Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-374577.5 HIG32.8%
——10An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.70dCVE-2026-31705—32.8%
——10——CVE-2026-56235—32.8%
——10——CVE-2019-3997—32.8%
——10——CVE-2026-183037.8 HIG32.8%
——10GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29399.20dCVE-2026-113246.1 MED32.8%
——10The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.67dCVE-2025-68541—32.8%
——10——CVE-2015-5231—32.8%
——10——CVE-2025-40618—32.8%
——10——CVE-2026-455575.8 MED32.8%
——10Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.60dCVE-2008-0001—32.8%
——10——CVE-2023-32665—32.8%
——10——CVE-2005-2873—32.8%
——10——CVE-2026-476238.2 HIG32.8%
——10NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.46dCVE-2025-30762—32.8%
——10——CVE-2024-36624—32.8%
——10——CVE-2014-7954—32.8%
——10——CVE-2024-10768—32.8%
——10——CVE-2001-0424—32.8%
——10——CVE-2022-4898—32.8%
——10——CVE-2001-1059—32.8%
——10——CVE-2024-38749—32.8%
——10——CVE-2022-42985—32.8%
——10——CVE-2025-69382—32.8%
——10——CVE-2023-5366—32.8%
——10——CVE-2024-39339—32.8%
——10——CVE-2026-440615.9 MED32.8%
——10Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover authentication credentials via timing analysis.64dCVE-2014-1350—32.8%
——10——CVE-2026-878247.5 HIG32.8%
——10zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.3dCVE-2025-69599—32.8%
——10——CVE-2004-1179—32.8%
——10——CVE-2025-67997—32.8%
——10——CVE-2024-21113—32.8%
——10——CVE-2024-1762—32.8%
——10——CVE-2017-3757—32.8%
——10——CVE-2024-13595—32.8%
——10——CVE-2022-29209—32.8%
——10——CVE-2018-3638—32.8%
——10——CVE-2023-22912—32.8%
——10——CVE-2023-0204—32.8%
——10——