Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-156206.3 MED33.8%
——10A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The reported GitHub issue was closed with the label "not planned".70dCVE-2025-32059—33.8%
——10——CVE-2025-32061—33.8%
——10——CVE-2024-7955—33.8%
——10——CVE-2026-1423—33.8%
——10——CVE-2024-42995—33.8%
——10——CVE-2021-0113—33.8%
——10——CVE-2025-32111—33.8%
——10——CVE-2022-48297—33.8%
——10——CVE-2017-15121—33.8%
——10——CVE-2022-46328—33.8%
——10——CVE-2021-25471—33.8%
——10——CVE-2024-21249—33.8%
——10——CVE-2024-43359—33.8%
——10——CVE-2014-9066—33.8%
——10——CVE-2026-151258.8 HIG33.8%
——10Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)75dCVE-2026-664327.5 HIG33.8%
——10Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.39dCVE-2023-39385—33.8%
——10——CVE-2026-2008—33.8%
——10——CVE-2024-1441—33.8%
——10——CVE-2023-39971—33.8%
——10——CVE-2026-43510—33.8%
——10——CVE-2021-46867—33.8%
——10——CVE-2021-46875—33.8%
——10——CVE-2025-9943—33.8%
——10——CVE-2026-68489—33.8%
——10Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.4dCVE-2025-40653—33.8%
——10——CVE-2026-471435.1 MED33.8%
——10Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.54dCVE-2012-2314—33.8%
——10——CVE-2025-7101—33.8%
——10——CVE-2026-33438—33.8%
——10——CVE-2023-31145—33.8%
——10——CVE-2024-13750—33.8%
——10——CVE-2024-1487—33.8%
——10——CVE-2021-22378—33.8%
——10——CVE-2020-37151—33.8%
——10——CVE-2024-30199—33.8%
——10——CVE-2024-37898—33.8%
——10——CVE-2023-36466—33.8%
——10——CVE-2023-39391—33.8%
——10——