Vulnerabilities exploitable today
367,851in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,393
- High9,631
- Medium5,587
- Low548
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-325977.5 HIG18.6%
——6PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.16dCVE-2025-8050—18.6%
——6——CVE-2024-31583—18.6%
——6——CVE-2026-41648—18.6%
——6——CVE-2024-29019—18.6%
——6——CVE-2026-45039—18.6%
——6——CVE-2024-28021—18.6%
——6——CVE-2026-6189—18.6%
——6——CVE-2026-40108—18.6%
——6GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.41dCVE-2026-4495—18.6%
——6——CVE-2024-41752—18.6%
——6——CVE-2026-10696—18.6%
——6——CVE-2024-10324—18.6%
——6——CVE-2024-26852—18.6%
——6——CVE-2022-48815—18.6%
——6——CVE-2026-29078—18.6%
——6——CVE-2021-0190—18.6%
——6——CVE-2024-11503—18.6%
——6——CVE-2020-0466—18.6%
——6——CVE-2022-47339—18.6%
——6——CVE-2026-22541—18.6%
——6——CVE-2025-10642—18.6%
——6——CVE-2026-43291—18.6%
——6——CVE-2022-48811—18.6%
——6——CVE-2024-36478—18.6%
——6——CVE-2024-36121—18.6%
——6——CVE-2026-726658.1 HIG18.6%
——6Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.5dCVE-2026-186947.1 HIG18.6%
——6An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose a limited amount of server process memory.4dCVE-2016-0818—18.6%
——6——CVE-2025-29621—18.6%
——6——CVE-2026-101787.3 HIG18.6%
——6A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.42dCVE-2024-30106—18.6%
——6——CVE-2025-29429—18.6%
——6——CVE-2022-3893—18.6%
——6——CVE-2026-12048—18.6%
——6——CVE-2021-0188—18.6%
——6——CVE-2026-8172—18.6%
——6——CVE-2026-325589.8 CRI18.6%
——6Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.9dCVE-2026-115827.3 HIG18.6%
——6A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.41dCVE-2026-21956—18.6%
——6——