Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-33648—30.9%
——9——CVE-2024-45861—30.9%
——9——CVE-2023-0439—30.9%
——9——CVE-2023-29387—30.9%
——9——CVE-2025-63154—30.9%
——9——CVE-2026-911447.5 HIG30.9%
——9ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.2dCVE-2015-3318—30.9%
——9——CVE-2022-34262—30.9%
——9——CVE-2026-628037.8 HIG30.9%
——9Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.17dCVE-2026-789076.5 MED30.9%
——9Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)23dCVE-2023-0431—30.9%
——9——CVE-2025-31425—30.9%
——9——CVE-2026-35524.3 MED30.9%
——9The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410, ajax_delete_410, ajax_bulk_410_delete, ajax_empty_410, ajax_export_410) properly implement both authorization and nonce checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action. Injected URLs will cause the site to return HTTP 410 Gone responses to all visitors accessing those paths, potentially causing denial of service for legitimate pages and SEO damage through search engine delisting.68dCVE-2017-1468—30.9%
——9——CVE-2023-23657—30.9%
——9——CVE-2023-37970—30.9%
——9——CVE-2014-1378—30.9%
——9——CVE-2023-23999—30.9%
——9——CVE-2026-470948.8 HIG30.9%
——9SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a PUT request to the employee update endpoint with an arbitrary employee identifier and a controlled password value to take over target accounts, enumerate employee records, and retrieve sensitive personally identifiable information including private pay bulletins.3dCVE-2016-5604—30.9%
——9——CVE-2023-23828—30.9%
——9——CVE-2026-24137—30.9%
——9——CVE-2024-31304—30.9%
——9——CVE-2023-50833—30.9%
——9——CVE-2023-48053—30.9%
——9——CVE-2024-34139—30.9%
——9——CVE-2023-23827—30.9%
——9——CVE-2024-56317—30.9%
——9——CVE-2026-257879.1 CRI30.9%
——9Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page.
If a benign user with appropriate rights accesses the "Motion Control Diagnostics" parameters page, the malicious code would be executed in the scope of their web session.68dCVE-2024-6138—30.9%
——9——CVE-2025-20166—30.9%
——9——CVE-2023-48055—30.9%
——9——CVE-2021-3573—30.9%
——9——CVE-2024-53620—30.9%
——9——CVE-2006-0812—30.9%
——9——CVE-2022-38407—30.9%
——9——CVE-2025-43808—30.9%
——9——CVE-2014-1832—30.9%
——9——CVE-2025-62170—30.9%
——9——CVE-2026-79653—30.9%
——9In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path traversal.
The immediate workaround is to disable enable.attachment.store.to.file.system or update to fixed versions.18d