Vulnerabilities exploitable today
356,740in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,546
- High10,622
- Medium6,760
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-11252—8.6%
——3——CVE-2025-21542—8.6%
——3——CVE-2021-26382—8.6%
——3——CVE-2024-42178—8.6%
——3——CVE-2025-66258—8.6%
——3——CVE-2024-20812—8.6%
——3——CVE-2021-26254—8.6%
——3——CVE-2024-3467—8.6%
——3——CVE-2024-27080—8.6%
——3——CVE-2026-342286.5 MED8.6%
——3Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parameters. The server first downloads and executes the SQL file, then downloads the ZIP file and extracts it directly into the web root directory. This process does not validate a CSRF token. Therefore, an attacker only needs to trick an authenticated administrator into visiting a malicious link to achieve arbitrary SQL execution and arbitrary file write. This issue has been patched in version 2.6.8.16dCVE-2024-38658—8.6%
——3——CVE-2026-30139—8.6%
——3——CVE-2022-23403—8.6%
——3——CVE-2025-28876—8.6%
——3——CVE-2025-22018—8.6%
——3——CVE-2026-126065.3 MED8.6%
——3Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling. Grizzly 5.0.1 supports system properties that enable the behavior that fixes the vulnerability - set org.glassfish.grizzly.http.STRICT_HEADER_NAME_VALIDATION_RFC_9110 and org.glassfish.grizzly.http.STRICT_HEADER_VALUE_VALIDATION_RFC_9110 system properties to "true".13dCVE-2026-706017.5 HIG8.6%
——3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox, or with nodeIntegration enabled, this may escalate to Node.js access. Apps are affected if they expose Promise-returning functions via contextBridge, the standard pattern for wrapping ipcRenderer.invoke, in windows that load untrusted content. This issue is fixed in versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5.4dCVE-2025-22113—8.6%
——3——CVE-2022-34849—8.6%
——3——CVE-2024-38389—8.6%
——3——CVE-2026-0228—8.6%
——3——CVE-2026-22099—8.6%
——3The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.27dCVE-2025-231365.5 MED8.6%
——3In the Linux kernel, the following vulnerability has been resolved:
thermal: int340x: Add NULL check for adev
Not all devices have an ACPI companion fwnode, so adev might be NULL.
This is similar to the commit cd2fd6eab480
("platform/x86: int3472: Check for adev == NULL").
Add a check for adev not being set and return -ENODEV in that case to
avoid a possible NULL pointer deref in int3402_thermal_probe().
Note, under the same directory, int3400_thermal_probe() has such a
check.
[ rjw: Subject edit, added Fixes: ]26dCVE-2026-421723.1 LOW8.6%
——3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until manually revoked. This issue is fixed in version 4.0.0-beta.474.33dCVE-2025-63848—8.6%
——3——CVE-2012-3734—8.6%
——3——CVE-2025-10931—8.6%
——3——CVE-2025-11776—8.6%
——3——CVE-2026-54683.5 LOW8.6%
——3A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.16dCVE-2021-26257—8.6%
——3——CVE-2025-28866—8.6%
——3——CVE-2024-54226—8.6%
——3——CVE-2025-15043—8.6%
——3——CVE-2026-44520—8.6%
——3——CVE-2026-4067—8.6%
——3——CVE-2024-34806—8.6%
——3——CVE-2025-70302—8.6%
——3——CVE-2026-152564.8 MED8.6%
——3The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.2dCVE-2026-24449—8.6%
——3——CVE-2025-12766—8.6%
——3——