Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,495
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51715—32.2%
——10——CVE-2023-29020—32.2%
——10——CVE-2024-11497—32.2%
——10——CVE-2026-615169.8 CRI32.2%
——10Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.2dCVE-2026-863215.3 MED32.2%
——10A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.13dCVE-2023-36093—32.2%
——10——CVE-2021-21599—32.2%
——10——CVE-2016-8659—32.2%
——10——CVE-2019-0161—32.2%
——10——CVE-2018-1564—32.2%
——10——CVE-2022-45542—32.2%
——10——CVE-2024-8586—32.2%
——10——CVE-2026-80928.1 HIG32.2%
——10Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.55dCVE-2026-790386.5 MED32.2%
——10Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)26dCVE-2017-7377—32.2%
——10——CVE-2026-34517—32.2%
——10——CVE-2016-5328—32.2%
——10——CVE-2022-42843—32.2%
——10——CVE-2020-35916—32.2%
——10——CVE-2026-40346—32.2%
——10——CVE-2026-54517—32.2%
——10——CVE-2020-29571—32.2%
——10——CVE-2026-162176.3 MED32.2%
——10A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the argument project_id leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.63dCVE-2018-20941—32.2%
——10——CVE-2016-6310—32.2%
——10——CVE-2018-14985—32.2%
——10——CVE-2020-14758—32.2%
——10——CVE-2018-19522—32.2%
——10——CVE-2026-37712—32.2%
——10——CVE-2026-63383—32.2%
——10Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.12dCVE-2013-0222—32.2%
——10——CVE-2007-1086—32.2%
——10——CVE-2023-49233—32.2%
——10——CVE-2026-37713—32.2%
——10——CVE-2006-3813—32.2%
——10——CVE-2013-4577—32.2%
——10——CVE-2026-135126.3 MED32.2%
——10A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.83dCVE-2023-33163—32.2%
——10——CVE-2026-162146.3 MED32.2%
——10A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.61dCVE-2025-27193—32.2%
——10——