Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-12929—17.2%
——5——CVE-2024-49682—17.2%
——5——CVE-2023-3488—17.2%
——5——CVE-2023-52380—17.2%
——5——CVE-2026-728577.7 HIG17.2%
——5Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend database credentials and service account keys.17dCVE-2026-656717.8 HIG17.2%
——5Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.15dCVE-2026-687586.5 MED17.2%
——5A low-privileged authenticated user may access restricted support information under specific conditions.3dCVE-2024-49959—17.2%
——5——CVE-2021-44900—17.2%
——5——CVE-2026-583847.3 HIG17.2%
——5A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.46dCVE-2026-657747.8 HIG17.2%
——5Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.14dCVE-2022-20362—17.2%
——5——CVE-2022-20283—17.2%
——5——CVE-2026-762257.7 HIG17.2%
——5ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and return sensitive data from restricted services.10dCVE-2026-6489—17.2%
——5——CVE-2022-48730—17.2%
——5——CVE-2024-53162—17.2%
——5——CVE-2020-1707—17.2%
——5——CVE-2009-2794—17.2%
——5——CVE-2024-55907—17.2%
——5——CVE-2026-32898—17.2%
——5——CVE-2024-44183—17.2%
——5——CVE-2026-48934—17.2%
——5——CVE-2026-4830—17.2%
——5——CVE-2026-448846.5 MED17.2%
——5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template file endpoint (GET /api/custom_templates/{id}/file) allows any authenticated user to read the file content of any custom template by enumerating sequential integer IDs, bypassing Resource Control access restrictions. Template files may contain environment-specific values such as connection strings, API tokens, or registry credentials that administrators would not expect standard users to read. This vulnerability is fixed in 2.33.8 and 2.39.1.41dCVE-2026-583807.3 HIG17.2%
——5A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.46dCVE-2026-656727.8 HIG17.2%
——5Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.17dCVE-2023-29745—17.2%
——5——CVE-2024-11261—17.2%
——5——CVE-2022-48186—17.2%
——5——CVE-2019-19346—17.2%
——5——CVE-2026-108908.8 HIG17.2%
——5Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)40dCVE-2025-14595—17.2%
——5——CVE-2021-1106—17.2%
——5——CVE-2025-22757—17.2%
——5——CVE-2021-40013—17.2%
——5——CVE-2026-45715—17.2%
——5——CVE-2022-3728—17.2%
——5——CVE-2021-47313—17.2%
——5——CVE-2024-43794—17.2%
——5——