Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-1732—32.4%
——10——CVE-2025-68468—32.4%
——10——CVE-2025-6590—32.4%
——10——CVE-2014-2894—32.4%
——10——CVE-2026-527186.5 MED32.4%
——10A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash.54dCVE-2026-85590—32.4%
——10phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP without requiring password re-entry or a current TOTP code. The same downgrade is also reachable inline via PUT /api/user/data/update, which accepts a plain twofactor_enabled form field under the same session+CSRF-only guard. An attacker who has hijacked a user's session can silently strip two-factor protection from any account, including administrator accounts, after which password-only authentication succeeds.13dCVE-2023-42546—32.4%
——10——CVE-2022-46088—32.4%
——10——CVE-2024-34591—32.4%
——10——CVE-2024-10684—32.4%
——10——CVE-2023-42549—32.4%
——10——CVE-2024-1779—32.4%
——10——CVE-2026-476918.7 HIG32.4%
——10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.3dCVE-2025-53621—32.4%
——10——CVE-2024-20509—32.4%
——10——CVE-2023-0053—32.4%
——10——CVE-2025-24353—32.4%
——10——CVE-2025-66305—32.4%
——10——CVE-2023-47829—32.4%
——10——CVE-2023-31130—32.4%
——10——CVE-2017-12809—32.4%
——10——CVE-1999-1209—32.4%
——10——CVE-2024-5941—32.4%
——10——CVE-2012-1681—32.4%
——10——CVE-2024-51257—32.4%
——10——CVE-2024-28823—32.4%
——10——CVE-2023-21949—32.4%
——10——CVE-2024-13403—32.4%
——10——CVE-2025-8367—32.4%
——10——CVE-2019-12808—32.4%
——10——CVE-2026-30829—32.4%
——10——CVE-2023-38826—32.4%
——10——CVE-2023-42551—32.4%
——10——CVE-2021-1228—32.4%
——10——CVE-2025-9666—32.4%
——10——CVE-2024-24983—32.4%
——10——CVE-2023-6066—32.4%
——10——CVE-2026-4471—32.4%
——10——CVE-2016-8365—32.4%
——10——CVE-2019-1593—32.4%
——10——