Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,417
- High8,729
- Medium7,039
- Low799
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-2263—34.3%
——10——CVE-2022-30640—34.3%
——10——CVE-2022-30639—34.3%
——10——CVE-2022-30643—34.3%
——10——CVE-2026-57436—34.3%
——10——CVE-2025-65276—34.3%
——10——CVE-2024-27151—34.3%
——10——CVE-2024-235655.3 MED34.3%
——10HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.68dCVE-2023-30960—34.3%
——10——CVE-2016-7170—34.3%
——10——CVE-2020-2565—34.3%
——10——CVE-2013-1067—34.3%
——10——CVE-2016-7092—34.3%
——10——CVE-2025-04747.7 HIG34.3%
——10Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user.
This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.71dCVE-2020-29372—34.3%
——10——CVE-2024-45757—34.3%
——10——CVE-2018-12238—34.3%
——10——CVE-2023-50297—34.3%
——10——CVE-2023-4862—34.3%
——10——CVE-2026-1062—34.3%
——10——CVE-2023-50121—34.3%
——10——CVE-2024-22266—34.3%
——10——CVE-2026-3676—34.3%
——10——CVE-2026-198953.7 LOW34.3%
——10A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.34dCVE-2024-7027—34.3%
——10——CVE-2024-32743—34.3%
——10——CVE-2012-6546—34.3%
——10——CVE-2016-10395—34.3%
——10——CVE-2025-4640—34.3%
——10——CVE-2023-4388—34.3%
——10——CVE-2025-4852—34.3%
——10——CVE-2022-30638—34.3%
——10——CVE-2023-5956—34.3%
——10——CVE-2007-4590—34.3%
——10——CVE-2023-37518—34.3%
——10——CVE-2020-35907—34.3%
——10——CVE-2026-190019.8 CRI34.3%
——10The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.12dCVE-2020-210467.8 HIG34.3%
——10A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.77dCVE-2026-693577.1 HIG34.3%
——10Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.15dCVE-2026-57437—34.3%
——10——