Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-202615.8 MED30.8%
——9A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file. This vulnerability exists because of a logic error when a specific class of encrypted archive files is inspected. An attacker could exploit this vulnerability by sending a crafted, encrypted archive file through the affected device. A successful exploit could allow the attacker to send an encrypted archive file, which could contain malware and should have been blocked and dropped at the Cisco FTD device.39dCVE-2026-341186.5 MED30.8%
——9A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input.
An attacker
on the same network segment could trigger heap memory corruption conditions by
sending crafted payloads that cause write operations beyond allocated buffer
boundaries. Successful exploitation
causes a Denial-of-Service (DoS) condition, causing the device’s process to
crash or become unresponsive.31dCVE-2024-47493—30.8%
——9——CVE-2026-22601—30.8%
——9——CVE-2021-20257—30.8%
——9——CVE-2026-377506.1 MED30.8%
——9A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php.61dCVE-2023-24406—30.8%
——9——CVE-2023-26515—30.8%
——9——CVE-2023-32292—30.8%
——9——CVE-2023-26539—30.8%
——9——CVE-2023-23881—30.8%
——9——CVE-2025-45311—30.8%
——9——CVE-2024-28583—30.8%
——9——CVE-2024-32966—30.8%
——9——CVE-2023-34369—30.8%
——9——CVE-2023-25021—30.8%
——9——CVE-2023-23720—30.8%
——9——CVE-2023-23863—30.8%
——9——CVE-2023-22684—30.8%
——9——CVE-2023-26016—30.8%
——9——CVE-2023-2490—30.8%
——9——CVE-2023-47122—30.8%
——9——CVE-2023-27425—30.8%
——9——CVE-2023-25797—30.8%
——9——CVE-2026-405364.3 MED30.8%
——9An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.1dCVE-2026-580425.9 MED30.8%
——9A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.
Repeated triggering of this condition can lead to denial of service.
This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.16dCVE-2023-27439—30.8%
——9——CVE-2023-25796—30.8%
——9——CVE-2023-25792—30.8%
——9——CVE-2026-29787—30.8%
——9——CVE-2023-30749—30.8%
——9——CVE-2023-34170—30.8%
——9——CVE-2023-29094—30.8%
——9——CVE-2023-28422—30.8%
——9——CVE-2023-30875—30.8%
——9——CVE-2022-47434—30.8%
——9——CVE-2023-30786—30.8%
——9——CVE-2025-51384—30.8%
——9——CVE-2021-32461—30.8%
——9——CVE-2023-25979—30.8%
——9——