Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,360
- High9,604
- Medium5,457
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-56356.3 MED15.7%
——5A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.36dCVE-2023-40202—15.7%
——5——CVE-2026-796616.5 MED15.7%
——5Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter of any echo (including private echoes) by supplying its UUID, which can be harvested from the public GET /api/echo/page feed. Repeated requests are accepted without deduplication, each triggering a database write and a four-key cache invalidation, allowing attackers to inflate popularity metrics and amplify load on the database and cache. Fixed in 4.7.3.2dCVE-2026-592756.6 MED15.7%
——5A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier17hCVE-2026-13229—15.7%
——5Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.20hCVE-2026-7672—15.7%
——5——CVE-2021-46996—15.7%
——5——CVE-2023-25463—15.7%
——5——CVE-2018-11876—15.7%
——5——CVE-2026-57196.3 MED15.7%
——5A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.36dCVE-2024-50446—15.7%
——5——CVE-2022-47609—15.7%
——5——CVE-2026-4485—15.7%
——5——CVE-2026-255674.3 MED15.7%
——5WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier.46dCVE-2026-504727.0 HIG15.7%
——5Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.13dCVE-2024-55592—15.7%
——5——CVE-2024-23928—15.7%
——5——CVE-2026-41522—15.7%
——5Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL endpoint at `/graphql` that does not enforce the same authorization checks as the REST API. Any authenticated user can abuse it in three ways: unauthorized IOC read across cases (IDOR), bulk IOC disclosure via `case.iocs`. The `case(caseId: …).iocs` resolver returns IOCs linked to an arbitrary case without verifying the caller has access to that case, and unauthorized case creation. All three are reachable by any authenticated user, regardless of role or case ACL. This is fixed in v2.4.28. The GraphQL blueprint, resolvers, and dependencies (`graphene`, `graphene-sqlalchemy`, `graphql-server[flask]`) were removed entirely, since the feature was not in use. As a workaround, block `/graphql` at the reverse proxy (recommended) or comment out the `graphql_blueprint` import and `register_blueprint` call in `source/app/views.py` and restart.38dCVE-2026-400487.8 HIG15.7%
——5The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cast to `java.security.KeyPair` is evaluated only after `readObject()` has already returned, so any `readObject()` side effects in the deserialized object run before the type check. An attacker who can write to the key directory used by a Camel application — for example through a path traversal into the directory, misconfigured filesystem permissions on the volume where keys are stored, a compromised key provisioning pipeline, or a symlink attack — can place a crafted serialized Java object that, when deserialized during normal key lifecycle operations, results in arbitrary code execution in the context of the application.
This issue affects Apache Camel: from 4.19.0 before 4.20.0, from 4.18.0 before 4.18.2.
Users are recommended to upgrade to version 4.20.0, which fixes the issue by replacing java.io.ObjectInputStream-based key and metadata storage with standard PKCS#8 (private key) / X.509 SubjectPublicKeyInfo (public key) Base64 JSON encoding. For users on the 4.18.x LTS releases stream, upgrade to 4.18.2.45dCVE-2026-73082—15.7%
——5Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host. This issue is fixed in version 0.82.0.18dCVE-2022-41987—15.7%
——5——CVE-2026-627237.0 HIG15.7%
——5Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.11dCVE-2020-37152—15.7%
——5——CVE-2022-491075.5 MED15.7%
——5In the Linux kernel, the following vulnerability has been resolved:
ceph: fix memory leak in ceph_readdir when note_last_dentry returns error
Reset the last_readdir at the same time, and add a comment explaining
why we don't free last_readdir when dir_emit returns false.16dCVE-2024-50502—15.7%
——5——CVE-2026-613667.0 HIG15.7%
——5Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.13dCVE-2024-47718—15.7%
——5——CVE-2026-619387.0 HIG15.7%
——5Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.12dCVE-2018-11874—15.7%
——5——CVE-2025-11333—15.7%
——5——CVE-2026-24590—15.7%
——5——CVE-2026-613467.0 HIG15.7%
——5Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.13dCVE-2026-53864—15.7%
——5——CVE-2026-12011—15.7%
——5——CVE-2024-7889—15.7%
——5——CVE-2026-56366.3 MED15.7%
——5A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.36dCVE-2024-56364—15.7%
——5——CVE-2025-2913—15.7%
——5——CVE-2026-55836.3 MED15.7%
——5A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.36dCVE-2026-790208.1 HIG15.7%
——5Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)15h