Vulnerabilities exploitable today
355,082in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,577
- High9,224
- Medium7,474
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-84218.8 HIG6.7%
——2Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php. An attacker who can cause an authenticated administrator to visit a crafted page, and who has placed or caused a package to be present under DIR_PACKAGES/<handle>/, can force the installation of that package without any CSRF protection. Package installation executes the package controller's install() method as the web server user, enabling remote code execution. In order to be vulnerable, the victim must be passing canInstallPackages. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks https://github.com/maru1009 for reporting.11dCVE-2024-36936—6.7%
——2——CVE-2026-1513—6.7%
——2——CVE-2025-63035—6.7%
——2——CVE-2026-543444.7 MED6.7%
——2ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open pull request with a deploy command to execute shell commands on the CI runner and exfiltrate deployment secrets. This issue is reported as fixed in version 3.20.180.25dCVE-2025-63052—6.7%
——2——CVE-2026-57660—6.7%
——2——CVE-2023-53746—6.7%
——2——CVE-2019-5246—6.7%
——2——CVE-2023-53754—6.7%
——2——CVE-2023-53761—6.7%
——2——CVE-2026-19957.8 HIG6.7%
——2In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the system. An attacker can overwrite or edit the files to specify a path to an arbitrary executable, which will then be executed by the id_service.exe process with SYSTEM privileges.13dCVE-2024-3100—6.7%
——2——CVE-2022-36349—6.7%
——2——CVE-2025-40313—6.7%
——2——CVE-2025-0760—6.7%
——2——CVE-2025-40314—6.7%
——2——CVE-2023-31021—6.7%
——2——CVE-2023-31023—6.7%
——2——CVE-2017-18062—6.7%
——2——CVE-2025-64729—6.7%
——2——CVE-2025-47701—6.7%
——2——CVE-2023-0200—6.7%
——2——CVE-2023-43064—6.7%
——2——CVE-2025-63055—6.7%
——2——CVE-2023-25520—6.7%
——2——CVE-2017-18061—6.7%
——2——CVE-2023-30648—6.7%
——2——CVE-2025-378907.8 HIG6.7%
——2In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
As described in Gerrard's report [1], we have a UAF case when an hfsc class
has a netem child qdisc. The crux of the issue is that hfsc is assuming
that checking for cl->qdisc->q.qlen == 0 guarantees that it hasn't inserted
the class in the vttree or eltree (which is not true for the netem
duplicate case).
This patch checks the n_active class variable to make sure that the code
won't insert the class in the vttree or eltree twice, catering for the
reentrant case.
[1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/5dCVE-2023-32120—6.7%
——2——CVE-2025-67537—6.7%
——2——CVE-2026-6520—6.7%
——2——CVE-2024-5661—6.7%
——2——CVE-2025-67542—6.7%
——2——CVE-2026-330745.3 MED6.7%
——2Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.10dCVE-2026-0231—6.7%
——2——CVE-2020-0306—6.7%
——2——CVE-2026-273015.5 MED6.7%
——2Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.10dCVE-2025-67553—6.7%
——2——CVE-2020-26270—6.7%
——2——