Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,696
- Medium6,987
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-7447—34.2%
——10——CVE-2025-48742—34.2%
——10——CVE-2025-62462—34.2%
——10——CVE-2024-11147—34.2%
——10——CVE-2026-534476.5 MED34.2%
——10Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35.69dCVE-2022-1204—34.2%
——10——CVE-2024-7132—34.2%
——10——CVE-2026-41502—34.2%
——10——CVE-2026-841088.1 HIG34.2%
——10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.17hCVE-2026-825269.8 CRI34.2%
——10R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account.15dCVE-2024-52872—34.2%
——10——CVE-2024-9528—34.2%
——10——CVE-2026-572748.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in password field (no key present)83dCVE-2026-572778.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in key field83dCVE-2023-38082—34.2%
——10——CVE-2023-37349—34.2%
——10——CVE-2025-14900—34.2%
——10——CVE-2025-64757—34.2%
——10——CVE-2026-41882—34.2%
——10——CVE-2019-19490—34.2%
——10——CVE-2024-46886—34.2%
——10——CVE-2025-432648.8 HIG34.2%
——10The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.61dCVE-2026-33133—34.2%
——10——CVE-2024-21671—34.2%
——10——CVE-2023-34309—34.2%
——10——CVE-2017-6277—34.2%
——10——CVE-2022-25576—34.2%
——10——CVE-2025-28236—34.2%
——10——CVE-2023-302377.8 HIG34.2%
——10CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.76dCVE-2019-4383—34.2%
——10——CVE-2026-40413—34.2%
——10——CVE-2024-46961—34.2%
——10——CVE-2023-6844—34.2%
——10——CVE-2024-26478—34.2%
——10——CVE-2026-15320—34.2%
——10——CVE-2026-23780—34.2%
——10——CVE-2026-572788.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in ip field83dCVE-2023-50938—34.2%
——10——CVE-2019-5669—34.2%
——10——CVE-2023-37354—34.2%
——10——