Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-569148.4 HIG0.0%
——0In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3hCVE-2026-43636——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.66dCVE-2023-40157——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2023-27508——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused26dCVE-2026-94381——
——0MISP has a security issue that can let a user gain more access than their API key is supposed to allow.
A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function could accidentally restore the user’s normal account permissions. This means someone with a read-only API key could potentially gain write, delete, or even administrator access if their underlying account has those permissions.
Exploiting the issue requires a valid read-only API key and a single request to the affected function.
The main impact is that MISP’s API key restrictions can be bypassed, allowing actions that the API key was specifically meant to prevent.
Version affected: <2.5.475hCVE-2026-53991——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2026-74226——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.33dCVE-2023-37395—0.0%
——0——CVE-2023-54386——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.47dCVE-2026-925748.8 HIG—
——0A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary.
Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released.
Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.4hCVE-2026-46536——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.32dCVE-2026-631168.8 HIG—
——0deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When an authenticated user sends a PATCH_MULTI record operation while permission.type is config, getRulesForMessage returns a null rule specification and ConfigPermission.canPerformAction treats the missing specification as an unconditional allow instead of applying RULE_TYPES.WRITE. Any authenticated user can therefore modify arbitrary protected records, corrupt application state, or cause service disruption; deployments using the default permission type none already allow all operations and are not additionally affected. This issue is fixed in version 10.1.1.2hCVE-2026-944497.5 HIG—
——0A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory.2hCVE-2026-71982——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.28dCVE-2026-90839——
——0Rejected reason: this is rejected15hCVE-2026-58461——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.69dCVE-2026-22651——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.42dCVE-2026-623698.1 HIG—
——0KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination without sufficient validation. During keadm join or installation on Windows edge nodes, an archive influenced through a compromised, replaced, or untrusted download source can contain parent-directory components, Windows-style backslashes, absolute paths, or drive-prefixed paths that escape the intended directory. The affected keadm process can consequently write or overwrite files with its own privileges, potentially modifying configuration, executable, or service files and enabling persistent system modification or code execution. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.2hCVE-2023-22446——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused26dCVE-2026-91921——
——0Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain unsanitised content blocks. The impact is limited to the user’s own interactive session; no compromise of internal infrastructure, access to third-party data or impact on administrative panels has been identified.8hCVE-2023-39931——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-67619——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2025-25275——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused40dCVE-2026-585046.1 MED—
——0draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed by TextFormatPanel.addFont() in src/main/webapp/js/grapheditor/Format.js. An HTML sibling cell keeps the formatted-label path enabled while an editable=0 plain-text sibling is excluded from the merged selection style but remains in the iteration set. graph.cellRenderer.getLabelValue() returns that plain-text label without HTML encoding, and mxUtils.canConvertHtmlToSvg() parses it as HTML, bypassing the earlier CVE-2026-46642 remediation. Successful exploitation can expose diagram data, browser storage, non-HttpOnly cookies, and same-origin actions available to the victim. This issue is fixed in version 30.2.5.3hCVE-2020-37258——
——0Rejected reason: This CVE ID has been rejected.41dCVE-2026-29025——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.42dCVE-2023-32631——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2023-21178—0.0%
——0——CVE-2026-76069——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.31dCVE-2023-34393——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2023-31201——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused25dCVE-2026-89155——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2dCVE-2023-54367——
——0Rejected reason: This CVE ID has been rejected.41dCVE-2023-54383——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.47dCVE-2026-14942——
——0Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report was withdrawn: the precondition it depends on, an attacker obtaining a review form identifier belonging to a customer they do not already have access to, could not be demonstrated. No advisory was issued for this ID.24dCVE-2026-842983.1 LOW—
——0Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and callback delivery resolves that map by task UUID without tenant identity. An authenticated tenant worker that knows another tenant's durable task UUID and keeps a stream open on the same dispatcher process can receive that task's durable callback result payload. UUIDv4 values are not enumerable, and single-tenant deployments are unaffected in practice. This issue is fixed in version 0.95.3.1hCVE-2026-6889——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.53dCVE-2026-771656.5 MED—
——0File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.1hCVE-2026-51301——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.52dCVE-2026-6822——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.32d