Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-181926.5 MED31.9%
——10VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.53dCVE-2021-45476—31.9%
——10——CVE-2026-574989.6 CRI31.9%
——10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474.83dCVE-2026-170576.5 MED31.9%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.13dCVE-2023-32344—31.9%
——10——CVE-2016-6065—31.9%
——10——CVE-2025-69246—31.9%
——10——CVE-2026-8319—31.9%
——10——CVE-2022-47438—31.9%
——10——CVE-2013-6394—31.9%
——10——CVE-2026-706699.8 CRI31.9%
——10Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).27dCVE-2010-2538—31.9%
——10——CVE-2025-22699—31.9%
——10——CVE-2024-5626—31.9%
——10——CVE-2026-131258.8 HIG31.9%
——10GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
In order to access the websocket server, no authentication is required. As such, any malicious website can attempt to open a connection to the server and potentially access sensitive APIs. In particular, it's possible to call a combination of the `create` method and `getScreenCapture` to retrieve the content of the user's screen.81dCVE-2015-6403—31.9%
——10——CVE-2025-23773—31.9%
——10——CVE-2024-56412—31.9%
——10——CVE-2026-8270—31.9%
——10——CVE-2026-21438—31.9%
——10——CVE-2025-60339—31.9%
——10——CVE-2023-45636—31.9%
——10——CVE-2026-1702—31.9%
——10——CVE-2022-48507—31.9%
——10——CVE-2021-46879—31.9%
——10——CVE-2021-4258—31.9%
——10——CVE-2024-8786—31.9%
——10——CVE-2025-3692—31.9%
——10——CVE-2013-5724—31.9%
——10——CVE-2026-7330—31.9%
——10——CVE-2026-16599—31.9%
——10GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa24dCVE-2025-24649—31.9%
——10——CVE-2025-713358.1 HIG31.9%
——10Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.82dCVE-2025-3923—31.9%
——10——CVE-2026-50745—31.9%
——10——CVE-2022-2959—31.9%
——10——CVE-2023-48276—31.9%
——10——CVE-2024-25551—31.9%
——10——CVE-2017-7720—31.9%
——10——CVE-2024-13396—31.9%
——10——