Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,189
- Medium7,120
- Low649
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-67284—11.0%
——3Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users.3dCVE-2025-21477—11.0%
——3——CVE-2026-5750—11.0%
——3——CVE-2026-442136.5 MED11.0%
——3The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the INSTANA_ENDPOINT_PROXY environment variable. If a network attacker can Man-in-the-Middle (MitM) the proxy connection, all OpenTelemetry telemetry data and the Instana API key are exposed to the attacker. This vulnerability is fixed in 1.1.0.23dCVE-2026-32616—11.0%
——3——CVE-2025-59991—11.0%
——3——CVE-2026-396505.3 MED11.0%
——3Missing Authorization vulnerability in Unitech Web UnitechPay unitechpay-paiements-mobile-money allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnitechPay: from n/a through <= 1.0.2.21dCVE-2024-41684—11.0%
——3——CVE-2025-59996—11.0%
——3——CVE-2025-59984—11.0%
——3——CVE-2025-54511—11.0%
——3——CVE-2026-50282—11.0%
——3Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination. This issue has been resolved in versions 5.9.21 and 4.17.14.43dCVE-2025-59997—11.0%
——3——CVE-2020-36988—11.0%
——3——CVE-2023-44402—11.0%
——3——CVE-2026-12715—11.0%
——3Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.
This vulnerability was patched on 15 April 2026, and no customer action is needed.28dCVE-2021-47905—11.0%
——3——CVE-2024-42078—11.0%
——3——CVE-2022-44455—11.0%
——3——CVE-2025-40695—11.0%
——3——CVE-2024-49850—11.0%
——3——CVE-2024-47799—11.0%
——3——CVE-2025-60002—11.0%
——3——CVE-2026-426547.1 HIG11.0%
——3Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation.
This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.23dCVE-2021-347614.4 MED11.0%
——3A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.3dCVE-2026-42337—11.0%
——3MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL path without validating ownership, allowing attackers to perform operations under other applications’ policies. This vulnerability is fixed in 2.8.1.23dCVE-2026-387552.9 LOW11.0%
——3A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.26dCVE-2026-1842—11.0%
——3——CVE-2025-59995—11.0%
——3——CVE-2026-24441—11.0%
——3——CVE-2025-27073—11.0%
——3——CVE-2025-14767—11.0%
——3——CVE-2025-21452—11.0%
——3——CVE-2026-452708.7 HIG11.0%
——3CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including administrators. Because pages may be promoted to the site home page, the payload can be served at `/` and reach every visitor of the site. Version 0.31.9.0 patches the issue.24dCVE-2024-57956—11.0%
——3——CVE-2025-59993—11.0%
——3——CVE-2023-3078—11.0%
——3——CVE-2026-40866—11.0%
——3——CVE-2025-2299—11.0%
——3——CVE-2026-387522.9 LOW11.0%
——3A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.26d