Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,534
- High10,642
- Medium6,742
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-26679—8.1%
——2——CVE-2025-2629—8.1%
——2——CVE-2026-504577.8 HIG8.1%
——2Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.17dCVE-2024-31154—8.1%
——2——CVE-2026-12450—8.1%
——2——CVE-2025-2630—8.1%
——2——CVE-2025-25334—8.1%
——2——CVE-2026-655177.1 HIG8.1%
——2Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.2dCVE-2025-12022—8.1%
——2——CVE-2026-503617.8 HIG8.1%
——2Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.17dCVE-2026-53536—8.1%
——2Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined with a missing null-check on the decoded fileId, this allowed any caller holding any valid Activepieces JWT (including a freshly created user's own access token) to receive a step-file belonging to another tenant. The file returned was whatever PostgreSQL happened to scan first for type = FLOW_STEP_FILE, varying over time as the database changed, so an authenticated user could obtain step-file attachments belonging to other tenants on the same instance; the attacker could not target a specific victim or file, and the access was read-only with no integrity or availability impact. This issue is fixed in version 0.83.0.22dCVE-2025-38324—8.1%
——2——CVE-2026-24433—8.1%
——2——CVE-2025-4294—8.1%
——2——CVE-2023-32555—8.1%
——2——CVE-2026-42180—8.1%
——2——CVE-2026-177285.4 MED8.1%
——2Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)9dCVE-2025-23179—8.1%
——2——CVE-2023-0221—8.1%
——2——CVE-2025-12751—8.1%
——2——CVE-2026-42341—8.1%
——2FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.32dCVE-2022-24120—8.1%
——2——CVE-2026-160275.4 MED8.1%
——2Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery.
This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.1dCVE-2025-62149—8.1%
——2——CVE-2024-37104—8.1%
——2——CVE-2022-25976—8.1%
——2——CVE-2026-34416.1 MED8.1%
——2A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.26dCVE-2024-37272—8.1%
——2——CVE-2023-35181—8.1%
——2——CVE-2023-54112—8.1%
——2——CVE-2025-68282—8.1%
——2——CVE-2025-30417—8.1%
——2——CVE-2025-68221—8.1%
——2——CVE-2025-64094—8.1%
——2——CVE-2024-4607—8.1%
——2——CVE-2025-68200—8.1%
——2——CVE-2025-62955—8.1%
——2——CVE-2025-13149—8.1%
——2——CVE-2024-37448—8.1%
——2——CVE-2024-37242—8.1%
——2——