Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-882737.2 HIG31.0%
——9GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.9dCVE-2025-62717—31.0%
——9——CVE-2026-72536.0 MED31.0%
——9IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.58dCVE-2024-32694—31.0%
——9——CVE-2026-448237.8 HIG31.0%
——9Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.59dCVE-2025-11065—31.0%
——9——CVE-2023-26061—31.0%
——9——CVE-2026-84586.5 MED31.0%
——9libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
"services".
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.5dCVE-2018-3667—31.0%
——9——CVE-2024-31191—31.0%
——9——CVE-2026-907157.3 HIG31.0%
——9A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.8 mitigates this issue. The name of the patch is 9b337c3eae5833c3956bed1fc01c21c14fd443f2. Upgrading the affected component is recommended.5dCVE-2024-22149—31.0%
——9——CVE-2026-190107.3 HIG31.0%
——9A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.38dCVE-2024-37884—31.0%
——9——CVE-2026-41383—31.0%
——9——CVE-2024-4283—31.0%
——9——CVE-2025-0290—31.0%
——9——CVE-2020-5794—31.0%
——9——CVE-2025-2919—31.0%
——9——CVE-2011-1494—31.0%
——9——CVE-2019-16860—31.0%
——9——CVE-2025-68065—31.0%
——9——CVE-2026-54911—31.0%
——9——CVE-2025-68068—31.0%
——9——CVE-2025-59827—31.0%
——9——CVE-2025-31867—31.0%
——9——CVE-2026-177238.3 HIG31.0%
——9Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)40dCVE-2024-8908—31.0%
——9——CVE-2024-1957—31.0%
——9——CVE-2026-2862—31.0%
——9——CVE-2024-37482—31.0%
——9——CVE-2026-882767.2 HIG31.0%
——9GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.9dCVE-2025-7691—31.0%
——9——CVE-2026-8431—31.0%
——9——CVE-2026-910877.3 HIG31.0%
——9A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.4dCVE-2023-21353—31.0%
——9——CVE-2026-102367.3 HIG31.0%
——9A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.60dCVE-2025-6386—31.0%
——9——CVE-2026-882757.2 HIG31.0%
——9GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.9dCVE-2025-138053.7 LOW31.0%
——9A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component LiteRpc-Serializer. Executing a manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been made available to the public and could be used for attacks.17d