Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-46858—32.1%
——10——CVE-2023-36686—32.1%
——10——CVE-2023-32965—32.1%
——10——CVE-2023-30475—32.1%
——10——CVE-2023-22703—32.1%
——10——CVE-2023-32118—32.1%
——10——CVE-2023-37976—32.1%
——10——CVE-2023-32511—32.1%
——10——CVE-2023-32503—32.1%
——10——CVE-2023-32510—32.1%
——10——CVE-2023-30782—32.1%
——10——CVE-2023-27450—32.1%
——10——CVE-2015-0884—32.1%
——10——CVE-2023-29388—32.1%
——10——CVE-2023-34184—32.1%
——10——CVE-2023-32300—32.1%
——10——CVE-2023-28750—32.1%
——10——CVE-2023-22710—32.1%
——10——CVE-2023-27412—32.1%
——10——CVE-2023-32106—32.1%
——10——CVE-2023-37893—32.1%
——10——CVE-2023-38384—32.1%
——10——CVE-2023-24413—32.1%
——10——CVE-2023-28992—32.1%
——10——CVE-2023-35775—32.1%
——10——CVE-2023-32499—32.1%
——10——CVE-2023-31094—32.1%
——10——CVE-2023-28166—32.1%
——10——CVE-2022-46822—32.1%
——10——CVE-2023-31071—32.1%
——10——CVE-2025-12268—32.1%
——10——CVE-2026-8169—32.1%
——10ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization. Depending on device configuration and version, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation requires either a valid low-privilege account on the device (remote scenario) or physical serial console access (local scenario). This vulnerability is distinct from CVE-2017-14329, which addressed a different issue involving Python script privileges.
Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.62dCVE-2026-73241—32.1%
——10FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.12dCVE-2026-425055.3 MED32.1%
——10Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.5dCVE-2001-0568—32.1%
——10——CVE-2001-1409—32.1%
——10——CVE-2026-124837.5 HIG32.1%
——10The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for authenticated attackers, with subscriber-level access and above who are enrolled in a course with assignment uploads enabled, to upload arbitrary disallowed files, including PHP files, to the server's wp-content/uploads/learndash/assignments/ directory. The uploaded files can only be used for Remote Code Execution if default server configurations have been changed to allow for execution.13dCVE-2020-1641—32.1%
——10——CVE-2024-26335—32.1%
——10——CVE-2023-37232—32.1%
——10——