Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,704
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-18245—34.1%
——10——CVE-2026-35486—34.1%
——10——CVE-2026-577399.3 CRI34.1%
——10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.72dCVE-2024-6098—34.1%
——10——CVE-2026-46608—34.1%
——10——CVE-2023-49765—34.1%
——10——CVE-2018-5486—34.1%
——10——CVE-2008-5367—34.1%
——10——CVE-2026-535478.8 HIG34.1%
——10Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user export that includes the global settings table even though the rest of the export is user-scoped. The settings table contains reset_code_ and temp_reset_token_ password-reset artifacts, allowing a low-privileged authenticated user to recover another local account's reset code and complete the normal password-reset flow. Successful exploitation results in local-user account takeover and administrative compromise when the victim is an administrator. This issue is fixed in version 2.3.2.14dCVE-2012-4106—34.1%
——10——CVE-2022-35672—34.1%
——10——CVE-2012-1090—34.1%
——10——CVE-2013-2119—34.1%
——10——CVE-2023-49151—34.1%
——10——CVE-2023-52943—34.1%
——10——CVE-2024-3089—34.1%
——10——CVE-2023-47071—34.1%
——10——CVE-2023-45646—34.1%
——10——CVE-2016-4025—34.1%
——10——CVE-2022-48350—34.1%
——10——CVE-2018-25090—34.1%
——10——CVE-2023-533609.8 CRI34.1%
——10In the Linux kernel, the following vulnerability has been resolved:
NFSv4.2: Rework scratch handling for READ_PLUS (again)
I found that the read code might send multiple requests using the same
nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is
how we ended up occasionally double-freeing the scratch buffer, but also
means we set a NULL pointer but non-zero length to the xdr scratch
buffer. This results in an oops the first time decoding needs to copy
something to scratch, which frequently happens when decoding READ_PLUS
hole segments.
I fix this by moving scratch handling into the pageio read code. I
provide a function to allocate scratch space for decoding read replies,
and free the scratch buffer when the nfs_pgio_header is freed.50dCVE-2024-22407—34.1%
——10——CVE-2024-45650—34.1%
——10——CVE-2021-40376—34.1%
——10——CVE-2026-54849—34.1%
——10——CVE-2025-25403—34.1%
——10——CVE-2024-321624.3 MED34.1%
——10CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.76dCVE-2023-38054—34.1%
——10——CVE-2025-29757—34.1%
——10——CVE-2016-3563—34.1%
——10——CVE-2020-7280—34.1%
——10——CVE-2025-20790—34.1%
——10——CVE-2024-21116—34.1%
——10——CVE-2022-48360—34.1%
——10——CVE-2026-54831—34.1%
——10——CVE-2025-30118—34.1%
——10——CVE-2023-38048—34.1%
——10——CVE-2024-24911—34.1%
——10——CVE-2026-3558—34.1%
——10——