Vulnerabilities exploitable today
354,470in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,643
- High9,463
- Medium7,694
- Low694
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-554385.8 MED4.6%
——1Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL's username matched the real owner, while the CORS middleware trusted the unverified username in the hostname. Practical exploitation requires subdomain app routing (wildcard hostname) enabled and a victim who visits the attacker's crafted app URL while authenticated. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 validates the subdomain username against the resolved workspace's actual owner and bases the same-owner CORS decision on the authoritative owner identity. No known workarounds are available.23dCVE-2025-38081—4.6%
——1——CVE-2026-648214.3 MED4.6%
——1djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by exploiting order-cancellation logic implemented inside HTTP GET method handlers in CancelarOrcamentoVendaView, CancelarPedidoVendaView, CancelarOrcamentoCompraView, and CancelarPedidoCompraView. Attackers can lure an authenticated victim with change_orcamentovenda or equivalent permissions to a page containing a cross-origin reference such as an img tag pointing to the cancellation endpoint, bypassing CSRF token validation entirely since Django's CsrfViewMiddleware only enforces CSRF checks on unsafe HTTP methods.8dCVE-2024-33848—4.6%
——1——CVE-2023-31366—4.6%
——1——CVE-2021-35098—4.6%
——1——CVE-2016-20031—4.6%
——1——CVE-2021-47823—4.6%
——1——CVE-2025-38487—4.6%
——1——CVE-2026-40319—4.6%
——1——CVE-2022-41594—4.6%
——1——CVE-2024-25078—4.6%
——1——CVE-2025-57781—4.6%
——1——CVE-2024-25079—4.6%
——1——CVE-2025-64187—4.6%
——1——CVE-2019-25306—4.6%
——1——CVE-2024-42425—4.6%
——1——CVE-2025-23376—4.6%
——1——CVE-2025-38606—4.6%
——1——CVE-2025-61993.3 LOW4.6%
——1A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.31dCVE-2019-25275—4.6%
——1——CVE-2026-21437—4.6%
——1——CVE-2020-36652—4.6%
——1——CVE-2025-39847—4.6%
——1——CVE-2023-28074—4.6%
——1——CVE-2026-559854.3 MED4.6%
——1The web management interface in
Tycon Systems TPDIN-Monitor-WEB2
stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.18hCVE-2026-1446—4.6%
——1——CVE-2025-9884—4.6%
——1——CVE-2026-46423—4.6%
——1——CVE-2024-34615—4.6%
——1——CVE-2024-47149—4.6%
——1——CVE-2025-3770—4.6%
——1——CVE-2024-20869—4.6%
——1——CVE-2020-11293—4.6%
——1——CVE-2025-65842—4.6%
——1——CVE-2025-39846—4.6%
——1——CVE-2025-46328—4.6%
——1——CVE-2021-47803—4.6%
——1——CVE-2021-1963—4.6%
——1——CVE-2025-12343—4.6%
——1——