Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-41868—31.0%
——9——CVE-2023-44258—31.0%
——9——CVE-2024-54489—31.0%
——9——CVE-2024-1761—31.0%
——9——CVE-2024-23463—31.0%
——9——CVE-2024-51651—31.0%
——9——CVE-2026-22177—31.0%
——9——CVE-2024-56294—31.0%
——9——CVE-2024-45051—31.0%
——9——CVE-2023-53925—31.0%
——9——CVE-2023-46129—31.0%
——9——CVE-2024-54445—31.0%
——9——CVE-2024-56804—31.0%
——9——CVE-2025-7863—31.0%
——9——CVE-2021-28130—31.0%
——9——CVE-2024-12245—31.0%
——9——CVE-2024-0900—31.0%
——9——CVE-2026-0852—31.0%
——9——CVE-2026-759938.5 HIG31.0%
——9ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.1dCVE-2007-5619—31.0%
——9——CVE-2023-7085—31.0%
——9——CVE-2024-39740—31.0%
——9——CVE-2026-572668.3 HIG31.0%
——9GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.
#### 2wayAudio command index-out-of-bound79dCVE-2026-144228.8 HIG31.0%
——9Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)79dCVE-2025-29776—31.0%
——9——CVE-2025-7665—30.9%
——9——CVE-2010-3851—30.9%
——9——CVE-2025-3403—30.9%
——9——CVE-2024-3961—30.9%
——9——CVE-2025-22601—30.9%
——9——CVE-2023-0978—30.9%
——9——CVE-2023-28785—30.9%
——9——CVE-2025-63153—30.9%
——9——CVE-2025-2371—30.9%
——9——CVE-2024-5995—30.9%
——9——CVE-2026-584248.9 HIG30.9%
——9Permanent Fork PR Workflow Approval Gate Bypass75dCVE-2019-25461—30.9%
——9——CVE-2026-11364—30.9%
——9——CVE-2025-22657—30.9%
——9——CVE-2023-23798—30.9%
——9——