Vulnerabilities exploitable today
356,768in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,533
- High10,540
- Medium6,708
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32397—8.9%
——3——CVE-2025-39409—8.9%
——3——CVE-2026-396575.3 MED8.9%
——3Missing Authorization vulnerability in leadlovers leadlovers forms leadlovers-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects leadlovers forms: from n/a through <= 1.0.2.16dCVE-2024-1747—8.9%
——3——CVE-2022-4574—8.9%
——3——CVE-2021-320869.8 CRI8.9%
——3An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.6dCVE-2022-48308—8.9%
——3——CVE-2026-57340—8.9%
——3——CVE-2024-41902—8.9%
——3——CVE-2026-5106—8.9%
——3——CVE-2026-99966.5 MED8.9%
——3Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)20dCVE-2026-4255—8.9%
——3——CVE-2026-544705.3 MED8.9%
——3Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.24dCVE-2026-26027—8.9%
——3——CVE-2025-0217—8.9%
——3——CVE-2025-47680—8.9%
——3——CVE-2026-396765.3 MED8.9%
——3Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.20dCVE-2022-50547—8.9%
——3——CVE-2023-2961—8.9%
——3——CVE-2026-32409—8.9%
——3——CVE-2024-54014—8.9%
——3——CVE-2020-3610—8.9%
——3——CVE-2026-396525.3 MED8.9%
——3Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: from n/a through <= 1.3.16dCVE-2025-23981—8.9%
——3——CVE-2026-396245.3 MED8.9%
——3Missing Authorization vulnerability in kutethemes Biolife biolife allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Biolife: from n/a through <= 3.2.3.16dCVE-2025-39365—8.9%
——3——CVE-2024-12740—8.9%
——3——CVE-2026-38528—8.9%
——3——CVE-2025-0836—8.9%
——3——CVE-2022-30747—8.9%
——3——CVE-2026-57334—8.9%
——3——CVE-2026-0588—8.9%
——3——CVE-2026-100186.5 MED8.9%
——3Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)20dCVE-2025-21815—8.9%
——3——CVE-2026-712767.1 HIG8.9%
——3Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf() in both the PostgreSQL reader (readers/postgres/messages.go: `fmt.Sprintf("SELECT * FROM %s WHERE %s ...", format, cond)`) and the TimescaleDB reader (readers/timescale/messages.go, same pattern), enabling SQL injection by any authenticated user able to query channel messages.4dCVE-2025-39407—8.9%
——3——CVE-2026-58804.3 MED8.9%
——3Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)17dCVE-2026-395615.3 MED8.9%
——3Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.7.16dCVE-2024-50011—8.9%
——3——CVE-2021-27784—8.9%
——3——