Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,639
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59417—33.8%
——10——CVE-2026-32948.8 HIG33.8%
——10An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.
Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.62dCVE-2026-131178.1 HIG33.8%
——10An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage48dCVE-2025-14988—33.8%
——10——CVE-2024-30550—33.8%
——10——CVE-2024-36112—33.8%
——10——CVE-2026-4678—33.8%
——10——CVE-2025-3831—33.8%
——10——CVE-2024-29092—33.8%
——10——CVE-2023-32572—33.8%
——10——CVE-2024-31219—33.8%
——10——CVE-2025-12599—33.8%
——10——CVE-2026-758407.5 HIG33.8%
——10ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes and read arbitrary files on the host system as the ArcadeDB server process.14dCVE-2026-95764.9 MED33.8%
——10The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.84dCVE-2023-42036—33.8%
——10——CVE-2020-37193—33.8%
——10——CVE-2024-6600—33.8%
——10——CVE-2008-7273—33.8%
——10——CVE-2008-5987—33.8%
——10——CVE-2025-7880—33.8%
——10——CVE-2024-39553—33.8%
——10——CVE-2024-29130—33.8%
——10——CVE-2024-31419—33.8%
——10——CVE-2024-58336—33.8%
——10——CVE-2023-49554—33.8%
——10——CVE-2026-92138.1 HIG33.8%
——10A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.62dCVE-2025-65288—33.8%
——10——CVE-2020-36609—33.8%
——10——CVE-2023-40485—33.8%
——10——CVE-2023-20886—33.8%
——10——CVE-2010-5245—33.8%
——10——CVE-2025-709997.5 HIG33.8%
——10A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID.80dCVE-2026-3474—33.8%
——10——CVE-2026-28944—33.8%
——10——CVE-2004-2276—33.8%
——10——CVE-2026-632999.9 CRI33.8%
——10An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.11dCVE-2026-26747—33.8%
——10——CVE-2017-5578—33.8%
——10——CVE-2023-29755—33.8%
——10——CVE-2025-27214—33.8%
——10——