Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-20847—3.9%
——1——CVE-2025-26582—3.9%
——1——CVE-2026-23865—3.9%
——1——CVE-2025-8351—3.9%
——1——CVE-2024-56496—3.9%
——1——CVE-2022-48470—3.9%
——1——CVE-2026-47274—3.9%
——1——CVE-2022-48719—3.9%
——1——CVE-2023-53426—3.9%
——1——CVE-2025-64999—3.9%
——1——CVE-2025-49148—3.9%
——1——CVE-2026-563595.4 MED3.9%
——1n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges.18dCVE-2024-47783—3.9%
——1——CVE-2025-26578—3.9%
——1——CVE-2025-26547—3.9%
——1——CVE-2026-32893—3.9%
——1——CVE-2026-570777.7 HIG3.9%
——1YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.
In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover.
Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.10dCVE-2025-38165—3.9%
——1——CVE-2026-44259—3.9%
——1——CVE-2026-46100—3.9%
——1——CVE-2025-27769—3.9%
——1——CVE-2025-12635—3.9%
——1——CVE-2025-13120—3.9%
——1——CVE-2025-9513—3.9%
——1——CVE-2025-26543—3.9%
——1——CVE-2024-56811—3.9%
——1——CVE-2025-38167—3.9%
——1——CVE-2025-26572—3.9%
——1——CVE-2024-56810—3.9%
——1——CVE-2022-38682—3.9%
——1——CVE-2026-551107.5 HIG3.9%
——1A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.18dCVE-2025-25160—3.9%
——1——CVE-2026-20601—3.9%
——1——CVE-2025-26568—3.9%
——1——CVE-2026-61456—3.9%
——1——CVE-2025-69014—3.9%
——1——CVE-2025-21897—3.9%
——1——CVE-2026-31953—3.9%
——1——CVE-2025-43497—3.9%
——1——CVE-2025-38128—3.9%
——1——