Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-3777—34.6%
——10——CVE-2019-1020014—34.6%
——10——CVE-2026-928035.3 MED34.6%
——10LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances.1dCVE-2026-649587.5 HIG34.6%
——10An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.48dCVE-2025-46877—34.6%
——10——CVE-2025-59140—34.6%
——10——CVE-2023-36385—34.6%
——10——CVE-2023-46693—34.6%
——10——CVE-2023-5987—34.6%
——10——CVE-2024-4566—34.6%
——10——CVE-2024-57068—34.6%
——10——CVE-2023-4523—34.6%
——10——CVE-2024-26312—34.6%
——10——CVE-2026-779276.5 MED34.6%
——10ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.1dCVE-2005-0457—34.6%
——10——CVE-2023-37284—34.6%
——10——CVE-2023-23548—34.6%
——10——CVE-2022-47591—34.6%
——10——CVE-2025-59331—34.6%
——10——CVE-2025-52483—34.6%
——10——CVE-2025-26268—34.6%
——10——CVE-2024-10865—34.6%
——10——CVE-2023-28994—34.6%
——10——CVE-2023-22682—34.6%
——10——CVE-2017-11158—34.6%
——10——CVE-2024-6446—34.6%
——10——CVE-2025-48888—34.6%
——10——CVE-2004-1151—34.6%
——10——CVE-2023-48314—34.6%
——10——CVE-2025-46872—34.6%
——10——CVE-2025-3302—34.6%
——10——CVE-2026-825505.3 MED34.6%
——10A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.24dCVE-2013-0420—34.6%
——10——CVE-2025-7186—34.6%
——10——CVE-2026-828035.3 MED34.6%
——10A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation of the argument valuestring leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.21dCVE-2023-40628—34.6%
——10——CVE-2026-53926—34.6%
——10——CVE-2024-5813—34.6%
——10——CVE-2025-8135—34.6%
——10——CVE-2026-105137.2 HIG34.6%
——10The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' and 'url' author metadata. This is due to insufficient input sanitization and output escaping on user-supplied MF2 author properties processed by the unauthenticated webmention REST endpoint and rendered directly into HTML 'value' attributes by the edit-comment-form template without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a privileged user (moderator or administrator) opens the affected comment edit screen.84d