Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-22328——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2023-7354——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.46dCVE-2025-24837——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused40dCVE-2023-32640——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-7809——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.12dCVE-2021-47994——
——0Rejected reason: This CVE ID has been rejected.41dCVE-2026-72845——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.32dCVE-2023-27884——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-61710——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61453. Reason: This candidate is a duplicate of CVE-2026-61453. Notes: All CVE users should reference CVE-2026-61453 instead of this candidate.68dCVE-2026-49944——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.75dCVE-2026-23675——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.42dCVE-2026-89155——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.1dCVE-2023-49592——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-940464.3 MED—
——0A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPath/filePath can lead to path traversal. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. isPathInsideProjectRoot only blocks filePath escaping the attacker-chosen projectRootPath; the root itself is untrusted client input - set projectRootPath=/etc, filePath=hosts and the guard passes. The project was informed of the problem early through an issue report but has not responded yet.11hCVE-2026-940284.3 MED—
——0A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.26.0 is able to address this issue. This patch is called fb221afa258c8dd2c4ac95b1996c33ef9db3f477. The affected component should be upgraded.17hCVE-2026-941068.8 HIG—
——0getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.18hCVE-2023-47176——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-6890——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.52dCVE-2026-72858——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2023-49720——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-6822——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2023-35000——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-939762.4 LOW—
——0A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.20hCVE-2026-587166.7 MED0.0%
——0In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.3dCVE-2023-42777——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2023-42432——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-51279——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.52dCVE-2026-76829——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.28dCVE-2026-74226——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.32dCVE-2026-22657——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.42dCVE-2026-51285——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.52dCVE-2013-1446——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Was assigned for an old issue in the brltty daemon and never published completely.6dCVE-2025-13398——
——0Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID.19dCVE-2023-45216——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2023-23544——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-11902——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2023-54378——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.46dCVE-2026-43636——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.65dCVE-2021-47993——
——0Rejected reason: This CVE ID has been rejected.41dCVE-2026-29026——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.42d