Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-0123—34.6%
——10——CVE-2024-5813—34.6%
——10——CVE-2026-53926—34.6%
——10——CVE-2023-40628—34.6%
——10——CVE-2026-825505.3 MED34.6%
——10A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.24dCVE-2026-828035.3 MED34.6%
——10A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation of the argument valuestring leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.21dCVE-2025-54459—34.6%
——10——CVE-2025-41645—34.6%
——10——CVE-2023-40664—34.6%
——10——CVE-2022-45349—34.6%
——10——CVE-2023-0896—34.6%
——10——CVE-2024-25662—34.6%
——10——CVE-2026-3592—34.6%
——10——CVE-2023-41235—34.6%
——10——CVE-2025-58149—34.6%
——10——CVE-2024-10941—34.6%
——10——CVE-2024-50996—34.6%
——10——CVE-2024-45877—34.6%
——10——CVE-2026-10092—34.6%
——10——CVE-2026-242517.8 HIG34.6%
——10NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.83dCVE-2026-40126—34.6%
——10OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server.
This issue was fixed in OutSystems Service Center version 11.41.226dCVE-2024-11438—34.6%
——10——CVE-2025-46572—34.6%
——10——CVE-2026-163509.8 CRI34.6%
——10Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.61dCVE-2024-45120—34.6%
——10——CVE-2025-8256—34.6%
——10——CVE-2026-39857.5 HIG34.6%
——10The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `has_checkout_consent()` method. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.33dCVE-2023-2020—34.6%
——10——CVE-2026-751439.8 CRI34.6%
——10FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.23dCVE-2025-43793—34.6%
——10——CVE-2026-45257.5 HIG34.6%
——10If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.71dCVE-2026-47279—34.6%
——10——CVE-2019-8534—34.6%
——10——CVE-2026-58488—34.6%
——10HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attackers to circumvent the rate-limiting of the /login and /register routes by spoofing IP addresses. HedgeDoc instances checked for CloudFlare's cf-connecting-ip header and used that instead of the users real IP address, if the header was present even when the request did not originate from Cloudflare. This made it possible for an attacker to spam login requests or create multiple arbitrary accounts by sending another cf-connecting-ip header every few requests. The issue has been fixed in version 1.11.0.71dCVE-2008-0779—34.6%
——10——CVE-2013-0420—34.6%
——10——CVE-2025-7186—34.6%
——10——CVE-2019-14389—34.6%
——10——CVE-2026-60030—34.6%
——10Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.62dCVE-2026-826235.3 MED34.6%
——10A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.23d