.7%
——6——CVE-2023-27465—19.7%
——6——CVE-2026-2105—19.7%
——6——CVE-2025-58240—19.7%
——6——CVE-2025-15199—19.7%
——6——CVE-2025-22760—19.7%
——6——CVE-2025-32116—19.7%
——6——CVE-2024-36613—19.7%
——6——CVE-2024-41785—19.7%
——6——