Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-1657—31.7%
——10——CVE-2025-66298—31.7%
——10——CVE-2024-37071—31.7%
——10——CVE-2020-23363—31.7%
——10——CVE-2025-6867—31.7%
——10——CVE-2026-814428.1 HIG31.7%
——10Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.3dCVE-2020-10723—31.7%
——10——CVE-2026-409583.7 LOW31.7%
——10CVE-2026-40958
is a input validation error in Secure Access clients prior to 14.55. Attackers
with intimate knowledge of and total control over the tunnel protocol can
create a non-persistent DoS against their client.67dCVE-2025-10245—31.7%
——10——CVE-2025-11049—31.7%
——10——CVE-2026-27747—31.7%
——10——CVE-2023-39409—31.7%
——10——CVE-2023-7325—31.7%
——10——CVE-2017-15112—31.7%
——10——CVE-2021-25755—31.7%
——10——CVE-2026-864844.6 MED31.7%
——10In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS13dCVE-2023-41299—31.7%
——10——CVE-2023-32761—31.7%
——10——CVE-2023-23629—31.7%
——10——CVE-2025-59332—31.7%
——10——CVE-2023-20056.3 MED31.7%
——10Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 .
This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.
35dCVE-2023-21725—31.7%
——10——CVE-2023-2679—31.7%
——10——CVE-2013-4482—31.7%
——10——CVE-2025-40838—31.7%
——10——CVE-2026-28991—31.7%
——10——CVE-2024-9896—31.7%
——10——CVE-2026-4076—31.7%
——10——CVE-2020-10722—31.7%
——10——CVE-2011-0995—31.7%
——10——CVE-2008-1951—31.7%
——10——CVE-2025-47682—31.7%
——10——CVE-2023-46447—31.7%
——10——CVE-2024-10747—31.6%
——9——CVE-2026-603167.2 HIG31.6%
——9Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).55dCVE-2023-50368—31.6%
——9——CVE-2026-54805—31.6%
——9——CVE-2024-6078—31.6%
——9——CVE-2025-27796—31.6%
——9——CVE-2025-119938.8 HIG31.6%
——9The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via the import configuration feature without capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No POP chain is present within the vulnerable plugin itself, but if a POP chain is present via an additional plugin or theme installed on the target system, it could allow an attacker to delete arbitrary files, retrieve sensitive data, or execute code.62d