Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-748789.8 CRI33.9%
——10openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.21dCVE-2023-53775—33.9%
——10——CVE-2025-3281—33.9%
——10——CVE-2025-11481—33.9%
——10——CVE-2023-21216—33.9%
——10——CVE-2023-39437—33.9%
——10——CVE-2026-352097.5 HIG33.9%
——10defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype pollution. A crafted payload containing a `__proto__` key can override intended default values in the merged resul. The internal `_defu` function used `Object.assign({}, defaults)` to copy the defaults object. `Object.assign` invokes the `__proto__` setter, which replaces the resulting object's `[[Prototype]]` with attacker-controlled values. Properties inherited from the polluted prototype then bypass the existing `__proto__` key guard in the `for...in` loop and land in the final result. Version 6.1.5 replaces `Object.assign({}, defaults)` with object spread (`{ ...defaults }`), which uses `[[DefineOwnProperty]]` and does not invoke the `__proto__` setter.63dCVE-2024-23888—33.9%
——10——CVE-2026-32401—33.9%
——10——CVE-2020-15843—33.9%
——10——CVE-2025-28099—33.9%
——10——CVE-2016-2521—33.9%
——10——CVE-2026-33102—33.9%
——10——CVE-2024-50921—33.9%
——10——CVE-2024-43756—33.9%
——10——CVE-2022-41661—33.9%
——10——CVE-2026-650585.3 MED33.9%
——10Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.54dCVE-2024-39581—33.9%
——10——CVE-2026-33838—33.9%
——10——CVE-2026-557388.8 HIG33.9%
——10A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.44dCVE-2024-203416.1 MED33.9%
——10A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This vulnerability is due to improper validation of user-supplied input to application endpoints. An attacker could exploit this vulnerability by persuading a user to follow a link designed to submit malicious input to the affected application. A successful exploit could allow the attacker to execute arbitrary HTML or script code in the browser in the context of the web services page.42dCVE-2025-1170—33.9%
——10——CVE-2023-24027—33.9%
——10——CVE-2022-41662—33.9%
——10——CVE-2021-25406—33.9%
——10——CVE-2024-23884—33.9%
——10——CVE-2025-8434—33.9%
——10——CVE-2024-10852—33.9%
——10——CVE-2025-11431—33.9%
——10——CVE-2026-8783—33.9%
——10——CVE-2026-33285—33.9%
——10——CVE-2026-170944.3 MED33.8%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.37dCVE-2019-5011—33.8%
——10——CVE-2023-42829—33.8%
——10——CVE-2024-7955—33.8%
——10——CVE-2025-20134—33.8%
——10——CVE-2026-418636.5 MED33.8%
——10Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.
Affected versions:
Spring AI: 1.1.0 through 1.1.x61dCVE-2024-5861—33.8%
——10——CVE-2007-0739—33.8%
——10——CVE-2024-34906—33.8%
——10——