Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-21387—33.6%
——10——CVE-2023-33211—33.6%
——10——CVE-2025-48257—33.6%
——10——CVE-2025-3063—33.6%
——10——CVE-2026-165605.3 MED33.6%
——10A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.62dCVE-2024-33857—33.6%
——10——CVE-2025-10617—33.6%
——10——CVE-2026-2114—33.6%
——10——CVE-2020-2731—33.6%
——10——CVE-2026-199653.7 LOW33.6%
——10A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.33dCVE-2026-44439—33.6%
——10——CVE-2024-58265—33.6%
——10——CVE-2026-2189—33.6%
——10——CVE-2024-47397—33.6%
——10——CVE-2026-501345.8 MED33.6%
——10Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redirects. An allowed server (or an attacker controlling its DNS or response) could therefore redirect the request to a host that the policy was meant to forbid and Hugo would fetch from the redirected target. The same bypass also lifted any host-shape restriction the operator had put in place. This vulnerability is fixed in 0.162.0.77dCVE-2026-91188.8 HIG33.6%
——10Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)61dCVE-2025-3560—33.6%
——10——CVE-2026-628717.8 HIG33.6%
——10Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.40dCVE-2024-7511—33.6%
——10——CVE-2024-6675—33.6%
——10——CVE-2023-37874—33.6%
——10——CVE-2026-28818—33.6%
——10——CVE-2026-2196—33.6%
——10——CVE-2024-6233—33.6%
——10——CVE-2025-63372—33.6%
——10——CVE-2026-621958.3 HIG33.6%
——10OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.70dCVE-2026-680799.8 CRI33.6%
——10In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.47dCVE-2026-91268.8 HIG33.6%
——10Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)61dCVE-2026-91128.8 HIG33.6%
——10Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)64dCVE-2023-32505—33.6%
——10——CVE-2024-47923—33.6%
——10——CVE-2026-1884—33.6%
——10——CVE-2025-49546—33.6%
——10——CVE-2023-32515—33.6%
——10——CVE-2014-125071—33.6%
——10——CVE-2008-1694—33.6%
——10——CVE-2020-10058—33.6%
——10——CVE-2021-38132—33.6%
——10——CVE-2025-4863—33.6%
——10——CVE-2023-50310—33.6%
——10——