Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-6475—17.5%
——5——CVE-2026-759205.3 MED17.5%
——5phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.18hCVE-2025-32198—17.5%
——5——CVE-2026-49789.8 CRI17.5%
——5Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection.
This issue affects Traffic Analysis System: from 30 before 34.33dCVE-2026-0817—17.5%
——5——CVE-2025-24202—17.5%
——5——CVE-2026-554954.3 MED17.5%
——5Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.32dCVE-2026-582385.9 MED17.5%
——5SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.6dCVE-2024-6908—17.5%
——5——CVE-2025-56075—17.5%
——5——CVE-2025-10579—17.5%
——5——CVE-2021-47553—17.5%
——5——CVE-2024-41941—17.5%
——5——CVE-2024-25050—17.5%
——5——CVE-2023-53154—17.5%
——5——CVE-2026-33069—17.5%
——5——CVE-2025-13174—17.5%
——5——CVE-2025-61879—17.5%
——5——CVE-2026-1284—17.5%
——5——CVE-2026-56227—17.5%
——5——CVE-2025-67931—17.5%
——5——CVE-2026-27428—17.5%
——5——CVE-2025-13181—17.5%
——5——CVE-2024-8829—17.5%
——5——CVE-2024-36437—17.5%
——5——CVE-2024-13422—17.5%
——5——CVE-2026-4544—17.5%
——5——CVE-2025-13182—17.5%
——5——CVE-2023-38496—17.5%
——5——CVE-2026-48917—17.5%
——5——CVE-2026-37340—17.5%
——5——CVE-2026-3347—17.5%
——5——CVE-2026-40161—17.5%
——5——CVE-2025-68141—17.5%
——5——CVE-2025-68116—17.5%
——5——CVE-2024-35633—17.5%
——5——CVE-2021-4438—17.5%
——5——CVE-2026-654846.3 MED17.5%
——5Contributor Broken Access Control in Style Kits <= 2.6.5 versions.40dCVE-2026-346726.2 MED17.5%
——5CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.5dCVE-2026-791086.5 MED17.5%
——5UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)22h