Vulnerabilities exploitable today
364,238in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,592
- High10,528
- Medium5,768
- Low534
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-353966.1 MED13.3%
——4WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IsaidaControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.30dCVE-2025-31899—13.3%
——4——CVE-2025-2111—13.3%
——4——CVE-2025-23981—13.3%
——4——CVE-2024-46085—13.3%
——4——CVE-2025-39393—13.3%
——4——CVE-2025-145767.8 HIG13.3%
——4Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.25dCVE-2021-22743—13.3%
——4——CVE-2025-24566—13.3%
——4——CVE-2026-566708.2 HIG13.3%
——4ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content-type handling, allowing stored cross-site scripting in the ComfyUI origin. This issue is fixed in version 0.28.0.23dCVE-2025-26743—13.3%
——4——CVE-2025-23788—13.3%
——4——CVE-2025-26992—13.3%
——4——CVE-2026-97546.5 MED13.3%
——4An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command31dCVE-2025-39365—13.3%
——4——CVE-2022-42838—13.3%
——4——CVE-2025-57935—13.3%
——4——CVE-2026-277858.8 HIG13.3%
——4Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.29dCVE-2024-6677—13.3%
——4——CVE-2025-23988—13.3%
——4——CVE-2025-15154—13.3%
——4——CVE-2024-501597.0 HIG13.3%
——4In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup()
Clang static checker(scan-build) throws below warning:
| drivers/firmware/arm_scmi/driver.c:line 2915, column 2
| Attempt to free released memory.
When devm_add_action_or_reset() fails, scmi_debugfs_common_cleanup()
will run twice which causes double free of 'dbg->name'.
Remove the redundant scmi_debugfs_common_cleanup() to fix this problem.19dCVE-2026-148205.3 MED13.3%
——4The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to brute-force passwords while bypassing brute-force protection Quiz and Survey Master (QSM) WordPress plugin before 11.1.3.27dCVE-2026-470322.6 LOW13.3%
——4Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).18dCVE-2026-6312—13.3%
——4——CVE-2025-31907—13.3%
——4——CVE-2024-27440—13.3%
——4——CVE-2025-8608—13.3%
——4——CVE-2025-23983—13.3%
——4——CVE-2025-7979—13.3%
——4——CVE-2023-52566—13.3%
——4——CVE-2025-70368—13.3%
——4——CVE-2024-38739—13.3%
——4——CVE-2025-24615—13.3%
——4——CVE-2024-8489—13.3%
——4——CVE-2026-179879.6 CRI13.3%
——4Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)20dCVE-2026-554335.4 MED13.3%
——4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild. Exploitation requires an existing low-privilege role with access to the target workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an explicit `ActionUpdate` authorization check before the agent is dialed like the delete endpoint. No known workarounds are available.46dCVE-2025-23792—13.3%
——4——CVE-2024-27847—13.3%
——4——CVE-2020-359905.5 MED13.3%
——4Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.45d