Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,301
- High9,893
- Medium4,852
- Low455
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53024—14.7%
——4——CVE-2023-25514—14.7%
——4——CVE-2022-23157—14.7%
——4——CVE-2025-37927—14.7%
——4——CVE-2026-729218.1 HIG14.7%
——4SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.14dCVE-2025-51540—14.7%
——4——CVE-2025-54739—14.7%
——4——CVE-2024-359637.1 HIG14.6%
——4In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sock: Fix not validating setsockopt user input
Check user input length before copying data.23dCVE-2025-53030—14.7%
——4——CVE-2026-563544.1 MED14.7%
——4n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions can inject malicious scripts or redirect parameters to perform stored XSS attacks or phishing redirects against end users.45dCVE-2025-66864—14.7%
——4——CVE-2024-40805—14.7%
——4——CVE-2024-47126—14.7%
——4——CVE-2025-52559—14.7%
——4——CVE-2024-6150—14.7%
——4——CVE-2021-0390—14.7%
——4——CVE-2021-47958—14.7%
——4——CVE-2026-715116.5 MED14.7%
——4Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list endpoints to obtain crypted password verifier fields that are not filtered by the base API serializer or the Members API class, potentially enabling offline password cracking attacks.3dCVE-2023-48426—14.7%
——4——CVE-2021-47146—14.7%
——4——CVE-2024-9778—14.7%
——4——CVE-2026-47349—14.6%
——4Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.35dCVE-2025-446497.5 HIG14.6%
——4In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.54dCVE-2021-47618—14.6%
——4——CVE-2024-369738.4 HIG14.6%
——4In the Linux kernel, the following vulnerability has been resolved:
misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe()
When auxiliary_device_add() returns error and then calls
auxiliary_device_uninit(), callback function
gp_auxiliary_device_release() calls ida_free() and
kfree(aux_device_wrapper) to free memory. We should't
call them again in the error handling path.
Fix this by skipping the redundant cleanup functions.23dCVE-2024-34572—14.6%
——4——CVE-2025-23354—14.6%
——4——CVE-2026-47351—14.6%
——4Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2.35dCVE-2006-2930—14.6%
——4——CVE-2025-0747—14.6%
——4——CVE-2025-11240—14.6%
——4——CVE-2023-52498—14.6%
——4——CVE-2021-0151—14.6%
——4——CVE-2024-0430—14.6%
——4——CVE-2020-12900—14.6%
——4——CVE-2025-8567—14.6%
——4——CVE-2026-42745—14.6%
——4——CVE-2025-46809—14.6%
——4——CVE-2025-22632—14.6%
——4——CVE-2020-12902—14.6%
——4——