Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-1320—31.3%
——9——CVE-2026-27859—31.3%
——9——CVE-2017-6353—31.3%
——9——CVE-2024-12250—31.3%
——9——CVE-2023-5421—31.3%
——9——CVE-2023-49175—31.3%
——9——CVE-2024-12651—31.3%
——9——CVE-2026-13544—31.3%
——9——CVE-2025-65844—31.3%
——9——CVE-2023-32296—31.3%
——9——CVE-2019-14302—31.3%
——9——CVE-2026-891747.5 HIG31.3%
——9Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.10dCVE-2026-54746.3 MED31.3%
——9A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the local network to execute the attack. The project was informed of the problem early through an issue report but has not responded yet.58dCVE-2017-0491—31.3%
——9——CVE-2024-2231—31.3%
——9——CVE-2008-4972—31.3%
——9——CVE-2025-6919—31.3%
——9——CVE-2025-0525—31.3%
——9——CVE-2026-155256.3 MED31.3%
——9A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the argument final_url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 0.10.0 is able to resolve this issue. The patch is named 217399723e3a2fb39389e5355d49ed80aaf9ea7c. Upgrading the affected component is advised.70dCVE-2024-5212—31.3%
——9——CVE-2025-39439—31.3%
——9——CVE-2023-6527—31.3%
——9——CVE-2014-4431—31.3%
——9——CVE-2023-39991—31.3%
——9——CVE-2026-41196—31.3%
——9——CVE-2026-748687.5 HIG31.3%
——9SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go). The Publish Service runs on a separate, unauthenticated-by-default listener (default TCP port 6808) and gates named publish-viewer accounts (Conf.Publish.Auth.Accounts) with Basic Auth that has no rate limiting, per-account lockout, or backoff. Unauthenticated remote attackers can submit unlimited password guesses against named accounts to gain access to published notes/notebooks.26dCVE-2023-34180—31.3%
——9——CVE-2026-76556—31.3%
——9The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by default and may also grant to lower roles, to perform SQL injection attacks.4dCVE-2008-5154—31.3%
——9——CVE-2015-1377—31.3%
——9——CVE-2026-76557—31.3%
——9The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to perform SQL injection attacks.4dCVE-2009-0667—31.3%
——9——CVE-2013-1776—31.3%
——9——CVE-2024-6887—31.3%
——9——CVE-2026-602818.1 HIG31.3%
——9Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).59dCVE-2026-22635.3 MED31.3%
——9The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics.58dCVE-2023-49184—31.3%
——9——CVE-2025-11340—31.3%
——9——CVE-2023-51295—31.3%
——9——CVE-2024-55975—31.3%
——9——