Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,270
- High8,461
- Medium6,876
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-347325.3 MED35.3%
——11WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php both require admin privileges, the list.json.php template was shipped without this guard. Every plugin that uses the CreatePlugin code generator inherits this omission, resulting in 21 unauthenticated data listing endpoints across the platform. These endpoints expose sensitive data including user PII, payment transaction logs, IP addresses, user agents, and internal system records. At time of publication, there are no publicly available patches.63dCVE-2021-3544—35.3%
——11——CVE-2025-6495—35.3%
——11——CVE-2025-8468—35.3%
——11——CVE-2026-56337—35.3%
——11——CVE-2023-233817.8 HIG35.3%
——11Visual Studio Remote Code Execution Vulnerability37dCVE-2024-54236—35.3%
——11——CVE-2026-860037.5 HIG35.3%
——11CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack without the dns.DefaultMsgAcceptFunc request policy used by UDP, TCP, and DNS-over-TLS. An unauthenticated client can send an RFC 2136 UPDATE that the proxy or forward plugin passes unchanged to an update-capable upstream. If that upstream trusts CoreDNS's source address or connection and does not require an attacker-unknown end-to-end TSIG, the request appears to originate from CoreDNS and can add, replace, or delete DNS records, redirect traffic, take over names, alter mail routing, or disrupt the writable zone. This issue is fixed in version 1.14.7.22hCVE-2024-54265—35.3%
——11——CVE-2021-46559—35.3%
——11——CVE-2017-7884—35.3%
——11——CVE-2024-54240—35.3%
——11——CVE-2026-21042—35.3%
——11Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.17dCVE-2026-891735.3 MED35.3%
——11Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.14dCVE-2026-615035.3 MED35.3%
——11Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin account, facilitating password-guessing and session-forgery attacks.72dCVE-2024-54299—35.3%
——11——CVE-2023-42052—35.3%
——11——CVE-2026-586544.3 MED35.3%
——11The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType) beginning with 'image/' and does not inspect the actual file content or restrict the resulting extension, allowing an authenticated user to store arbitrary content — including PHP code, SVG with embedded JavaScript, and polyglot payloads — under user/accounts/avatars/ with predictable filenames. Direct HTTP access to the stored files is blocked by .htaccess (returns 403), but the files persist on disk and could lead to remote code execution or stored XSS in the presence of a path traversal flaw or server misconfiguration. Fixed in 1.0.1.79dCVE-2024-54235—35.3%
——11——CVE-2019-14898—35.3%
——11——CVE-2026-25727—35.3%
——11——CVE-2023-4962—35.3%
——11——CVE-2024-3323—35.3%
——11——CVE-2024-54364—35.3%
——11——CVE-2022-22313—35.3%
——11——CVE-2024-54231—35.3%
——11——CVE-2024-51392—35.3%
——11——CVE-2024-28196—35.3%
——11——CVE-2024-54275—35.3%
——11——CVE-2024-54322—35.3%
——11——CVE-2024-54288—35.3%
——11——CVE-2024-54302—35.3%
——11——CVE-2021-20854—35.3%
——11——CVE-2024-45872—35.3%
——11——CVE-2024-10498—35.3%
——11——CVE-2019-17650—35.3%
——11——CVE-2024-54290—35.3%
——11——CVE-2023-4810—35.3%
——11——CVE-2023-42087—35.3%
——11——CVE-2024-54406—35.3%
——11——