Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-4272—32.3%
——10——CVE-2026-81906—32.3%
——10Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.10dCVE-2024-8646—32.3%
——10——CVE-2024-5371—32.3%
——10——CVE-2026-33334—32.3%
——10——CVE-2026-797734.9 MED32.3%
——10Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.24dCVE-2025-40715—32.3%
——10——CVE-2026-1721—32.3%
——10——CVE-2026-571665.3 MED32.3%
——10PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback for an entered command line. Several command-line handling paths write an attacker-influenced amount of data into fixed-size buffers without sufficient bounds checking, so a long command line can overflow them. This affects only applications that enable the telnet CLI front-end (e.g. pj_cli_telnet_create() / --cli-telnet-port). The telnet CLI is an interactive administration interface with no authentication, so any client able to reach it can already issue arbitrary CLI commands. A malformed or overly long command line can overflow a fixed-size stack buffer while rendering command-line feedback, which may lead to application termination. Because reaching this code already requires access to the unauthenticated CLI, the impact beyond that existing access is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 4472a31.10dCVE-2024-2521—32.3%
——10——CVE-2024-27334—32.3%
——10——CVE-2025-11189—32.3%
——10——CVE-2025-28993—32.3%
——10——CVE-2024-6208—32.3%
——10——CVE-2022-4631—32.3%
——10——CVE-2025-26855—32.3%
——10——CVE-2024-8486—32.3%
——10——CVE-2024-40407—32.3%
——10——CVE-2024-5370—32.3%
——10——CVE-2026-454663.3 LOW32.3%
——10Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.61dCVE-2026-32595—32.3%
——10——CVE-2020-37033—32.3%
——10——CVE-2025-25170—32.3%
——10——CVE-2009-2714—32.3%
——10——CVE-2021-4257—32.3%
——10——CVE-2025-23762—32.3%
——10——CVE-2020-0386—32.3%
——10——CVE-2021-4251—32.3%
——10——CVE-2026-82754—32.3%
——10Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix.
oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias.
This issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.13dCVE-2022-40675—32.3%
——10——CVE-2025-63460—32.3%
——10——CVE-2025-63462—32.3%
——10——CVE-2022-45398—32.3%
——10——CVE-2026-25799—32.3%
——10——CVE-2026-19464.3 MED32.3%
——10The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the plugin from GravityWrite via the 'gwaiwebu_gravitywrite_disconnect' AJAX action.70dCVE-2025-23731—32.3%
——10——CVE-2023-44436—32.3%
——10——CVE-2025-49978—32.3%
——10——CVE-2025-25108—32.3%
——10——CVE-2025-23753—32.3%
——10——