Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,190
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-44976—7.6%
——2——CVE-2026-394015.4 MED7.6%
——2Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privilege user who can create and run events can modify any event property, including webhook URLs and notification emails. This vulnerability is fixed in 0.9.111.18dCVE-2025-32497—7.6%
——2——CVE-2025-12124—7.6%
——2——CVE-2026-6645—7.6%
——2——CVE-2025-32610—7.6%
——2——CVE-2025-12066—7.6%
——2——CVE-2023-30903—7.6%
——2——CVE-2025-30857—7.6%
——2——CVE-2016-4982—7.6%
——2——CVE-2025-32621—7.6%
——2——CVE-2024-41724—7.6%
——2——CVE-2024-21861—7.6%
——2——CVE-2025-5307—7.6%
——2——CVE-2025-66496—7.6%
——2——CVE-2018-11960—7.6%
——2——CVE-2022-48675—7.6%
——2——CVE-2025-39547—7.6%
——2——CVE-2025-39548—7.6%
——2——CVE-2021-47185—7.6%
——2——CVE-2025-66498—7.6%
——2——CVE-2025-32501—7.6%
——2——CVE-2025-32484—7.6%
——2——CVE-2026-7933—7.6%
——2——CVE-2025-30555—7.6%
——2——CVE-2025-32500—7.6%
——2——CVE-2026-40763—7.6%
——2——CVE-2026-1166—7.6%
——2——CVE-2022-48745—7.6%
——2——CVE-2025-32617—7.6%
——2——CVE-2025-68245—7.6%
——2——CVE-2026-28401—7.6%
——2——CVE-2025-66167—7.5%
——2——CVE-2026-445855.4 MED7.5%
——2Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request. An attacker could modify the service ID value in the client-side request and successfully create a ticket associated with another user's service.
The vulnerability requires authentication and does not provide direct access to service contents or customer data. However, referenced service information could become visible to support personnel handling the ticket. Successful exploitation could allow an authenticated user to: create support tickets referencing services belonging to other users, potentially cause support staff to interact with or review unrelated customer services. The vulnerability did not allow direct access to another user's service, modification of another user's service or retrieval of confidential service data through the vulnerable endpoint itself. This issue has been fixed in version 1.5.0.15dCVE-2026-472558.2 HIG7.5%
——2AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.15dCVE-2023-53792—7.5%
——2——CVE-2024-38830—7.5%
——2——CVE-2023-21286—7.5%
——2——CVE-2025-67561—7.5%
——2——CVE-2026-30287—7.5%
——2——