Vulnerabilities exploitable today
369,139in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,634
Distribution · last window
- Critical2,182
- High7,846
- Medium5,731
- Low553
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-480124.3 MED19.5%
——6Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's `Referer` header and uses that value as the redirect destination. In the validated behavior, the server does not restrict that fallback target to same-origin URLs, does not require a relative path, and does not reject dangerous schemes such as `javascript:`. As a result, an unauthenticated request can turn this endpoint into a reusable redirect primitive whose destination is fully controlled by attacker-supplied request metadata. The security problem is not limited to a harmless navigation mismatch. The endpoint sits under `/api/oauth/`, which gives the redirect a trustworthy application-controlled origin and makes it suitable for phishing chains, branded redirect abuse, and cases where client software automatically follows redirects issued by a trusted host. The attached evidence also shows that the response is not only an HTTP `302` with a user-controlled `Location` header. The HTML body contains a matching meta refresh tag and redirect link built from the same attacker-controlled value. In the validated proof, the endpoint redirects to `https://attacker.example/poc` when that URL is supplied through `Referer`, and it also reflects `javascript:alert(1)` into `Location` and the HTML redirect body without any scheme filtering. This report therefore stays conservative and claims an open redirect with arbitrary redirect targets, while noting that the lack of scheme restrictions makes the behavior materially worse than a same-scheme external redirect. Version 6.7.10.1 fixes the issue.39dCVE-2026-27067—19.5%
——6——CVE-2025-55708—19.5%
——6——CVE-2025-45751—19.5%
——6——CVE-2026-580808.2 HIG19.5%
——6In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permission checks, allowing an anonymous client where anonymous sessions are permitted to read role-permission metadata, invoke protected methods, or delete protected nodes.31dCVE-2026-37429—19.5%
——6——CVE-2023-42756—19.5%
——6——CVE-2025-70994—19.5%
——6——CVE-2025-37850—19.5%
——6——CVE-2024-47429—19.5%
——6——CVE-2024-47427—19.5%
——6——CVE-2019-14629—19.5%
——6——CVE-2025-44180—19.5%
——6——CVE-2025-28937—19.5%
——6——CVE-2023-40361—19.5%
——6——CVE-2025-21155—19.5%
——6——CVE-2025-40941—19.5%
——6——CVE-2022-495537.8 HIG19.5%
——6In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate BOOT sectors_per_clusters
When the NTFS BOOT sectors_per_clusters field is > 0x80, it represents a
shift value. Make sure that the shift value is not too large before using
it (NTFS max cluster size is 2MB). Return -EVINVAL if it too large.
This prevents negative shift values and shift values that are larger than
the field size.
Prevents this UBSAN error:
UBSAN: shift-out-of-bounds in ../fs/ntfs3/super.c:673:16
shift exponent -192 is negative32dCVE-2021-418398.2 HIG19.5%
——6An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.25dCVE-2026-53843—19.5%
——6——CVE-2020-4278—19.5%
——6——CVE-2025-44998—19.5%
——6——CVE-2025-12465—19.5%
——6——CVE-2022-41858—19.5%
——6——CVE-2026-74869.8 CRI19.5%
——6Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection.
This issue affects E-İmar: from 2.10.1.0 before 3.0.2.44dCVE-2026-610153.7 LOW19.5%
——6Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).33dCVE-2023-31425—19.5%
——6——CVE-2025-11814—19.5%
——6——CVE-2018-5718—19.5%
——6——CVE-2025-11879—19.5%
——6——CVE-2025-44181—19.5%
——6——CVE-2024-47428—19.5%
——6——CVE-2024-47432—19.5%
——6——CVE-2026-78749.1 CRI19.5%
——6IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.65dCVE-2024-38752—19.5%
——6——CVE-2024-47430—19.5%
——6——CVE-2026-153128.8 HIG19.5%
——6The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and omitting any `promote_users` capability check before passing the sanitized value directly to `WP_User::set_role()`. This makes it possible for authenticated attackers with `ndpv_manager`-level access and above to create a new WordPress user account with the `administrator` role assigned, achieving full vertical privilege escalation. The `ndpv_manager` capability is a sub-administrator CRM team role granted by Propovoice itself, meaning the attack surface extends beyond site administrators to any user the plugin has elevated to a manager position.16dCVE-2023-45588—19.5%
——6——CVE-2025-30148—19.5%
——6——CVE-2025-44183—19.5%
——6——