Vulnerabilities exploitable today
360,756in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,494
- High11,027
- Medium7,023
- Low632
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-52888—11.9%
——4——CVE-2024-37021—11.9%
——4——CVE-2026-20421—11.9%
——4——CVE-2026-598046.8 MED11.9%
——4Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-origin WebSocket connection to the local Socket.IO server, which performs no Origin header validation and requires no authentication token. Attackers can connect from any web page visited by the victim to seize the single-client slot, intercept and inject automation commands, exfiltrate command-payload data, or unconditionally terminate the server by supplying the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter.37dCVE-2026-349307.8 HIG11.9%
——4An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection mechanism.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.24dCVE-2023-40529—11.9%
——4——CVE-2024-21457—11.9%
——4——CVE-2025-23095—11.9%
——4——CVE-2025-60450—11.9%
——4——CVE-2025-63712—11.9%
——4——CVE-2025-62394—11.9%
——4——CVE-2026-452067.8 HIG11.9%
——4An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection communication mechanism.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.24dCVE-2026-278835.0 MED11.9%
——4Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any team, bypassing team-based authorization. The $teamId is extracted from the authentication token but never used to scope the database query. This vulnerability is fixed in 4.0.0-beta.464.46dCVE-2023-42563—11.9%
——4——CVE-2024-9649—11.9%
——4——CVE-2018-5552—11.9%
——4——CVE-2024-36589—11.9%
——4——CVE-2024-9352—11.9%
——4——CVE-2025-24135—11.9%
——4——CVE-2024-38285—11.9%
——4——CVE-2026-45085—11.9%
——4——CVE-2023-31189—11.9%
——4——CVE-2023-36658—11.9%
——4——CVE-2023-3433—11.9%
——4——CVE-2026-42559—11.9%
——4——CVE-2024-39364—11.9%
——4——CVE-2026-44087—11.9%
——4——CVE-2025-3768—11.9%
——4——CVE-2021-429237.3 HIG11.9%
——4ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user privileges unless the user specifically runs ShowMyPC as administrator.39dCVE-2026-92464.3 MED11.9%
——4Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier24dCVE-2023-43572—11.9%
——4——CVE-2020-0444—11.9%
——4——CVE-2021-47389—11.9%
——4——CVE-2025-43260—11.9%
——4——CVE-2026-27444—11.9%
——4——CVE-2023-53808—11.9%
——4——CVE-2023-28202—11.9%
——4——CVE-2026-2201—11.9%
——4——CVE-2022-32896—11.9%
——4——CVE-2025-69351—11.9%
——4——