Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-46606—4.0%
——1——CVE-2026-577858.8 HIG4.0%
——1Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.4dCVE-2024-34637—4.0%
——1——CVE-2025-605357.3 HIG4.0%
——1A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.23dCVE-2026-80784.8 MED4.0%
——1Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicious HTML or JavaScript in changelog messages that executes in other users' browsers when they view the Activate Changes page or Audit log.5dCVE-2026-319815.9 MED4.0%
——1A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.17dCVE-2026-46150—4.0%
——1——CVE-2023-33074—4.0%
——1——CVE-2026-247613.7 LOW4.0%
——1Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metadata of resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.5dCVE-2023-53286—4.0%
——1——CVE-2026-464327.8 HIG4.0%
——1LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there are no publicly available patches.5dCVE-2025-14416—4.0%
——1——CVE-2025-20964—4.0%
——1——CVE-2026-146124.2 MED4.0%
——1Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.21dCVE-2026-28357—4.0%
——1——CVE-2022-23594—4.0%
——1——CVE-2026-10610—4.0%
——1Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.3dCVE-2024-12925—4.0%
——1——CVE-2024-28044—4.0%
——1——CVE-2025-39861—4.0%
——1——CVE-2023-30716—4.0%
——1——CVE-2023-20915—4.0%
——1——CVE-2024-34606—4.0%
——1——CVE-2026-27285—4.0%
——1——CVE-2024-34607—4.0%
——1——CVE-2024-34608—4.0%
——1——CVE-2024-34609—4.0%
——1——CVE-2026-577668.8 HIG4.0%
——1Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.25dCVE-2026-598385.9 MED4.0%
——1A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>12dCVE-2026-23497—4.0%
——1——CVE-2026-33003—4.0%
——1——CVE-2024-34604—4.0%
——1——CVE-2026-31780—4.0%
——1——CVE-2018-11983—4.0%
——1——CVE-2026-577598.8 HIG4.0%
——1Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.25dCVE-2023-41819—4.0%
——1——CVE-2025-20963—4.0%
——1——CVE-2025-20737—4.0%
——1——CVE-2026-493172.4 LOW4.0%
——1Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window — for example via a separately tracked CAN bus-off technique — can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation.6dCVE-2026-30868—4.0%
——1——