Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,705
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-20891—34.1%
——10——CVE-2026-576799.3 CRI34.1%
——10Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.83dCVE-2021-42755—34.1%
——10——CVE-2024-39387—34.1%
——10——CVE-2026-560038.5 HIG34.1%
——10A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.76dCVE-2026-146095.6 MED34.1%
——10A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.79dCVE-2025-41067—34.1%
——10——CVE-2026-555945.3 MED34.1%
——10ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.83dCVE-2023-2809—34.1%
——10——CVE-2026-56067—34.1%
——10——CVE-2026-1290—34.1%
——10——CVE-2023-33751—34.1%
——10——CVE-2025-24651—34.1%
——10——CVE-2022-47549—34.1%
——10——CVE-2022-46438—34.1%
——10——CVE-2018-1998—34.1%
——10——CVE-2025-14014—34.1%
——10——CVE-2025-686405.3 MED34.1%
——10The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of devices associated with the account.62dCVE-2026-168883.7 LOW34.1%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.34dCVE-2026-581757.5 HIG34.1%
——10Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.53dCVE-2026-67477.5 HIG34.1%
——10Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.70dCVE-2019-3815—34.1%
——10——CVE-2019-19166—34.1%
——10——CVE-2024-12299—34.1%
——10——CVE-2010-3357—34.1%
——10——CVE-2017-18347—34.1%
——10——CVE-2026-581787.5 HIG34.1%
——10The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.53dCVE-2020-12499—34.1%
——10——CVE-2026-56068—34.1%
——10——CVE-2022-48140—34.1%
——10——CVE-2026-759328.6 HIG34.1%
——10Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.33dCVE-2019-18996—34.1%
——10——CVE-2026-123525.9 MED34.1%
——10This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.72dCVE-2026-920369.8 CRI34.1%
——10Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.2dCVE-2026-24052—34.1%
——10——CVE-2020-10768—34.1%
——10——CVE-2026-12798—34.0%
——10——CVE-2025-10978—34.0%
——10——CVE-2023-45715—34.0%
——10——CVE-2024-51812—34.0%
——10——