Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-38783—32.0%
——10——CVE-2023-48739—32.0%
——10——CVE-2026-396847.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfood allows PHP Local File Inclusion.This issue affects OrganicFood: from n/a through <= 3.6.4.59dCVE-2012-3199—32.0%
——10——CVE-2022-2172—32.0%
——10——CVE-2025-12226—32.0%
——10——CVE-2026-32400—32.0%
——10——CVE-2024-35683—32.0%
——10——CVE-2023-47823—32.0%
——10——CVE-2025-438924.3 MED32.0%
——10A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.41dCVE-2024-37921—32.0%
——10——CVE-2025-8796—32.0%
——10——CVE-2024-32826—32.0%
——10——CVE-2024-37468—32.0%
——10——CVE-2024-37456—32.0%
——10——CVE-2026-262189.8 CRI32.0%
——10newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.69dCVE-2022-35897—32.0%
——10——CVE-2026-32392—32.0%
——10——CVE-2012-0842—32.0%
——10——CVE-2025-47600—32.0%
——10——CVE-2020-2599—32.0%
——10——CVE-2026-134469.8 CRI32.0%
——10IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.61dCVE-2025-12315—32.0%
——10——CVE-2019-8902—32.0%
——10——CVE-2011-0412—32.0%
——10——CVE-2026-73358.8 HIG32.0%
——10Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)59dCVE-2026-396817.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows PHP Local File Inclusion.This issue affects Homeo: from n/a through <= 1.2.59.59dCVE-2015-3332—32.0%
——10——CVE-2014-6540—32.0%
——10——CVE-2026-395447.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechco allows PHP Local File Inclusion.This issue affects LabtechCO: from n/a through <= 8.3.59dCVE-2022-20452—32.0%
——10——CVE-2009-4306—32.0%
——10——CVE-2025-50260—32.0%
——10——CVE-2025-50180—32.0%
——10——CVE-2026-20144—32.0%
——10——CVE-2014-6473—32.0%
——10——CVE-2025-26649—32.0%
——10——CVE-2026-395387.5 HIG32.0%
——10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through <= 1.6.59dCVE-2024-43219—32.0%
——10——CVE-2024-37926—32.0%
——10——