Vulnerabilities exploitable today
356,679in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,538
- High10,671
- Medium6,789
- Low678
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-01286.5 MED8.0%
——2In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.33dCVE-2026-43981—8.0%
——2——CVE-2026-354736.1 MED8.0%
——2WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IentradaControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.15dCVE-2024-38557—8.0%
——2——CVE-2026-562404.3 MED8.0%
——2Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion.26dCVE-2025-24516—8.0%
——2——CVE-2024-39283—8.0%
——2——CVE-2024-54550—8.0%
——2——CVE-2025-43262—8.0%
——2——CVE-2025-3082—8.0%
——2——CVE-2025-40773—8.0%
——2——CVE-2025-59824—8.0%
——2——CVE-2024-37941—8.0%
——2——CVE-2026-648234.7 MED8.0%
——2Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against an image-only allowlist. Attackers can cause the media player proxy endpoint to serve attacker-controlled bytes with Content-Type text/html in the Home Assistant web origin, enabling theft of session tokens from local storage and authenticated calls to sensitive service endpoints including lock, alarm, and cover controls.17dCVE-2026-156157.5 HIG8.0%
——2Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.12dCVE-2025-1939—8.0%
——2——CVE-2023-42830—8.0%
——2——CVE-2025-49333—8.0%
——2——CVE-2025-55713—8.0%
——2——CVE-2025-66498—8.0%
——2——CVE-2024-41885—8.0%
——2——CVE-2026-419896.7 MED8.0%
——2Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.25dCVE-2020-0399—8.0%
——2——CVE-2024-42231—8.0%
——2——CVE-2021-38121—8.0%
——2——CVE-2024-12484.8 MED8.0%
——2The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.
Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.30dCVE-2023-50821—8.0%
——2——CVE-2025-71326—8.0%
——2——CVE-2025-42936—8.0%
——2——CVE-2025-21973—8.0%
——2——CVE-2026-26291—8.0%
——2——CVE-2024-37938—8.0%
——2——CVE-2025-70297—8.0%
——2——CVE-2024-37939—8.0%
——2——CVE-2024-51679—8.0%
——2——CVE-2025-57890—8.0%
——2——CVE-2021-22458—8.0%
——2——CVE-2026-110346.1 MED8.0%
——2Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)17dCVE-2026-41479—8.0%
——2——CVE-2024-27363—8.0%
——2——