Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,511
- Medium6,637
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59946—30.6%
——9——CVE-2017-0804—30.6%
——9——CVE-2025-59183.9 LOW30.6%
——9A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.17dCVE-2024-12694—30.6%
——9——CVE-2025-55118—30.6%
——9——CVE-2024-20816—30.6%
——9——CVE-2005-0822—30.6%
——9——CVE-2024-13629—30.6%
——9——CVE-2025-53987—30.6%
——9——CVE-2026-571576.5 MED30.6%
——9FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled scan attacker-supplied DeviceName and VirtualChannelName fields for a NUL terminator in channels/rdpecam/server/camera_device_enumerator_main.c and then dereference once past the scan bound, allowing a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. This issue is fixed in version 3.28.0.67dCVE-2017-0802—30.6%
——9——CVE-2023-39139—30.6%
——9——CVE-2017-1422—30.6%
——9——CVE-2025-59932—30.6%
——9——CVE-2024-8552—30.6%
——9——CVE-2014-3312—30.6%
——9——CVE-2026-199684.3 MED30.6%
——9A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.29dCVE-2001-1017—30.6%
——9——CVE-2026-726606.5 MED30.6%
——9Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.16dCVE-2010-1160—30.6%
——9——CVE-1999-1116—30.6%
——9——CVE-2016-7118—30.6%
——9——CVE-2026-101906.5 MED30.6%
——9A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.59dCVE-2026-21950—30.6%
——9——CVE-2003-0630—30.6%
——9——CVE-2024-2049—30.6%
——9——CVE-2025-24704—30.6%
——9——CVE-2025-23775—30.6%
——9——CVE-2025-26564—30.6%
——9——CVE-2023-35075—30.6%
——9——CVE-2025-70103—30.6%
——9——CVE-2026-637358.1 HIG30.6%
——9SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in other tenants by specifying the target scope in the URL path, reading sensitive data or triggering unintended operations.57dCVE-2026-32059—30.6%
——9——CVE-2026-759998.4 HIG30.6%
——9ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.6hCVE-2020-21469—30.6%
——9——CVE-2015-3002—30.6%
——9——CVE-2025-26579—30.6%
——9——CVE-2004-2148—30.6%
——9——CVE-2025-66863—30.6%
——9——CVE-2026-24954—30.6%
——9——