Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-41481—34.6%
——10——CVE-2023-40655—34.6%
——10——CVE-2022-45352—34.6%
——10——CVE-2012-1242—34.6%
——10——CVE-2024-50997—34.6%
——10——CVE-2023-37849—34.6%
——10——CVE-2008-2099—34.6%
——10——CVE-2023-48747—34.6%
——10——CVE-2023-40656—34.6%
——10——CVE-2026-47377—34.6%
——10——CVE-2023-40627—34.6%
——10——CVE-2024-4712—34.6%
——10——CVE-2023-40657—34.6%
——10——CVE-2026-77614—34.6%
——10——CVE-2026-78551—34.6%
——10RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources.
For local authentication, the login implementation previously checked whether a submitted username existed before invoking the password hash verification function. Requests containing a nonexistent username therefore returned significantly faster than requests for valid accounts, for which the computationally expensive password verification routine was executed. A remote attacker could measure these response-time differences to determine which usernames correspond to valid RansomLook accounts.
In addition, the /login endpoint did not restrict the number or frequency of failed authentication attempts. An attacker could consequently perform password brute-force, dictionary, password-spraying, or credential-stuffing attacks against known accounts without server-side throttling. For valid usernames, each authentication attempt also invokes the password key-derivation function, which consumes a significant amount of CPU time. A sufficiently high rate of login attempts could therefore occupy the application's synchronous Gunicorn workers and cause a denial of service affecting the entire application.
The issue has been addressed by always performing password verification using a randomly generated dummy password hash when the supplied username does not exist, eliminating the username-dependent timing discrepancy. Failed authentication attempts are additionally rate-limited per client IP address using Valkey/Redis, with five failed attempts within five minutes resulting in a one-hour block. The reverse-proxy configuration was also updated so that the application derives the client address from a trusted X-Forwarded-For value that cannot be overridden by a client-supplied header.30dCVE-2026-9097—34.6%
——10——CVE-2024-2118—34.6%
——10——CVE-2026-933105.3 MED34.6%
——10A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through a bug report but has not responded yet.5dCVE-2017-9242—34.6%
——10——CVE-2026-10577—34.6%
——10A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.71dCVE-2023-2267—34.6%
——10——CVE-2025-36601—34.6%
——10——CVE-2026-865115.3 MED34.6%
——10A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.15dCVE-2024-32753—34.6%
——10——CVE-2023-34064—34.6%
——10——CVE-2026-68187.2 HIG34.6%
——10The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.77dCVE-2026-46348—34.6%
——10——CVE-2011-5157—34.6%
——10——CVE-2000-1163—34.6%
——10——CVE-2021-3734—34.6%
——10——CVE-2026-242507.8 HIG34.6%
——10NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.83dCVE-2026-7710—34.6%
——10——CVE-2026-905825.3 MED34.6%
——10A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.8dCVE-2023-41238—34.6%
——10——CVE-2024-11385—34.6%
——10——CVE-2023-40659—34.6%
——10——CVE-2024-3238—34.6%
——10——CVE-2026-163559.8 CRI34.6%
——10JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.61dCVE-2021-22929—34.6%
——10——CVE-2026-123886.5 MED34.6%
——10A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns high-level administrative roles (like realm-admin) to themselves or others. This allows a restricted administrator to bypass security checks and gain full control over the entire realm.84d