Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,419
- Medium6,836
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-3111—35.5%
——11——CVE-2026-713486.8 MED35.5%
——11Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.21hCVE-2026-762088.2 HIG35.5%
——11phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDAP. The state transition is not logged, so administrators cannot detect that the block was overridden. Fixed in 4.1.7.24dCVE-2026-42735—35.5%
——11——CVE-2005-4412—35.5%
——11——CVE-2024-0895—35.5%
——11——CVE-2025-64898—35.5%
——11——CVE-2017-17044—35.5%
——11——CVE-2026-156903.1 LOW35.5%
——11A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference. The attack can be executed remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit is publicly available and might be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.73dCVE-2025-57149—35.5%
——11——CVE-2024-50616—35.5%
——11——CVE-2023-7231—35.5%
——11——CVE-2026-120975.3 MED35.5%
——11The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.79dCVE-2021-44299—35.5%
——11——CVE-2026-729856.8 MED35.5%
——11Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.21hCVE-2026-749987.2 HIG35.5%
——11In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.17dCVE-2026-357176.3 MED35.5%
——11A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.65dCVE-2026-784516.8 MED35.5%
——11Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.14dCVE-2021-25424—35.5%
——11——CVE-2026-713496.8 MED35.5%
——11Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.21hCVE-2007-2454—35.5%
——11——CVE-2023-30743—35.5%
——11——CVE-2025-47204—35.5%
——11——CVE-2026-3375—35.5%
——11——CVE-2026-541326.8 MED35.5%
——11Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.65dCVE-2026-22207—35.5%
——11——CVE-2024-9906—35.5%
——11——CVE-2026-694906.8 MED35.5%
——11Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.21hCVE-2023-42452—35.5%
——11——CVE-2025-59109—35.5%
——11——CVE-2023-6881—35.5%
——11——CVE-2026-45339—35.5%
——11——CVE-2026-713296.8 MED35.5%
——11Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.21hCVE-2024-9320—35.5%
——11——CVE-2022-40274—35.5%
——11——CVE-2013-4459—35.5%
——11——CVE-2019-2444—35.5%
——11——CVE-2024-48868—35.5%
——11——CVE-2022-4792—35.5%
——11——CVE-2026-2888—35.5%
——11——