Vulnerabilities exploitable today
355,177in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,606
- High9,258
- Medium7,548
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-62258—6.8%
——2——CVE-2026-446136.1 MED6.8%
——2Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.3dCVE-2026-341704.3 MED6.8%
——2Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base URL for server-side HTTP requests without allowlisting or private IP blocking, allowing an authenticated user to configure a GitHub App source that causes Coolify to request internal services or cloud metadata endpoints. This issue is reported as fixed in version 4.0.0-beta.471.27dCVE-2026-485595.4 MED6.8%
——2Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.13dCVE-2025-23338—6.8%
——2——CVE-2022-50224—6.8%
——2——CVE-2023-52516—6.8%
——2——CVE-2026-3938—6.8%
——2——CVE-2023-45165—6.8%
——2——CVE-2025-55059—6.8%
——2——CVE-2021-25407—6.8%
——2——CVE-2023-21511—6.8%
——2——CVE-2025-0467—6.8%
——2——CVE-2025-6504—6.8%
——2——CVE-2025-63032—6.8%
——2——CVE-2024-49304—6.8%
——2——CVE-2025-39686—6.8%
——2——CVE-2021-47911—6.8%
——2——CVE-2025-3630—6.8%
——2——CVE-2022-38099—6.8%
——2——CVE-2022-35257—6.8%
——2——CVE-2022-20499—6.8%
——2——CVE-2024-20841—6.8%
——2——CVE-2024-53085—6.8%
——2——CVE-2026-387657.8 HIG6.8%
——2An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys10dCVE-2026-57664—6.8%
——2——CVE-2025-36754—6.8%
——2——CVE-2024-41629—6.8%
——2——CVE-2023-42579—6.8%
——2——CVE-2024-53079—6.8%
——2——CVE-2021-36277—6.8%
——2——CVE-2024-2502—6.8%
——2——CVE-2023-38299—6.8%
——2——CVE-2025-2793—6.8%
——2——CVE-2023-21510—6.8%
——2——CVE-2025-67858—6.8%
——2——CVE-2019-25588—6.8%
——2——CVE-2022-25905—6.8%
——2——CVE-2026-42541—6.8%
——2——CVE-2024-54455—6.8%
——2——