Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,397
- High9,645
- Medium5,598
- Low550
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-11853—18.7%
——6——CVE-2022-49359—18.7%
——6——CVE-2026-47348—18.7%
——6Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.41dCVE-2015-2234—18.7%
——6——CVE-2021-47145—18.7%
——6——CVE-2026-40910—18.7%
——6——CVE-2022-48866—18.7%
——6——CVE-2025-54475—18.7%
——6——CVE-2025-281726.5 MED18.7%
——6Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force attack.59dCVE-2026-451234.3 MED18.7%
——6MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in fetch_remote_file() fails open when get_ip_by_hostname() returns no result because that function does not return IPv6 results, allowing a crafted remote target to bypass the host restriction. The uniquely identifying implementation details include fail-open verification, and inc/functions.php. This issue is fixed in version 1.8.40.15dCVE-2025-54214—18.7%
——6——CVE-2024-9245—18.7%
——6——CVE-2026-34264—18.7%
——6——CVE-2025-54227—18.7%
——6——CVE-2026-747918.6 HIG18.7%
——6Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.2dCVE-2019-2115—18.7%
——6——CVE-2022-0168—18.7%
——6——CVE-2020-15137—18.7%
——6——CVE-2025-3087—18.7%
——6——CVE-2024-27883—18.7%
——6——CVE-2026-179508.8 HIG18.7%
——6Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)33dCVE-2026-41237—18.7%
——6Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escaping. Version 2.3.7 contains an updated patch.42dCVE-2026-561135.3 MED18.7%
——6dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or impersonating a DHCPv6 server can trigger dhcp6_deprecatedele() to free a delegated child address while an outer TAILQ_FOREACH_SAFE iterator in dhcp6_deprecateaddrs() still holds the freed pointer, causing a use-after-free when TAILQ_REMOVE is reached.49dCVE-2026-332408.8 HIG18.7%
——6Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.8dCVE-2026-7011—18.7%
——6——CVE-2026-559998.5 HIG18.7%
——6Local attackers with a X connection able to provide PCX fonts to the X
server xorg-server before 21.2.24 and xwayland before 24.1.13 could
cause a heap buffer overflow via SetFont due to missing glyph boundary checks.55dCVE-2026-790224.3 MED18.7%
——6UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)5dCVE-2026-27663—18.7%
——6——CVE-2026-455435.3 MED18.7%
——6Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.42dCVE-2020-36623—18.7%
——6——CVE-2026-34565—18.7%
——6——CVE-2019-25707—18.7%
——6——CVE-2025-56747—18.7%
——6——CVE-2026-15576—18.7%
——6Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.7dCVE-2026-34567—18.7%
——6——CVE-2025-5267—18.7%
——6——CVE-2024-20046—18.7%
——6——CVE-2025-24969—18.7%
——6——CVE-2025-59815—18.7%
——6——CVE-2024-31299—18.7%
——6——