Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-791086.5 MED17.5%
——5UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)22hCVE-2025-55005—17.5%
——5——CVE-2015-4582—17.5%
——5——CVE-2025-64436—17.5%
——5——CVE-2021-1091—17.5%
——5——CVE-2024-7553—17.5%
——5——CVE-2025-24215—17.5%
——5——CVE-2026-43892—17.5%
——5——CVE-2026-554954.3 MED17.5%
——5Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.32dCVE-2024-6908—17.5%
——5——CVE-2025-32198—17.5%
——5——CVE-2026-49789.8 CRI17.5%
——5Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection.
This issue affects Traffic Analysis System: from 30 before 34.33dCVE-2026-582385.9 MED17.5%
——5SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.6dCVE-2026-0817—17.5%
——5——CVE-2020-36250—17.5%
——5——CVE-2022-48969—17.5%
——5——CVE-2024-553986.5 MED17.5%
——54C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.59dCVE-2022-44593—17.5%
——5——CVE-2024-12165—17.5%
——5——CVE-2025-68033—17.5%
——5——CVE-2024-3036—17.5%
——5——CVE-2017-1764—17.5%
——5——CVE-2023-35656—17.5%
——5——CVE-2026-26738—17.5%
——5——CVE-2024-8848—17.4%
——5——CVE-2025-13932—17.5%
——5——CVE-2024-44046—17.5%
——5——CVE-2026-481698.8 HIG17.5%
——5PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and delete resources in any workspace just by swapping UUIDs in their API requests. On top of that, every member management endpoint (add, update role, remove) only requires `min_role="member"`, which lets any workspace member promote themselves to owner and kick out the original owner. A low-privilege member of one workspace can steal data from every other workspace and take over any workspace they belong to. Both issues come from the same gap: the route layer pulls `workspace_id` from the URL and verifies membership, but the service layer ignores the workspace scope for resource lookups and ignores the caller's role level for member operations. The `require_workspace_member()` dependency does its job correctly. The problem is that the service layer doesn't use the information it provides. Version 0.1.4 of the PraisonAI Platform API patch the issue.22dCVE-2024-421047.8 HIG17.5%
——5In the Linux kernel, the following vulnerability has been resolved:
nilfs2: add missing check for inode numbers on directory entries
Syzbot reported that mounting and unmounting a specific pattern of
corrupted nilfs2 filesystem images causes a use-after-free of metadata
file inodes, which triggers a kernel bug in lru_add_fn().
As Jan Kara pointed out, this is because the link count of a metadata file
gets corrupted to 0, and nilfs_evict_inode(), which is called from iput(),
tries to delete that inode (ifile inode in this case).
The inconsistency occurs because directories containing the inode numbers
of these metadata files that should not be visible in the namespace are
read without checking.
Fix this issue by treating the inode numbers of these internal files as
errors in the sanity check helper when reading directory folios/pages.
Also thanks to Hillf Danton and Matthew Wilcox for their initial mm-layer
analysis.28dCVE-2021-2192—17.5%
——5——CVE-2025-674049.8 CRI17.5%
——5Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.33dCVE-2024-41938—17.5%
——5——CVE-2024-23347—17.5%
——5——CVE-2025-1230—17.5%
——5——CVE-2021-1092—17.5%
——5——CVE-2025-5282—17.5%
——5——CVE-2025-24593—17.5%
——5——CVE-2025-2667—17.5%
——5——CVE-2025-53840—17.5%
——5——CVE-2024-24819—17.5%
——5——