Vulnerabilities exploitable today
379,234in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,371
- High8,538
- Medium7,064
- Low795
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-5731—34.8%
——10——CVE-2026-544128.2 HIG34.8%
——10LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet.45dCVE-2024-13296—34.8%
——10——CVE-2020-28008—34.8%
——10——CVE-2016-9913—34.8%
——10——CVE-2018-12173—34.8%
——10——CVE-2012-5532—34.8%
——10——CVE-2014-0876—34.8%
——10——CVE-2024-7427—34.8%
——10——CVE-2026-692087.5 HIG34.8%
——10Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an application that protects at least one route with DigestAuth, an unauthenticated attacker can repeatedly trigger authentication challenges, causing the persistent nonce map to grow until the JVM exhausts heap memory. This issue is fixed in versions 0.23.35 and 1.0.0-M47.7dCVE-2015-7962—34.8%
——10——CVE-2015-8034—34.8%
——10——CVE-2021-34420—34.8%
——10——CVE-2018-14828—34.8%
——10——CVE-2026-5816—34.8%
——10——CVE-2014-3563—34.8%
——10——CVE-2017-8239—34.8%
——10——CVE-2024-6086—34.8%
——10——CVE-2025-6073—34.8%
——10——CVE-2026-712389.1 CRI34.8%
——10DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens, achieving full account takeover.29dCVE-2018-6653—34.8%
——10——CVE-2023-38989—34.8%
——10——CVE-2024-51031—34.8%
——10——CVE-2004-2554—34.8%
——10——CVE-2024-5463—34.8%
——10——CVE-2026-609786.5 MED34.8%
——10Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).54dCVE-2026-684879.9 CRI34.8%
——10Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.13dCVE-2026-347127.5 HIG34.8%
——10CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.27dCVE-2025-14987—34.8%
——10——CVE-2023-25466—34.8%
——10——CVE-2025-59163—34.8%
——10——CVE-2017-14609—34.8%
——10——CVE-2018-2560—34.8%
——10——CVE-2017-8072—34.8%
——10——CVE-2003-0994—34.8%
——10——CVE-2012-10022—34.8%
——10——CVE-2014-2893—34.8%
——10——CVE-2020-0366—34.8%
——10——CVE-2016-8910—34.8%
——10——CVE-2011-2213—34.8%
——10——