Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,131
- Low649
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-491446.5 MED11.1%
——3BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.24dCVE-2026-177896.5 MED11.1%
——3Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)11dCVE-2026-54345.9 MED11.1%
——3Honeywell Control
Network Module (CNM) contains
insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing
system files, potentially resulting in unintended
access to protected data.
Honeywell
recommends updating to the most recent version of this product, service or
offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].16dCVE-2025-33118—11.1%
——3——CVE-2026-577795.3 MED11.1%
——3Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.33dCVE-2023-52779—11.1%
——3——CVE-2026-465187.7 HIG11.1%
——3OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/HTML multi-print feature allows a patient portal user to execute arbitrary JavaScript in a clinician's browser session. Patient demographic fields (name, address) are rendered without output encoding in multiprintcss_header(), and portal patients can write attacker-controlled HTML directly into patient_data by calling the PUT api/patient/:num endpoint, which bypasses the intended audit review workflow. Because the XSS fires in the clinician's authenticated session on the main OpenEMR interface, the attacker can access CSRF tokens, session data, and perform actions as the clinician — crossing the patient-to-clinician trust boundary. This issue has been patched in version 8.0.0.1.23dCVE-2022-49980—11.1%
——3——CVE-2024-8597—11.1%
——3——CVE-2020-4008—11.1%
——3——CVE-2024-8594—11.1%
——3——CVE-2026-24547—11.1%
——3——CVE-2026-28558—11.1%
——3——CVE-2024-8598—11.1%
——3——CVE-2025-219067.6 HIG11.1%
——3In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: clean up ROC on failure
If the firmware fails to start the session protection, then we
do call iwl_mvm_roc_finished() here, but that won't do anything
at all because IWL_MVM_STATUS_ROC_P2P_RUNNING was never set.
Set IWL_MVM_STATUS_ROC_P2P_RUNNING in the failure/stop path.
If it started successfully before, it's already set, so that
doesn't matter, and if it didn't start it needs to be set to
clean up.
Not doing so will lead to a WARN_ON() later on a fresh remain-
on-channel, since the link is already active when activated as
it was never deactivated.16dCVE-2026-23974—11.1%
——3——CVE-2023-1195—11.1%
——3——CVE-2026-33583—11.1%
——3——CVE-2022-50837—11.1%
——3——CVE-2024-34674—11.1%
——3——CVE-2024-8589—11.1%
——3——CVE-2026-1008—11.1%
——3——CVE-2025-48334—11.1%
——3——CVE-2025-4763—11.1%
——3——CVE-2022-50817—11.1%
——3——CVE-2020-9087—11.1%
——3——CVE-2025-53668—11.1%
——3——CVE-2026-393746.5 MED11.1%
——3Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches issues by ID without filtering by workspace or project, enabling cross-boundary data modification. This vulnerability is fixed in 1.3.0.21dCVE-2022-50820—11.1%
——3——CVE-2026-15183—11.1%
——3Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. An attacker could exploit these vulnerabilities by supplying a crafted OAuth token request URL, placing malicious files in an ingestion pipeline, injecting SQL via staging options in a shared Spark environment , or issuing runtime SET commands in a shared Spark-SQL session to inject arbitrary SQL into the SnowflakeFallbackCatalog's option map, which executes under the cluster admin's JDBC credentials. Successful exploitation may result in credential theft, unauthorized access to Snowflake account data, or privilege escalation within connected infrastructure.30dCVE-2022-48481—11.1%
——3——CVE-2024-40950—11.1%
——3——CVE-2024-7670—11.1%
——3——CVE-2024-8592—11.1%
——3——CVE-2025-30329—11.1%
——3——CVE-2024-9997—11.1%
——3——CVE-2025-9817—11.1%
——3——CVE-2024-27839—11.1%
——3——CVE-2026-6835—11.1%
——3——CVE-2024-47752—11.1%
——3——