Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-10277—31.4%
——9——CVE-2018-12174—31.4%
——9——CVE-2024-8724—31.4%
——9——CVE-2024-34071—31.4%
——9——CVE-2025-49693—31.4%
——9——CVE-2024-13164—31.4%
——9——CVE-2024-9610—31.4%
——9——CVE-2023-38255—31.4%
——9——CVE-2020-9079—31.4%
——9——CVE-2022-45137—31.4%
——9——CVE-2024-44820—31.4%
——9——CVE-2023-0010—31.4%
——9——CVE-2022-34260—31.4%
——9——CVE-2009-3940—31.4%
——9——CVE-2024-9346—31.4%
——9——CVE-2023-22096—31.4%
——9——CVE-2026-492227.6 HIG31.4%
——9Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product question operations allow a low-privileged Vendor to manage questions under another Vendor's products. The admin/sql/sqlite/product_question.sql queries accept a caller-controlled product_question_id and do not verify product_question.product_id against product.admin_id for the current admin_id. An attacker can read pending question content and moderation data, change question status, edit question content, or delete questions, manipulating product Q&A visibility and integrity. This issue is fixed in version 1.0.8.4.12dCVE-2021-25671—31.4%
——9——CVE-2009-3524—31.4%
——9——CVE-2023-1190—31.4%
——9——CVE-2013-2007—31.4%
——9——CVE-2025-29156—31.4%
——9——CVE-2016-3640—31.4%
——9——CVE-2014-6147—31.4%
——9——CVE-2024-25597—31.4%
——9——CVE-2023-21479—31.4%
——9——CVE-2025-27451—31.4%
——9——CVE-2026-828157.3 HIG31.4%
——9A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.19dCVE-2025-5184—31.4%
——9——CVE-2026-538256.5 MED31.4%
——9OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers with operator.write access can specify arbitrary local file paths to import file content into wiki memory, bypassing access restrictions.60dCVE-2024-25224—31.4%
——9——CVE-2021-1118—31.4%
——9——CVE-2025-10743—31.4%
——9——CVE-2026-193007.5 HIG31.4%
——9IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.12dCVE-2009-2899—31.4%
——9——CVE-2018-7472—31.4%
——9——CVE-2004-1263—31.4%
——9——CVE-2015-5448—31.4%
——9——CVE-2026-39007—31.4%
——9——CVE-2020-8719—31.4%
——9——