Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-4406—31.7%
——10——CVE-2026-40157—31.7%
——10——CVE-2023-33322—31.7%
——10——CVE-2024-47915—31.7%
——10——CVE-2023-52113—31.7%
——10——CVE-2022-44849—31.7%
——10——CVE-2026-4014—31.7%
——10——CVE-2025-30778—31.7%
——10——CVE-2023-23691—31.7%
——10——CVE-2005-0508—31.7%
——10——CVE-2024-46547—31.7%
——10——CVE-2026-289357.5 HIG31.7%
——10The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.4dCVE-2026-55367.3 HIG31.7%
——10A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.59dCVE-2025-14327—31.7%
——10——CVE-2023-24671—31.7%
——10——CVE-2025-26575—31.7%
——10——CVE-2007-4794—31.7%
——10——CVE-2007-5839—31.7%
——10——CVE-2023-27059—31.7%
——10——CVE-2014-3602—31.7%
——10——CVE-2024-54138—31.7%
——10——CVE-2022-48344—31.7%
——10——CVE-2013-3227—31.7%
——10——CVE-2023-0620—31.7%
——10——CVE-2005-3108—31.7%
——10——CVE-2011-1490—31.7%
——10——CVE-2026-650114.3 MED31.7%
——10Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.60dCVE-2019-19582—31.7%
——10——CVE-2016-10723—31.7%
——10——CVE-2025-31086—31.7%
——10——CVE-2005-4881—31.7%
——10——CVE-2026-9587—31.7%
——10An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.66dCVE-2008-5395—31.7%
——10——CVE-2025-32543—31.7%
——10——CVE-2026-12194—31.7%
——10PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.77dCVE-2026-7402—31.7%
——10——CVE-2025-26546—31.7%
——10——CVE-2026-192907.5 HIG31.7%
——10IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.5dCVE-2025-26541—31.7%
——10——CVE-2020-36322—31.7%
——10——