Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,590
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-7421—34.6%
——10——CVE-2026-48515—34.6%
——10——CVE-2022-47011—34.6%
——10——CVE-2024-2399—34.6%
——10——CVE-2026-48514—34.6%
——10——CVE-2024-7238—34.6%
——10——CVE-2021-31421—34.6%
——10——CVE-2025-4650—34.6%
——10——CVE-2026-48516—34.6%
——10——CVE-2025-69213—34.6%
——10——CVE-2007-2525—34.6%
——10——CVE-2022-47010—34.6%
——10——CVE-2024-11455—34.6%
——10——CVE-2023-27327—34.6%
——10——CVE-2026-437318.8 HIG34.6%
——10A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.37dCVE-2016-2414—34.6%
——10——CVE-2024-52801—34.6%
——10——CVE-2020-2648—34.6%
——10——CVE-2025-58059—34.6%
——10——CVE-2024-11570—34.6%
——10——CVE-2026-3054—34.6%
——10——CVE-2008-0889—34.6%
——10——CVE-2016-5501—34.6%
——10——CVE-2007-1592—34.6%
——10——CVE-2026-115553.7 LOW34.6%
——10A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.63dCVE-2026-688278.0 HIG34.6%
——10Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.6dCVE-2022-4219—34.6%
——10——CVE-2019-15807—34.6%
——10——CVE-2026-334455.9 MED34.6%
——10CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with an
intimate knowledge of and total control over the tunnel protocol can create a
persistent DoS against the server.69dCVE-2023-43292—34.6%
——10——CVE-2025-8109—34.6%
——10——CVE-2025-0154—34.6%
——10——CVE-2023-32126—34.6%
——10——CVE-2026-48846—34.6%
——10——CVE-2026-56767.3 HIG34.6%
——10A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used.62dCVE-2026-1355—34.6%
——10——CVE-2025-148435.3 MED34.6%
——10The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted request with a valid order ID.48dCVE-2019-9424—34.6%
——10——CVE-2026-50703—34.6%
——10——CVE-2026-48511—34.6%
——10——