Vulnerabilities exploitable today
367,851in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,393
- High9,631
- Medium5,587
- Low548
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-42467—18.6%
——6——CVE-2025-29691—18.6%
——6——CVE-2025-54046—18.6%
——6——CVE-2026-56076.3 MED18.6%
——6A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument request.params.name/request.params.arguments leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.40dCVE-2025-53463—18.6%
——6——CVE-2024-6126—18.6%
——6——CVE-2026-35504—18.6%
——6——CVE-2025-6883—18.6%
——6——CVE-2026-21885—18.6%
——6——CVE-2024-45986—18.6%
——6——CVE-2025-62158—18.6%
——6——CVE-2026-44318—18.6%
——6——CVE-2021-35030—18.6%
——6——CVE-2025-66042—18.6%
——6——CVE-2021-37122—18.6%
——6——CVE-2025-2022—18.6%
——6——CVE-2024-51773—18.6%
——6——CVE-2024-46413—18.6%
——6——CVE-2025-66503—18.6%
——6——CVE-2025-12725—18.6%
——6——CVE-2025-57910—18.6%
——6——CVE-2025-59210—18.6%
——6——CVE-2025-62403—18.6%
——6——CVE-2026-42343—18.6%
——6FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service relies solely on an application-level soft limit (a 500ms polling interval) for memory management and lacks strict OS-level constraints such as cgroups or kernel-level namespaces. This architectural weakness allows attackers to easily bypass memory checks via time-window attacks, or exhaust the entire JavaScript worker pool via concurrent CPU-intensive requests, resulting in a complete Denial of Service (DoS) for legitimate users. At time of publication, there are no publicly available patches.39dCVE-2025-47873—18.6%
——6——CVE-2024-8012—18.6%
——6——CVE-2025-43505—18.6%
——6——CVE-2026-30833—18.6%
——6——CVE-2025-5494—18.6%
——6——CVE-2026-584325.9 MED18.6%
——6Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea7dCVE-2025-25585—18.6%
——6——CVE-2026-28254—18.6%
——6——CVE-2004-2657—18.6%
——6——CVE-2025-2021—18.6%
——6——CVE-2025-2015—18.6%
——6——CVE-2026-354017.5 HIG18.6%
——6Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.39dCVE-2025-58427—18.6%
——6——CVE-2024-27885—18.6%
——6——CVE-2026-29954—18.6%
——6——CVE-2025-14373—18.6%
——6——