Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-50230—34.7%
——10——CVE-2025-50891—34.7%
——10——CVE-2026-22168—34.7%
——10——CVE-2023-218017.8 HIG34.7%
——10Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability35dCVE-2026-4801—34.7%
——10——CVE-2023-5769—34.6%
——10——CVE-2023-41170—34.6%
——10——CVE-2024-27336—34.7%
——10——CVE-2018-25128—34.7%
——10——CVE-2024-52861—34.7%
——10——CVE-2024-5215—34.7%
——10——CVE-2002-0169—34.7%
——10——CVE-2023-41747—34.7%
——10——CVE-2024-52857—34.7%
——10——CVE-2022-33250—34.7%
——10——CVE-2022-40513—34.7%
——10——CVE-2026-32973—34.7%
——10——CVE-2024-28113—34.7%
——10——CVE-2022-33309—34.7%
——10——CVE-2024-52865—34.7%
——10——CVE-2025-54992—34.7%
——10——CVE-2022-25733—34.7%
——10——CVE-2024-28245—34.7%
——10——CVE-2020-26307—34.7%
——10——CVE-2016-8650—34.7%
——10——CVE-2026-201205.8 MED34.7%
——10A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.
This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.5dCVE-2024-4085—34.7%
——10——CVE-2026-540768.1 HIG34.6%
——10ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and engine/src/main/java/com/arcadedb/schema/LocalProperty.java remained unchecked. An authenticated identity, including a read-only API token without UPDATE_SCHEMA permission, can use DROP PROPERTY, ALTER TYPE, or ALTER PROPERTY through the database command/query HTTP endpoints to rename types, change inheritance, alter aliases or buckets, drop properties, and change property constraints. The issue does not directly disclose or write record data, but unauthorized schema mutation can corrupt the meaning of stored records and breach the documented permission model. This issue is fixed in version 26.6.1.8dCVE-2026-348256.5 MED34.6%
——10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who triggers a workflow containing a SQL node with template variables from user-controlled data can inject arbitrary SQL. This issue has been patched in version 2.0.30.61dCVE-2024-33327—34.6%
——10——CVE-2024-21383—34.6%
——10——CVE-2023-6742—34.6%
——10——CVE-2023-47656—34.6%
——10——CVE-2024-400839.6 CRI34.6%
——10A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via sscanf reading the token and timezone JSON fields into a fixed-length buffer.81dCVE-2019-8758—34.6%
——10——CVE-2019-12456—34.6%
——10——CVE-2022-22811—34.6%
——10——CVE-2024-1080—34.6%
——10——CVE-2024-5710—34.6%
——10——CVE-2024-37993—34.6%
——10——