Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,330
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-4594—32.7%
——10——CVE-2023-5323—32.7%
——10——CVE-1999-0167—32.7%
——10——CVE-2017-15127—32.6%
——10——CVE-2021-46679—32.6%
——10——CVE-2007-0276—32.6%
——10——CVE-2025-59379—32.6%
——10——CVE-2026-5387—32.6%
——10——CVE-2023-6422—32.6%
——10——CVE-2025-203277.7 HIG32.6%
——10A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.5dCVE-2025-22548—32.6%
——10——CVE-2025-1311—32.6%
——10——CVE-2002-0754—32.6%
——10——CVE-2020-37107—32.6%
——10——CVE-2019-13531—32.6%
——10——CVE-2014-3638—32.6%
——10——CVE-2023-3828—32.6%
——10——CVE-2024-3627—32.6%
——10——CVE-2026-843645.3 MED32.6%
——10Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the nesting depth or the total number of intermediate objects created. Empty segments are preserved, so one deeply dotted field name can encode one nesting level per byte, while a large number of shallowly dotted fields can create the same amplification across a request. A request body within a normal size limit can therefore allocate an object graph far larger than the request after the body has already been accepted. An unauthenticated attacker who can reach an affected endpoint can send concurrent requests that exhaust the JavaScript heap, terminate the server process, and leave the service unavailable until restart. Dot-notation parsing is not enabled by default, and applications using the default behavior are not affected. This issue is fixed in version 4.13.5.20dCVE-2025-462066.5 MED32.6%
——10An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion79dCVE-2026-45431—32.6%
——10This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands on the targeted device.
Successful exploitation of this vulnerability could allow the attacker to perform remote code execution with root privileges on the targeted device.62dCVE-2024-46953—32.6%
——10——CVE-2015-0199—32.6%
——10——CVE-2023-6429—32.6%
——10——CVE-2001-1277—32.6%
——10——CVE-2025-8396—32.6%
——10——CVE-2026-764439.8 CRI32.6%
——10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.7dCVE-2013-1774—32.6%
——10——CVE-2025-58474—32.6%
——10——CVE-2026-26367—32.6%
——10——CVE-2024-38281—32.6%
——10——CVE-2023-26214—32.6%
——10——CVE-2025-67848—32.6%
——10——CVE-2021-46678—32.6%
——10——CVE-2009-3519—32.6%
——10——CVE-2026-654107.5 HIG32.6%
——10The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.6dCVE-2024-4290—32.6%
——10——CVE-2023-3543—32.6%
——10——CVE-2026-127939.8 CRI32.6%
——10The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.6dCVE-2023-6430—32.6%
——10——