Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,273
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-0121—17.2%
——5——CVE-2024-53060—17.2%
——5——CVE-2025-37877—17.2%
——5——CVE-2023-54333—17.2%
——5——CVE-2025-21075—17.2%
——5——CVE-2025-43024—17.2%
——5——CVE-2024-40239—17.2%
——5——CVE-2024-56427—17.2%
——5——CVE-2025-21604—17.2%
——5——CVE-2016-2867—17.2%
——5——CVE-2025-46461—17.2%
——5——CVE-2026-2040—17.2%
——5——CVE-2024-46821—17.2%
——5——CVE-2025-49037—17.2%
——5——CVE-2026-425568.9 HIG17.2%
——5Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7.38dCVE-2025-10575—17.2%
——5——CVE-2025-52545—17.2%
——5——CVE-2024-58055—17.2%
——5——CVE-2025-15258—17.2%
——5——CVE-2025-58477—17.2%
——5——CVE-2025-29427—17.2%
——5——CVE-2024-56536—17.2%
——5——CVE-2025-24550—17.2%
——5——CVE-2023-29069—17.2%
——5——CVE-2025-13750—17.2%
——5——CVE-2025-26950—17.2%
——5——CVE-2025-47780—17.2%
——5——CVE-2024-35410—17.2%
——5——CVE-2024-41265—17.2%
——5——CVE-2025-46260—17.2%
——5——CVE-2026-44749—17.2%
——5——CVE-2025-46471—17.2%
——5——CVE-2024-35288—17.2%
——5——CVE-2025-8589—17.2%
——5——CVE-2025-7803—17.2%
——5——CVE-2026-48820—17.2%
——5——CVE-2025-11740—17.2%
——5——CVE-2026-450699.1 CRI17.2%
——5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.47dCVE-2026-554367.4 HIG17.2%
——5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure transport when an upstream proxy was configured. In the default configuration (no upstream proxy), outbound HTTPS to the Coder access URL accepted any TLS certificate. Practical exploitation requires an on-path (man-in-the-middle) position between the AI Bridge Proxy and the Coder server. Deployments where they are co-located over loopback are effectively unaffected. The fix in versions 2.32.7, 2.33.8, and 2.34.2 applies the secure transport (TLS 1.2 or higher using system root CAs) unconditionally. As a workaround, ensure the Coder access URL uses a trusted certificate and secure the network path between the AI Bridge Proxy and the Coder server (for example, loopback or mTLS).54dCVE-2026-50190—17.2%
——5Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into the `pagetitle` template variable and the RainTPL template emits it into the document `<title>` element without HTML escaping. A bookmark title containing `</title><script>...</script>` closes the document title early and the injected script executes in the Shaarli origin for any visitor of `/shaare/{hash}`. Shaarli's metadata fetcher copies a remote page's `<title>` text verbatim into the local bookmark title, so an attacker who hosts an attacker-controlled URL and convinces an administrator to bookmark it plants the payload with no further interaction — and the resulting permalink fires for every visitor including the administrator on first save, providing a one-shot administrator account takeover. Version 0.16.3 fixes the issue.11d