Vulnerabilities exploitable today
355,017in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,558
- High9,191
- Medium7,449
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-562525.4 MED6.6%
——2Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their declared app boundary, bypassing the limited_to_apps authorization check.21dCVE-2025-6689—6.6%
——2——CVE-2021-4142—6.6%
——2——CVE-2025-4701—6.6%
——2——CVE-2023-38022—6.6%
——2——CVE-2022-24410—6.6%
——2——CVE-2022-41628—6.6%
——2——CVE-2026-22183—6.6%
——2——CVE-2024-51481—6.6%
——2——CVE-2024-6405—6.6%
——2——CVE-2022-43474—6.6%
——2——CVE-2025-21084—6.6%
——2——CVE-2025-712348.8 HIG6.6%
——2In the Linux kernel, the following vulnerability has been resolved:
wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add
The driver does not set hw->sta_data_size, which causes mac80211 to
allocate insufficient space for driver private station data in
__sta_info_alloc(). When rtl8xxxu_sta_add() accesses members of
struct rtl8xxxu_sta_info through sta->drv_priv, this results in a
slab-out-of-bounds write.
KASAN report on RISC-V (VisionFive 2) with RTL8192EU adapter:
BUG: KASAN: slab-out-of-bounds in rtl8xxxu_sta_add+0x31c/0x346
Write of size 8 at addr ffffffd6d3e9ae88 by task kworker/u16:0/12
Set hw->sta_data_size to sizeof(struct rtl8xxxu_sta_info) during
probe, similar to how hw->vif_data_size is configured. This ensures
mac80211 allocates sufficient space for the driver's per-station
private data.
Tested on StarFive VisionFive 2 v1.2A board.4dCVE-2025-43294—6.6%
——2——CVE-2025-4742—6.6%
——2——CVE-2022-34157—6.6%
——2——CVE-2022-32576—6.6%
——2——CVE-2026-37337—6.6%
——2——CVE-2025-47661—6.6%
——2——CVE-2024-52870—6.6%
——2——CVE-2026-37336—6.6%
——2——CVE-2023-20582—6.6%
——2——CVE-2026-482295.4 MED6.6%
——2Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into HTML form hidden input value attributes. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.11dCVE-2025-23414—6.6%
——2——CVE-2024-40035—6.6%
——2——CVE-2022-41693—6.6%
——2——CVE-2025-5585—6.6%
——2——CVE-2025-4965—6.6%
——2——CVE-2023-6363—6.6%
——2——CVE-2022-20073—6.6%
——2——CVE-2023-30760—6.6%
——2——CVE-2026-398757.8 HIG6.6%
——2A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.5dCVE-2026-31350—6.6%
——2——CVE-2024-13943—6.6%
——2——CVE-2026-482465.9 MED6.6%
——2Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys or session-bearing data in transit.11dCVE-2026-673076.3 MED6.6%
——2Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vulnerability documents by forging wazuh.cluster.name values and influencing the document _id prefix, potentially tampering with inventory records or, in shared-indexer multi-cluster deployments, poisoning another cluster's records when numeric agent IDs collide.2dCVE-2025-674077.3 HIG6.6%
——2Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.4dCVE-2026-343844.5 MED6.6%
——2Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in the same file (which correctly validates the token), these three approval actions read their parameters from $_GET and perform irreversible state changes without any protection. An attacker who has submitted a pending registration can extract their own user UUID from the registration confirmation email URL, then trick any user with the rol_approve_users right into visiting a crafted URL that automatically approves the registration. This bypasses the manual registration approval workflow entirely. This issue has been patched in version 5.0.8.10dCVE-2025-4740—6.6%
——2——CVE-2026-26204—6.6%
——2——