Vulnerabilities exploitable today
364,333in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,320
- High9,833
- Medium4,881
- Low459
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-8173—15.8%
——4——CVE-2026-41183—13.4%
——4——CVE-2025-30279—13.4%
——4——CVE-2024-42159—13.4%
——4——CVE-2022-37459—13.4%
——4——CVE-2025-64753—13.4%
——4——CVE-2026-39963—13.4%
——4——CVE-2022-50836—13.4%
——4——CVE-2021-47465—13.4%
——4——CVE-2025-13898—13.4%
——4——CVE-2025-21711—13.4%
——4——CVE-2024-56748—13.4%
——4——CVE-2025-24355—13.4%
——4——CVE-2022-3110—13.4%
——4——CVE-2026-769935.0 MED13.4%
——4A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The reported GitHub issue was closed with the label "not planned".4dCVE-2026-708533.3 LOW13.4%
——4Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L).3dCVE-2023-53856—13.4%
——4——CVE-2022-22465—13.4%
——4——CVE-2026-78795.3 MED13.4%
——4In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading
permission-restricted files bypasses the view_file permission check. Files without passwords can be downloaded and any user who knows a file's password can download a password protected file regardless of whether they have permission to access the file. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Youssef Eid for reporting32dCVE-2025-13448—13.4%
——4——CVE-2024-34545—13.4%
——4——CVE-2022-27677—13.4%
——4——CVE-2021-25117—13.4%
——4——CVE-2025-36062—13.4%
——4——CVE-2026-56663—13.4%
——4——CVE-2026-337096.1 MED13.4%
——4JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4.31dCVE-2025-23244—13.4%
——4——CVE-2025-29885—13.4%
——4——CVE-2024-38791—13.4%
——4——CVE-2023-53865—13.4%
——4——CVE-2024-36023—13.4%
——4——CVE-2025-7889—13.4%
——4——CVE-2026-58178.2 HIG13.4%
——4The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI registry, resulting in arbitrary code execution on the Docker host as the Docker Desktop user when inference is triggered.
Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model and request inference.32dCVE-2026-25051—13.4%
——4——CVE-2025-67474—13.4%
——4——CVE-2026-146256.3 MED13.4%
——4A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.49dCVE-2026-526066.1 MED13.4%
——4A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php.6dCVE-2025-11210—13.4%
——4——CVE-2026-526096.1 MED13.4%
——4A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php.6dCVE-2025-36537.3 HIG13.4%
——4Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership verification. Attackers can control any device by sending serial numbers to device control APIs to change feeding schedules, trigger manual feeds, access camera feeds, and modify device settings without authorization checks.35d