Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-7684—34.7%
——10——CVE-2025-27199—34.7%
——10——CVE-2026-0803—34.7%
——10——CVE-1999-0374—34.7%
——10——CVE-2026-568316.5 MED34.7%
——10Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.7dCVE-2020-21643—34.7%
——10——CVE-2026-50230—34.7%
——10——CVE-2023-49215—34.6%
——10——CVE-2020-5355—34.7%
——10——CVE-2024-49543—34.7%
——10——CVE-2024-49545—34.7%
——10——CVE-2026-33538—34.7%
——10——CVE-2024-28245—34.7%
——10——CVE-2017-14019—34.7%
——10——CVE-2017-16537—34.7%
——10——CVE-2024-52992—34.7%
——10——CVE-2022-25734—34.7%
——10——CVE-2024-52864—34.7%
——10——CVE-2024-53960—34.7%
——10——CVE-2026-102163.7 LOW34.7%
——10A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.64dCVE-2022-33254—34.7%
——10——CVE-2026-1708—34.7%
——10——CVE-2022-40503—34.6%
——10——CVE-2024-52862—34.7%
——10——CVE-2025-57792—34.7%
——10——CVE-2022-25735—34.7%
——10——CVE-2024-28755—34.7%
——10——CVE-2022-25733—34.7%
——10——CVE-2025-54992—34.7%
——10——CVE-2024-52865—34.7%
——10——CVE-2025-1677—34.7%
——10——CVE-2023-39493—34.7%
——10——CVE-2026-26929—34.7%
——10——CVE-2025-61514—34.7%
——10——CVE-2023-218017.8 HIG34.7%
——10Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability35dCVE-2025-50891—34.7%
——10——CVE-2026-22168—34.7%
——10——CVE-2018-25128—34.7%
——10——CVE-2026-448438.2 HIG34.7%
——10LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="all". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime paths require. As a result, attacker-supplied LangChain serialized constructor dictionaries may cause trusted runtime paths to instantiate classes with untrusted constructor arguments. This vulnerability is fixed in 0.3.85 and 1.3.3.63dCVE-2019-19055—34.7%
——10——