Vulnerabilities exploitable today
353,511in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,435
- High8,291
- Medium7,422
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-39776—4.0%
——1——CVE-2026-481903.5 LOW4.0%
——1An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected.
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X7dCVE-2025-38517—4.0%
——1——CVE-2020-0146—4.0%
——1——CVE-2020-0139—4.0%
——1——CVE-2020-0147—4.0%
——1——CVE-2020-0148—4.0%
——1——CVE-2024-36961—4.0%
——1——CVE-2023-25546—4.0%
——1——CVE-2020-0158—4.0%
——1——CVE-2024-48875—4.0%
——1——CVE-2025-21908—4.0%
——1——CVE-2023-53504—4.0%
——1——CVE-2025-22240—4.0%
——1——CVE-2025-9892—4.0%
——1——CVE-2023-53459—4.0%
——1——CVE-2024-35914—4.0%
——1——CVE-2020-0145—4.0%
——1——CVE-2026-12249—4.0%
——1——CVE-2026-0665—4.0%
——1——CVE-2022-50310—4.0%
——1——CVE-2025-38731—4.0%
——1——CVE-2022-50433—4.0%
——1——CVE-2026-481913.5 LOW4.0%
——1An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them.
This issue affects OTRS with STORM modules:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X7dCVE-2025-39790—4.0%
——1——CVE-2025-70560—4.0%
——1——CVE-2026-23599—4.0%
——1——CVE-2019-2088—4.0%
——1——CVE-2024-8085—4.0%
——1——CVE-2026-28992—4.0%
——1——CVE-2025-61679—4.0%
——1——CVE-2024-24901—4.0%
——1——CVE-2025-21094—4.0%
——1——CVE-2025-38607—4.0%
——1——CVE-2026-33246—4.0%
——1——CVE-2026-526843.7 LOW4.0%
——1If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the
child records are used immediately if not expired and thus valid, or the
records are expired, and in that case not used. So this case
can only happen if almost expired records are used to refresh the
authoritative NS records.6dCVE-2026-562935.4 MED4.0%
——1Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications between organizations. Attackers can exploit this omission to retain unauthorized access to deployment history records in the source organization or cause the destination organization to lose access to transferred application deployment records.21dCVE-2024-8095—4.0%
——1——CVE-2025-43313—4.0%
——1——CVE-2024-28953—4.0%
——1——