Vulnerabilities exploitable today
355,213in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,523
- High9,111
- Medium7,331
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-7996—6.9%
——2——CVE-2022-34421—6.9%
——2——CVE-2022-34422—6.9%
——2——CVE-2023-24589—6.9%
——2——CVE-2022-34420—6.9%
——2——CVE-2025-23698—6.9%
——2——CVE-2024-26719—6.9%
——2——CVE-2026-32351—6.9%
——2——CVE-2025-1680—6.9%
——2——CVE-2026-78876.4 MED6.9%
——2For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and receive valid API tokens. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N. Thanks 0x4c616e for reporting.12dCVE-2026-29051—6.9%
——2——CVE-2026-22804—6.9%
——2——CVE-2025-23677—6.9%
——2——CVE-2026-338016.5 MED6.9%
——2An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).
Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.
This issue affects:
* Junos OS versions 25.2 before 25.2R2;
* Junos OS Evolved versions 25.2 before 25.2R2-EVO.
This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.21dCVE-2024-43947—6.9%
——2——CVE-2026-399226.3 MED6.9%
——2GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.20dCVE-2024-57886—6.9%
——2——CVE-2026-22695—6.9%
——2——CVE-2026-396385.9 MED6.9%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.14.10dCVE-2024-57881—6.9%
——2——CVE-2026-0999—6.9%
——2——CVE-2025-23702—6.9%
——2——CVE-2026-565843.7 LOW6.9%
——2HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.5dCVE-2025-68978—6.9%
——2——CVE-2022-50933—6.9%
——2——CVE-2026-396675.9 MED6.9%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through <= 1.7.0.10dCVE-2025-23692—6.9%
——2——CVE-2026-31554—6.9%
——2——CVE-2021-33003—6.9%
——2——CVE-2025-68931—6.9%
——2——CVE-2026-21055—6.9%
——2Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.24dCVE-2025-59110—6.9%
——2——CVE-2022-46824—6.9%
——2——CVE-2026-46356.5 MED6.9%
——2Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel.. Mattermost Advisory ID: MMSA-2026-0063712dCVE-2026-0930—6.9%
——2——CVE-2023-54288—6.9%
——2——CVE-2022-34406—6.9%
——2——CVE-2025-13127—6.9%
——2——CVE-2026-396045.9 MED6.9%
——2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.10dCVE-2025-41432—6.9%
——2——