Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,705
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-24607—34.1%
——10——CVE-2021-4149—34.1%
——10——CVE-2019-2397—34.1%
——10——CVE-2024-7122—34.1%
——10——CVE-2020-5909—34.1%
——10——CVE-2019-256688.2 HIG34.1%
——10News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information.60dCVE-2026-181034.9 MED34.1%
——10A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containing an overly long InfiniBand MAC address, triggers a buffer overflow in the `print_hw_addr()` function. Successful exploitation leads to a persistent denial of service (DoS), causing the `dhcpd` service to crash and preventing it from restarting without manual intervention.48dCVE-2016-9062—34.1%
——10——CVE-2021-40981—34.1%
——10——CVE-2023-34228—34.1%
——10——CVE-2026-506574.7 MED34.1%
——10Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.63dCVE-2025-14432—34.1%
——10——CVE-2001-1394—34.1%
——10——CVE-2026-856036.5 MED34.1%
——10Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST field to write arbitrary .md files outside the pages directory with attacker-controlled content.9dCVE-2019-14404—34.1%
——10——CVE-2025-1156—34.1%
——10——CVE-2021-38538—34.1%
——10——CVE-2021-46668—34.1%
——10——CVE-2024-40734—34.1%
——10——CVE-2015-1323—34.1%
——10——CVE-2026-483349.3 CRI34.1%
——10Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.26dCVE-2024-36453—34.1%
——10——CVE-2024-8303—34.1%
——10——CVE-2025-5060—34.1%
——10——CVE-2026-15070—34.1%
——10——CVE-2026-56234—34.1%
——10——CVE-2024-0625—34.1%
——10——CVE-2026-56034—34.1%
——10——CVE-2021-46664—34.1%
——10——CVE-2026-920379.8 CRI34.1%
——10Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.2dCVE-2024-0596—34.1%
——10——CVE-2025-8749—34.1%
——10——CVE-2024-39387—34.1%
——10——CVE-2026-146095.6 MED34.1%
——10A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.79dCVE-2024-1245—34.1%
——10——CVE-2017-202528.2 HIG34.1%
——10Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information.35dCVE-2024-56290—34.1%
——10——CVE-2026-560038.5 HIG34.1%
——10A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.76dCVE-2026-555945.3 MED34.1%
——10ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.83dCVE-2017-9480—34.1%
——10——