Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,714
- High11,674
- Medium7,458
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-24535—10.3%
——3——CVE-2024-53236—10.3%
——3——CVE-2018-11886—10.3%
——3——CVE-2026-600626.4 MED10.3%
——3The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary.
Impact:
A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Agent configuration.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.7dCVE-2026-98087.1 HIG10.3%
——3An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users.23dCVE-2021-0605—10.3%
——3——CVE-2023-22293—10.3%
——3——CVE-2019-10569—10.3%
——3——CVE-2026-42202—10.3%
——3——CVE-2026-52858—10.3%
——3——CVE-2021-41223—10.3%
——3——CVE-2026-154736.3 MED10.3%
——3A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.30dCVE-2026-7092—10.3%
——3——CVE-2026-7044—10.3%
——3——CVE-2026-393604.3 MED10.3%
——3RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket can still exfiltrate victim objects by copying them into an attacker-controlled multipart upload and completing the upload. This breaks tenant isolation in multi-user / multi-tenant deployments. This vulnerability is fixed in alpha.90.20dCVE-2026-4505—10.3%
——3——CVE-2025-0035—10.3%
——3——CVE-2026-102056.3 MED10.3%
——3A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.22dCVE-2024-56613—10.3%
——3——CVE-2023-30644—10.3%
——3——CVE-2026-7091—10.3%
——3——CVE-2023-30649—10.3%
——3——CVE-2021-41226—10.3%
——3——CVE-2026-6744—10.3%
——3——CVE-2022-33912—10.3%
——3——CVE-2023-53091—10.3%
——3——CVE-2026-7150—10.3%
——3——CVE-2016-3677—10.3%
——3——CVE-2026-6617—10.3%
——3——CVE-2023-39431—10.3%
——3——CVE-2026-94126.3 MED10.3%
——3A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Multiple endpoints are affected.21dCVE-2022-22326—10.3%
——3——CVE-2026-178024.3 MED10.3%
——3Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)9dCVE-2026-6297—10.3%
——3——CVE-2024-46681—10.3%
——3——CVE-2026-30954—10.3%
——3——CVE-2025-50361—10.3%
——3——CVE-2023-5059—10.3%
——3——CVE-2024-42218—10.3%
——3——CVE-2023-20121—10.3%
——3——