Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-8758—34.6%
——10——CVE-2024-37993—34.6%
——10——CVE-2024-5710—34.6%
——10——CVE-2022-30623—34.6%
——10——CVE-2023-23979—34.6%
——10——CVE-2026-387545.1 MED34.6%
——10A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.63dCVE-2023-22309—34.6%
——10——CVE-2026-278517.4 HIG34.6%
——10When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.71dCVE-2019-12456—34.6%
——10——CVE-2022-22811—34.6%
——10——CVE-2024-400839.6 CRI34.6%
——10A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via sscanf reading the token and timezone JSON fields into a fixed-length buffer.81dCVE-2023-27421—34.6%
——10——CVE-2021-40833—34.6%
——10——CVE-2025-59330—34.6%
——10——CVE-2013-5781—34.6%
——10——CVE-2025-59141—34.6%
——10——CVE-2024-21001—34.6%
——10——CVE-2024-21383—34.6%
——10——CVE-2026-348256.5 MED34.6%
——10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who triggers a workflow containing a SQL node with template variables from user-controlled data can inject arbitrary SQL. This issue has been patched in version 2.0.30.61dCVE-2024-33327—34.6%
——10——CVE-2010-4817—34.6%
——10——CVE-2025-7745—34.6%
——10——CVE-2024-1471—34.6%
——10——CVE-2026-45672—34.6%
——10——CVE-2024-23174—34.6%
——10——CVE-2025-35053—34.6%
——10——CVE-2023-36501—34.6%
——10——CVE-2025-67844—34.6%
——10——CVE-2023-22704—34.6%
——10——CVE-2024-10399—34.6%
——10——CVE-2022-46843—34.6%
——10——CVE-2022-34474—34.6%
——10——CVE-2024-11684—34.6%
——10——CVE-2026-770188.8 HIG34.6%
——10The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.26dCVE-2024-23767—34.6%
——10——CVE-2023-36384—34.6%
——10——CVE-2010-1162—34.6%
——10——CVE-2015-4907—34.6%
——10——CVE-2023-5445—34.6%
——10——CVE-2026-30345—34.6%
——10——