Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,696
- Medium6,987
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-825269.8 CRI34.2%
——10R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account.15dCVE-2026-572748.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in password field (no key present)83dCVE-2024-9528—34.2%
——10——CVE-2026-572778.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in key field83dCVE-2024-52872—34.2%
——10——CVE-2023-38082—34.2%
——10——CVE-2023-50938—34.2%
——10——CVE-2023-302377.8 HIG34.2%
——10CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.76dCVE-2026-40413—34.2%
——10——CVE-2025-28236—34.2%
——10——CVE-2019-4383—34.2%
——10——CVE-2025-14900—34.2%
——10——CVE-2023-38079—34.2%
——10——CVE-2023-34303—34.2%
——10——CVE-2026-572768.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in password field (key present)83dCVE-2024-21671—34.2%
——10——CVE-2022-25576—34.2%
——10——CVE-2023-34309—34.2%
——10——CVE-2017-6277—34.2%
——10——CVE-2024-46886—34.2%
——10——CVE-2019-19490—34.2%
——10——CVE-2026-33133—34.2%
——10——CVE-2025-432648.8 HIG34.2%
——10The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.61dCVE-2024-6969—34.2%
——10——CVE-2024-12303—34.2%
——10——CVE-2026-146935.4 MED34.2%
——10A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_order of the file classes/Master.php. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used.79dCVE-2025-13451—34.2%
——10——CVE-2023-38084—34.2%
——10——CVE-2026-116187.3 HIG34.2%
——10A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Test Endpoint. Executing a manipulation can lead to improper authentication. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called f95389e7f74acec42bcee079a616aaa06f9551d2. A patch should be applied to remediate this issue.62dCVE-2026-0653—34.2%
——10——CVE-2025-9890—34.2%
——10——CVE-2026-572738.3 HIG34.2%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to provide the necessary details to connect to a camera. The handler associated with this command that we call`handle_connection_info` contains multiple instances of string copy that can overflow. The function `handle_connect_info` copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that do not enforce length limits.
#### Buffer Overflow in username field (no key present)83dCVE-2023-37348—34.2%
——10——CVE-2026-11846—34.2%
——10——CVE-2024-48937—34.2%
——10——CVE-2026-24484—34.2%
——10——CVE-2024-56143—34.2%
——10——CVE-2024-7105—34.2%
——10——CVE-2024-10535—34.2%
——10——CVE-2025-46192—34.2%
——10——