Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,665
- Medium7,438
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-727126.5 MED—
——0Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.1dCVE-2026-72773——
——0n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the tool to return the names and contents of arbitrary local files readable by the daemon's OS user. Any deployment where an actor can influence the tool's search input is affected.1dCVE-2026-72774——
——0n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pre-execution permission check compares the unresolved expression instead of the resolved credential type, the ownership check is skipped and the credential is loaded at execution time, allowing the member to use or exfiltrate a credential they were not granted. Exploitation requires knowing the target credential's identifier.1dCVE-2026-727806.5 MED—
——0Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.1dCVE-2026-4805610.0 CRI—
——0Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.1dCVE-2026-515838.5 HIG—
——0An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.5hCVE-2026-515849.8 CRI—
——0An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.5hCVE-2023-54370——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2023-54371——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2023-54372——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2023-54373——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2023-54374——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37257——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37258——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37260——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37261——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37263——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37265——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2021-47988——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2026-1706110.0 CRI—
——0A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.1dCVE-2021-47989——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2021-47990——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2020-37264——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2026-188608.7 HIG—
——0Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.1dCVE-2021-47991——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2021-47994——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2026-628867.8 HIG—
——0Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.10hCVE-2026-628857.8 HIG—
——0Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.19hCVE-2021-47995——
——0Rejected reason: This CVE ID has been rejected.1dCVE-2026-628836.7 MED—
——0Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.19hCVE-2026-628816.7 MED—
——0Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.19hCVE-2026-628807.8 HIG—
——0Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.10hCVE-2026-628789.8 CRI—
——0Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.9hCVE-2026-628278.8 HIG—
——0Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.10hCVE-2026-628248.8 HIG—
——0Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.10hCVE-2026-627997.8 HIG—
——0Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.10hCVE-2026-627977.8 HIG—
——0Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.10hCVE-2026-627877.5 HIG—
——0Use after free in Windows DNS allows an authorized attacker to execute code over a network.10hCVE-2026-727137.5 HIG—
——0XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an account without email verification, then submit crafted `file_name` values such as parent-directory traversal sequences to the `/workspace/file` handler to read host files including application secrets, database credentials, and system files outside the Docker sandbox.1dCVE-2026-730909.3 CRI—
——0PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a malicious federated server to rewrite another server's video metadata, visibility, media file, and HLS URLs. This issue is fixed in version 8.2.2.1d