Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2010-5271—34.0%
——10——CVE-2010-5200—34.0%
——10——CVE-2010-5265—34.0%
——10——CVE-2010-5243—34.0%
——10——CVE-2010-3373—34.0%
——10——CVE-2019-20636—34.0%
——10——CVE-2026-69220—34.0%
——10The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.12dCVE-2010-5255—34.0%
——10——CVE-2010-5244—34.0%
——10——CVE-2017-9694—34.0%
——10——CVE-2025-22221—34.0%
——10——CVE-2026-176964.3 MED34.0%
——10Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)54dCVE-2012-6547—34.0%
——10——CVE-2021-0591—34.0%
——10——CVE-2024-9243—34.0%
——10——CVE-2026-106177.3 HIG34.0%
——10A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.63dCVE-2023-30499—34.0%
——10——CVE-2021-35542—34.0%
——10——CVE-2023-30515—34.0%
——10——CVE-2024-5169—34.0%
——10——CVE-2017-9605—34.0%
——10——CVE-2024-39025—34.0%
——10——CVE-2023-21904—34.0%
——10——CVE-2019-3729—34.0%
——10——CVE-2023-33984—34.0%
——10——CVE-2016-3159—34.0%
——10——CVE-2024-38826—34.0%
——10——CVE-2010-5268—34.0%
——10——CVE-2026-1694010.0 CRI34.0%
——10The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover.28dCVE-2010-5256—34.0%
——10——CVE-2026-3153—34.0%
——10——CVE-2026-733996.5 MED34.0%
——10Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.34dCVE-2018-19638—34.0%
——10——CVE-2026-193456.5 MED34.0%
——10A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used.40dCVE-2016-8632—34.0%
——10——CVE-2026-3148—34.0%
——10——CVE-2010-5211—34.0%
——10——CVE-2010-5274—34.0%
——10——CVE-2025-53769—34.0%
——10——CVE-2024-21550—34.0%
——10——