Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,354
- High8,500
- Medium6,881
- Low783
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-215527.5 HIG34.4%
——10In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed26dCVE-2023-38400—34.4%
——10——CVE-2026-28068—34.4%
——10——CVE-2026-28057—34.4%
——10——CVE-2025-138756.3 MED34.4%
——10A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocihelper/service/impl/OciServiceImpl.java of the component OCI Configuration Upload. Executing manipulation of the argument File can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.21dCVE-2024-27328—34.4%
——10——CVE-2024-27899—34.4%
——10——CVE-2026-28067—34.4%
——10——CVE-2026-67497.5 HIG34.4%
——10Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.71dCVE-2022-2792—34.4%
——10——CVE-2026-524909.8 CRI34.4%
——10An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c14dCVE-2026-63385—34.4%
——10Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition.14dCVE-2026-12673—34.4%
——10——CVE-2026-28034—34.4%
——10——CVE-2026-215537.5 HIG34.4%
——10In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed26dCVE-2024-48461—34.4%
——10——CVE-2025-49924—34.4%
——10——CVE-2026-28020—34.4%
——10——CVE-2026-215557.5 HIG34.4%
——10In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed26dCVE-2026-215487.5 HIG34.4%
——10In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.26dCVE-2009-3456—34.4%
——10——CVE-2026-28026—34.4%
——10——CVE-2026-215547.5 HIG34.4%
——10In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed26dCVE-2023-48326—34.4%
——10——CVE-2026-28087—34.4%
——10——CVE-2026-4750—34.4%
——10——CVE-2020-24159—34.4%
——10——CVE-2026-28009—34.4%
——10——CVE-2020-8601—34.4%
——10——CVE-2026-156104.3 MED34.4%
——10The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger arbitrary re-embedding of stored RAG documents, modifying the rag_documents table and consuming the site owner's paid third-party AI API credits (OpenAI, Gemini, OpenRouter, or xAI).69dCVE-2023-47521—34.4%
——10——CVE-2023-49170—34.4%
——10——CVE-2024-27325—34.4%
——10——CVE-2024-36110—34.4%
——10——CVE-2016-5384—34.4%
——10——CVE-2023-32796—34.4%
——10——CVE-2026-27996—34.4%
——10——CVE-2023-49178—34.4%
——10——CVE-2018-16877—34.4%
——10——CVE-2026-28035—34.4%
——10——