Vulnerabilities exploitable today
353,240in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,348
- High8,119
- Medium7,274
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-562935.4 MED4.0%
——1Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications between organizations. Attackers can exploit this omission to retain unauthorized access to deployment history records in the source organization or cause the destination organization to lose access to transferred application deployment records.19dCVE-2026-33246—4.0%
——1——CVE-2025-32655—4.0%
——1——CVE-2026-16966.1 MED4.0%
——1Some HTTP security headers are not properly set by the web server when sending responses to the client application.18dCVE-2026-33248—4.0%
——1——CVE-2020-0468—4.0%
——1——CVE-2022-50492—4.0%
——1——CVE-2023-53209—4.0%
——1——CVE-2023-25546—4.0%
——1——CVE-2023-53195—4.0%
——1——CVE-2025-38731—4.0%
——1——CVE-2023-53645—4.0%
——1——CVE-2026-46006—4.0%
——1——CVE-2025-20738—4.0%
——1——CVE-2026-648027.8 HIG4.0%
——1In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration4dCVE-2018-25327—4.0%
——1——CVE-2026-648037.8 HIG4.0%
——1In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK4dCVE-2025-604855.5 MED4.0%
——1A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.6dCVE-2023-53504—4.0%
——1——CVE-2021-0369—4.0%
——1——CVE-2025-38517—4.0%
——1——CVE-2025-20739—4.0%
——1——CVE-2024-53753—4.0%
——1——CVE-2024-53750—4.0%
——1——CVE-2023-53493—4.0%
——1——CVE-2026-5409—4.0%
——1——CVE-2026-36756—4.0%
——1——CVE-2024-35914—4.0%
——1——CVE-2024-20895—4.0%
——1——CVE-2025-14873—4.0%
——1——CVE-2024-53755—4.0%
——1——CVE-2023-23904—4.0%
——1——CVE-2026-622215.4 MED4.0%
——1OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.6dCVE-2025-65431—4.0%
——1——CVE-2026-3196—4.0%
——1——CVE-2025-9892—4.0%
——1——CVE-2026-481913.5 LOW4.0%
——1An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them.
This issue affects OTRS with STORM modules:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X6dCVE-2025-39960—4.0%
——1——CVE-2025-38318—4.0%
——1——CVE-2025-604815.5 MED4.0%
——1A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.6d