Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-18255—33.0%
——10——CVE-2026-2742—33.0%
——10——CVE-2023-32709—33.0%
——10——CVE-2025-24665—33.0%
——10——CVE-2023-49381—33.0%
——10——CVE-2024-4151—33.0%
——10——CVE-2018-10796—33.0%
——10——CVE-2023-49379—33.0%
——10——CVE-2025-8188—33.0%
——10——CVE-2025-8189—33.0%
——10——CVE-2023-49395—33.0%
——10——CVE-2023-49377—33.0%
——10——CVE-2026-200976.5 MED33.0%
——10A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.25dCVE-2025-48386—33.0%
——10——CVE-2024-5236—33.0%
——10——CVE-2018-11035—33.0%
——10——CVE-2023-49378—33.0%
——10——CVE-2025-61587—33.0%
——10——CVE-2018-1650—33.0%
——10——CVE-2025-24664—33.0%
——10——CVE-2026-910914.3 MED33.0%
——10A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.7dCVE-2025-6774—33.0%
——10——CVE-2023-5837—33.0%
——10——CVE-2024-22179—33.0%
——10——CVE-2025-3893—33.0%
——10——CVE-2025-12450—33.0%
——10——CVE-2018-9063—33.0%
——10——CVE-2026-63303—33.0%
——10A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI.
The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.54dCVE-2026-8617—33.0%
——10——CVE-2023-49376—33.0%
——10——CVE-2023-49398—33.0%
——10——CVE-2005-3631—33.0%
——10——CVE-2013-3232—33.0%
——10——CVE-2023-49372—33.0%
——10——CVE-2023-49396—33.0%
——10——CVE-2024-42456—33.0%
——10——CVE-2017-14296—33.0%
——10——CVE-2025-5015—33.0%
——10——CVE-2025-8172—33.0%
——10——CVE-2024-3379—33.0%
——10——