Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,397
- High9,640
- Medium5,594
- Low550
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-395696.5 MED18.7%
——6Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.40dCVE-2024-25021—18.7%
——6——CVE-2026-1235—18.7%
——6——CVE-2026-673376.5 MED18.7%
——6better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.30dCVE-2024-3811—18.7%
——6——CVE-2002-1915—18.7%
——6——CVE-2020-25678—18.7%
——6——CVE-2022-35611—18.7%
——6——CVE-2024-45647—18.7%
——6——CVE-2009-2644—18.7%
——6——CVE-2025-28875—18.7%
——6——CVE-2024-36372—18.7%
——6——CVE-2006-6476—18.7%
——6——CVE-2020-1729—18.7%
——6——CVE-2020-3476—18.7%
——6——CVE-2025-26400—18.7%
——6——CVE-2025-3548—18.7%
——6——CVE-2024-20054—18.7%
——6——CVE-2025-52533—18.7%
——6——CVE-2025-63939—18.7%
——6——CVE-2001-1047—18.7%
——6——CVE-2025-8515—18.7%
——6——CVE-2025-14627—18.7%
——6——CVE-2012-6136—18.7%
——6——CVE-2018-4339—18.7%
——6——CVE-2023-3972—18.7%
——6——CVE-2023-0240—18.7%
——6——CVE-2009-0268—18.7%
——6——CVE-2021-1492—18.7%
——6——CVE-2011-2060—18.7%
——6——CVE-2015-1525—18.7%
——6——CVE-2022-46828—18.7%
——6——CVE-2026-558344.3 MED18.7%
——6Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+page.svelte uses the raw callbackURL in redirectWithError when prompt=none cannot complete silent authorization. The client-side path only blocks javascript and data schemes and does not invoke the backend callback allow-list validation, so an unauthenticated attacker who knows a valid client_id can redirect a victim browser to an arbitrary HTTP or HTTPS origin for phishing or OIDC error and state smuggling. This issue is fixed in version 2.9.0.5dCVE-2020-13481—18.7%
——6——CVE-2023-52975—18.7%
——6——CVE-2026-0751—18.7%
——6——CVE-2024-23219—18.7%
——6——CVE-2022-47927—18.7%
——6——CVE-2024-47486—18.7%
——6——CVE-2026-5341—18.7%
——6——