Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,417
- High8,729
- Medium7,039
- Low799
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3995—34.3%
——10——CVE-2026-197493.7 LOW34.3%
——10A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.37dCVE-2026-49864—34.3%
——10wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`'d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\x1b[5i...:...\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim's SSH session. Version 3.0.4 fixes the issue.14dCVE-2023-38367—34.3%
——10——CVE-2024-549996.5 MED34.3%
——10MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.81dCVE-2025-32744—34.3%
——10——CVE-2022-30646—34.3%
——10——CVE-2023-4925—34.3%
——10——CVE-2025-2390—34.3%
——10——CVE-2024-57704—34.3%
——10——CVE-2026-346868.7 HIG34.3%
——10Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.27dCVE-2026-43464—34.3%
——10——CVE-2025-2882—34.3%
——10——CVE-2022-318778.8 HIG34.3%
——10An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.77dCVE-2023-32491—34.3%
——10——CVE-2023-5943—34.3%
——10——CVE-2023-4862—34.3%
——10——CVE-2025-58218—34.3%
——10——CVE-2026-417092.7 LOW34.3%
——10VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.55dCVE-2023-4502—34.3%
——10——CVE-2025-22924—34.3%
——10——CVE-2026-693577.1 HIG34.3%
——10Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.15dCVE-2026-57437—34.3%
——10——CVE-2020-210467.8 HIG34.3%
——10A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.77dCVE-2023-5956—34.3%
——10——CVE-2016-7170—34.3%
——10——CVE-2020-2565—34.3%
——10——CVE-2016-7092—34.3%
——10——CVE-2013-1067—34.3%
——10——CVE-2023-4388—34.3%
——10——CVE-2025-4640—34.3%
——10——CVE-2022-30638—34.3%
——10——CVE-2025-4852—34.3%
——10——CVE-2016-10395—34.3%
——10——CVE-2026-812408.6 HIG34.3%
——10Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.2dCVE-2026-834585.3 MED34.3%
——10Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).5dCVE-2023-6037—34.3%
——10——CVE-2026-834595.3 MED34.3%
——10Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versions that are affected are 3.0.0-3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).7dCVE-2026-29191—34.3%
——10——CVE-2024-2263—34.3%
——10——